< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Identity management and passwordless tech address AI and credential risks

Cybersecurity experts are highlighting the evolving risks associated with traditional authentication and the rise of AI-driven challenges. Data from the Verizon Data Breach Investigations Report indicates that compromised credentials played a role in approximately 39 percent of investigated security incidents, positioning passwords as a primary vulnerability in modern digital environments.

To mitigate these risks, there is a growing emphasis on transitioning toward passwordless authentication, such as passkeys and platform-bound credentials. These methods replace shared secrets with cryptographic proofs managed by devices, which helps secure distributed SaaS environments and hybrid workforces.

In the context of AI, the challenge of ‘tokenmaxxing’—the management of high token consumption by AI agents—requires robust Identity and Access Management (IAM). Rather than relying on gateways to act as ‘token police’ by limiting usage after the fact, experts suggest using IAM to enforce the principle of least privilege. By restricting AI agents to specific tools and data through Model Context Protocol (MCP) servers from the outset, organizations can better control both security risks and the costs associated with token consumption.

Entities

Auth0 · OKTA · Verizon