As agencies adopt AI and zero trust, identity management must balance security, access and oversight in hybrid clouds, Ping Identity’s public sector CTO says.
As federal agencies modernize their IT environments and expand their use of artificial intelligence, identity management is becoming increasingly important for balancing security with seamless access.
Kelvin Brewer, public sector field chief technology officer at Ping Identity, said during Federal News Network’s Cloud Exchange 2026 that agencies need to protect their systems and data without creating unnecessary barriers for employees and the customers they serve.
“It is so important for identity to be an enabler that allows people to be productive, allows people to accomplish what they’re trying to do when the risk is low,” Brewer said.
“When the risk is medium or high, then you increase friction. You find ways to identify what kind of risk it is — whether it’s a threat actor or just somebody who’s got bad intent with what they’re trying to accomplish. And if that’s the case, then you need to increase the friction or block people. That’s really the balance that identity technology needs to maintain, that idea of taking away friction for people that are trusted, while still blocking those transactions that are too risky.”
Increasing security, reducing frictionAs agencies modernize their systems, Brewer said they should adopt identity solutions that eliminate unnecessary friction.
“The biggest challenge is being able to easily orchestrate and change processes to enable an agency to adjust their identity flows at any time based on new requirements, based on new technologies, based on the ability to eliminate requirements that may have changed,” he said. “Because as technology changes, as people change, as the threats change, it’s being able to pivot quickly. Those are the tenets that I would say are so important when you’re evaluating an identity solution.”
The rise of artificial intelligence is creating new challenges for identity and access management. Brewer said organizations need to begin treating AI agents as identities that require governance and oversight.
Brewer said agencies should establish clear accountability structures and guardrails before allowing AI agents to perform actions on behalf of employees.
“We suggest that you approach agents as a delegated model, that a user has to be involved to delegate authority to an agent for the agent to do things,” he said.
That approach ensures agencies maintain visibility and control over AI-driven actions. Brewer said that oversight is crucial to any AI deployment.
“If you take an agent and make it a first-class citizen and put in a process where somebody has to manage it, somebody has to approve its authority and take responsibility for what that agent does, then it changes the landscape,” he said. “There is no place for rogue agents, for agents that just do stuff without somebody’s oversight.”
Aligning AI and zero trustThe emergence of AI agents is also causing agencies to take a closer look at their zero trust architectures.
“AI agents are bringing us to the point where we’re looking more closely at what the principles of least privilege really mean, what a zero trust framework really can do for us in these circumstances,” Brewer said. “We need to have meaningful ways to measure whether or not our zero trust architecture is actually doing its job.”
That includes determining whether security controls are effectively stopping malicious activity while preserving user access.
“Is it actually catching what it needs to catch, preventing the bad actors while still allowing for users to get access to what they need to get access to,” Brewer said. “That zero trust framework, the very first pillar is identity. And when you’re talking about that zero trust framework, identity is going to be that front door.
As agencies explore agentic AI capabilities, Brewer said industry has a vital role to play in helping government organizations deploy the technology securely. That includes helping to identify AI agents, apply delegated permissions and establish strict limits around access.
As government agencies continue integrating AI into mission operations, Brewer said identity will remain the critical foundation for securing those capabilities while enabling innovation, and agencies will need flexible identity architectures capable of supporting a wide range of emerging technologies.
Discover more articles and videos now on the Cloud Exchange event page.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Cloud Exchange 2026: Google Public Sector’s Cameron Groves on how AI agents are reshaping government workflows | 0 | 5 | 18-06-2026 |
| 2 | Cloud Exchange 2026: Salesforce’s Robert Lindsley on delivering connected digital experiences across government | 0 | 5 | 18-06-2026 |
| 3 | Cloud Exchange 2026: Wiz’s Chris Saunders on controlling shadow AI | 0 | 5 | 18-06-2026 |
| 4 | Cloud Exchange 2026: Red Hat’s Michael Epley on building resilient AI architectures | 0 | 5 | 18-06-2026 |
| 5 | Cloud Exchange 2026: Splunk’s Jonathan Gines on tackling post-migration challenges | 0 | 5 | 18-06-2026 |
| 6 | How IAM providers are preparing for agentic AI | 0 | 5 | 29-06-2026 |
| 7 | AuthZEN at Identiverse 2026: authorization in the agent era | 0 | 5 | 14-07-2026 |
| 8 | Call for Participation: Demonstrate MCP-based AI agent security with open identity standards | 0 | 5 | 14-07-2026 |
| 9 | Билибино: Вечер 31 окт, Ср | 0 | 0 | 30-10-2018 |
| 10 | Рецепт засoлки кpаснoй pыбы 🔥 Ингpидиенты: Κpacнaя pыбa - 500-600 ... | 0 | 0 | 21-02-2025 |