RSA Thursday | Identity Security Series Issue #15 | Identity Security in the AI Era: How Is AI Transforming Identity Security?
Phishing messages used to be easier to spot. A grammatical error. An odd phrase. A tone that did not sound like the sender.
Today, AI can mimic an executive's writing style in seconds, generate targeted messages and make social engineering far more convincing.
But AI is not just a tool for attackers. The same technology can help security teams analyze millions of signals, identify relationships, detect abnormal behavior and evaluate identity risk more dynamically.
AI is therefore changing identity security in two ways:
Attacks are getting smarter. Defense must get smarter too.
AI Is Scaling Social Engineering
Trust is a core element of social engineering. The more an attacker knows about a target, the more convincing the attack can become.
Generative AI accelerates this process. Attackers can now:
Create targeted phishing messages
Mimic an organization's tone of voice
Generate different scenarios for many users
Adapt messages naturally across languages
Build more convincing fake conversations
Strengthen attacks with voice cloning and deepfakes
As a result, defenses that rely only on recognizing suspicious-looking messages are increasingly challenged.
An attack may no longer look suspicious.
Knowing the Identity Is Not Enough. Context Matters.
Traditional authentication often focused on a few checks: Is the password correct? Was MFA completed? Is the device registered?
Modern attacks, however, can pass some of these checks by involving the legitimate user.
Identity security therefore needs a broader context: the user's usual working hours, the devices they use, the applications they access, location patterns, how they use privileges, and their authentication history and habits. Together, these signals create a behavioral picture of the identity.
AI and machine learning can identify correlations and anomalies across these signals that would be difficult for people to spot.
The question is no longer only "Are the credentials correct?"
It is also: "Is this access actually normal for this identity?"

From Static Policies to Dynamic Risk
Access policies have often been static. A user in a particular group can access a particular application. Risk, however, is not static.
Two attempts by the same user to access the same application can carry very different levels of risk.
Access from a familiar device during normal working hours may be low risk. Access to a critical system from a previously unseen device, in an unusual location and at an unusual time, may require a different assessment.
AI-assisted approaches can combine these signals to support more dynamic risk decisions. As risk rises:
Additional authentication may be required
Further verification may be requested
Access may be restricted
The session may be reassessed
The security team may be alerted
Access policies can therefore respond to circumstances as well as identity.
Should AI Make Every Decision?
As AI's role in security grows, an important question arises: should security decisions be left entirely to AI?
No.
AI is a powerful tool for analysis and decision support, but it must operate within clear policies and governance frameworks.
An incorrect risk assessment does not merely create a false alarm. It could block a critical user from doing their job or mistakenly treat risky access as trustworthy.
The modern approach therefore combines:
AI + Policy + Context + Human Oversight
The goal is not to remove people from decision-making, but to help them evaluate many more signals, much faster.
AI Agents Are Also Becoming an Identity Challenge
AI is no longer just a technology that performs analysis. AI systems are increasingly becoming actors that perform tasks and hold identities of their own.
AI agents can connect to applications, make API calls, access enterprise data, initiate workflows and perform actions on systems.
This makes the non-human identity challenge discussed in Issue #13 even more critical. For an AI agent, organizations must clearly manage:
Which identity it operates under
Which resources it can access
What privileges it has
What actions it performs
Who approved its access
As autonomy grows, controlling identities and privileges becomes even more important.
Trust Is Being Redefined in the AI Era
Correct credentials alone are not enough. A previously seen device alone is not enough. An AI agent created by the organization should not automatically receive unlimited access.
Trust is becoming a dynamic decision that requires ongoing evaluation. Identity, device, behavior, access, risk and context must be considered together, continuously.
AI can make this evaluation faster and more scalable. But the underlying principle remains the same:
Do not assume trust. Evaluate it continuously.
When Attackers Use AI, Defense Must Adapt
As attacks become faster, more personalized and more scalable, static controls alone are not enough. Defenses must understand changing behavior and risk. The identity security approach of the future combines:
Strong Authentication + Passwordless + Adaptive Authentication + Identity Threat Detection + Identity Governance + AI-Assisted Risk Analysis
These capabilities need to work together as a whole. The goal is not to block every access attempt.
It is to place the right level of trust in the right identity under the right circumstances.
Key Takeaway
AI is changing both sides of identity security.
Attackers can make social engineering more personalized and scalable, while security teams can use AI and machine learning to analyze more signals and identify risk earlier.
The central question remains unchanged:
"Can this identity really be trusted?"
The answer must now be evaluated continuously, through identity, device, behavior and access context, not just at login.
Zero Second | RSA – Identity Security.
RSA Thursday | Identity Security Series Issue #15, prepared by Zero Second.





















Comments