Axios AI+

May 09, 2025
We did it. We made it through another week. Good job us. And happy Mother's Day in advance to all the moms, including mine! Today's AI+ is 1,134 words, a 4.5-minute read.
1 big thing: Fears grow over rogue AI agents
A new identity crisis faces the cybersecurity industry — not for people, but for AI agents that act autonomously and will need to be managed like employees.
Why it matters: Without proper guardrails, agents could, at the very least, cause incidental data breaches, misuse login credentials, and leak sensitive information.
The big picture: Just as companies start to embrace AI agents for critical tasks, security vendors are scrambling to build guardrails around them, warning that every agent must have a credentialed identity — or it risks undermining trust, compliance and control.
- Even without AI agents, hackers have already proven to be pretty good at hacking employee accounts through stolen and reused passwords.
- "You can't treat them like a human identity and think that multifactor authentication applies in the same way because humans click things, they can type things in, they can type codes," David Bradbury, chief security officer at Okta, told Axios.
- Agents require a new way of thinking: They need the same "elevated, high trust" that human accounts receive but in a new way, Bradbury said.
Driving the news: Securing AI agents' identities was a major theme of last week's RSA Conference in San Francisco.
- 1Password introduced two security tools right before the conference tailored to both AI agent developers and IT managers to help make securing agents' identities easier.
- Other identity security providers, including Okta and OwnID, also released products for securing AI identities earlier this year.
By the numbers: Deloitte predicts that 25% of companies that use generative AI will launch agentic AI pilots this year. Half will launch pilots by 2027, Deloitte says.
State of play: Security pros are already used to securing so-called nonhuman identities.
- Bot accounts, file servers, VPN gateways and any other machine-based entities require their own version of a username and password.
Between the lines: Securing the identities of AI agents doesn't require much additional innovation. But the stakes are higher since those agents could be given free rein on a company's network.
- "They work 24/7, without sleeping and at very quick speeds," Jeff Shiner, CEO of 1Password, told Axios. An agent "acts and reasons, and as a result of that, you need to understand what it's doing."
- Kevin Bocek, senior vice president of innovation at CyberArk, told Axios that security teams should create a kill switch for any agents operating on their networks.
- "If that agent should happen to have a bad day, or its many copies happen to have a bad day, then it's simple," Bocek said. "I can say, 'You know what, these agents are no longer authorized.'"
The intrigue: Knowledge of agents' unique security challenges varies across companies, and security companies are hustling to evangelize executives on the need to start securing these agents now as they rapidly deploy them in their environments.
- Shiner said agent security has come up at most of his private dinners with CISOs and developer leaders in recent month. "A lot of companies are just learning the implications from a security perspective and are looking for answers," he added.
- Bocek warned that many security teams don't have a seat in the room as companies discuss their new agent deployment plans.
- "They are not part of those AI agent discussions that are moving fast, to be completely honest," Bocek said.
What to watch: Agent deployment is expected to accelerate over the next year, Jason Clinton, CISO at Anthropic, said during a Coalition for Secure AI panel last week.
- Clinton warned that there could soon be a world where AI agents are managing other AI agents — and every human employee could one day be required to undergo management training to supervise these virtual employees.
- "If you have entry-level folks, help them make the transition to management, because they're going to be managing agents, not managing people," he added.
2. AI leaders push D.C. to ease regulation
Leaders of OpenAI, AMD, CoreWeave and Microsoft pressed lawmakers for minimal regulation and maximum government support to ensure U.S. AI dominance against China.
The big picture: Two years after OpenAI CEO Sam Altman asked lawmakers to regulate emerging generative AI technology, the tone on Capitol Hill has shifted dramatically in favor of scant, if any, regulation.
- The Senate Commerce Committee hearing yesterday covered everything from how AI should interact with children to what chip export rules should be.
"I think some policy is good, but it's easy for it to go too far," Altman said, after being asked by Sen. Brian Schatz (D-Hawaiʻi) if he believes the AI industry can self-regulate.
Context: Altman had meetings with lawmakers on the Hill ahead of the hearing, and on Wednesday he toured OpenAI's Stargate AI training facility in Texas.
What they're saying: "Are we who are working in this industry trying to build machines that are better than people, or are we trying to build machines that will help people become better? Emphatically, it is and needs to be the latter," said Microsoft's Brad Smith.
- Smith focused on the importance of export control rules, which the Trump administration is currently rewriting.
- "Whose technology is most broadly adopted in the rest of world, in this global market ... that is who wins the AI race. Whoever gets there first, it will be difficult to supplant. We need to export with the right rules," he said.
Case in point: Commerce Chair Ted Cruz (R-Texas) repeatedly lambasted EU-style AI regulation and suggested even guidelines for AI could stifle development.
- "Standards is a code word for regulation," he said.
Democrats pressed the witnesses on how Trump's tariff and trade whiplash has impacted their businesses, along with their views on how DOGE cuts of federal research across the government hurts AI advancement.
- "Does anyone truly have confidence that had DOGE been around decades ago, they would not have cut the project that created the internet as an example of wasteful, publicly funded research and development?" Sen. Tammy Duckworth (D-Illinois) asked.
- Microsoft's Smith said keeping public-private partnerships for innovative research is key: "We should never take this for granted. It is the foundation for the country's technological leadership."
The bottom line: It's a new day for AI companies in Washington. Safety, civil rights and moving slowly are out; beating China, dissing Europe and leading the world are in.
3. Training data
- Apple is working on new chips to power its AI servers and its forthcoming smart glasses, per sources. (Bloomberg)
- Meta named former Google DeepMind director Robert Fergus to lead its Fundamental AI Research (FAIR) lab. Fergus, who previously worked at Meta, replaces Joelle Pineau, who announced her departure last month. (Bloomberg)
- An avatar of Agatha Christie is "teaching" an online writing class. (NYT)
4. + This
If you've ever seen the Pixar lamp and thought, I want one of those, you're in luck. Lego announced its buildable version of the Luxo Jr. is coming June 1. The 613-piece set will set you back $69.99.
Thanks to Scott Rosenberg and Megan Morrone for editing this newsletter and Matt Piper for copy editing.
Sign up for Axios AI+



/2025/05/02/1746208363972.gif?w=3840)


