Cyber-Magazine-september2026 | Page 28

THE CYBER INTERVIEW
One of the biggest AI risks, Russ argues, is“ bad or irresponsible implementation – poor selection of your tools and models and not really looking at the privacy and data residency requirements of your customer base when selecting models”.
This explains why Ping Identity was quick to adopt the ISO 42001 AI governance model, helping it perform all essential checks and balances.
“ We’ re enabling businesses to use AI responsibly while still allowing them to get into the market quickly,” Russ goes on.
Such governance frameworks are not just a security feature but also a competitive differentiator:“ When people are looking to use the services or products of companies that use AI, those certifications and assurances that governance frameworks are in place is something that everyone’ s looking for now.”
The necessity of role-based control All organisations have a hierarchy, with each employee authorised to carry out certain actions. Agents, too, must abide by rules that curtail their access. Russ continues:“ We have some very capable products – agent gateways, MCP gateways, AI gateways – which enable you to essentially proxy and moderate an agent’ s behaviour and take it from a position of what should the agent be able to do and what should the agent have to ask permission to do.”
He explains that agents – in order to behave efficiently – should not simply be given broad permission to“ do everything possible”.
Russ adds:“ That’ s where we really use that human-in-the-loop model. There are things an agent can do at will and things you want it to check with you.”
Why AI is not a point solution The never-ending list of bugs being unearthed by AI-driven vulnerability detection has been keeping CISOs everywhere up at night.
Asked how Ping Identity is holding up, Russ states:“ It’ s not just AI discovering the vulnerability; it’ s AI triaging the vulnerability; it’ s AI developing the patch; it’ s AI deploying the patch.” The issue, Russ notes, is looking to AI as an individual capability.
28 September 2026