The strategic collaboration between WALLIX and Inria (Institut national de recherche en informatique et en automatique) on trusted AI for identity security highlights an emerging recognition: as machine identities proliferate, the systems that govern them must themselves be trustworthy and auditable. Artificial intelligence is increasingly proposed as a solution to identity security challenges, but AI that operates as a black box cannot be trusted with privileged access decisions.

The partnership addresses a paradox at the heart of modern identity governance. Organisations face exponential growth in machine identities — driven by cloud adoption, containerisation, API proliferation, and now AI agents. The attack surface is too large for traditional manual governance. Yet automation that lacks explainability and auditability creates new risks: if an AI system grants inappropriate access to a non-human identity and that access is later exploited, the question of accountability becomes intractable.

WALLIX’s focus on privileged access management (PAM) and Inria’s research in trusted AI converge on a practical need: machine identity governance requires intelligent automation, but that automation must be interpretable. When an AI system recommends revoking a machine identity or restricting its permissions, security teams need to understand why that recommendation was made. This is particularly critical for non-human identity governance, where the business impact of access changes (application downtime, service disruption) can be severe.

Trusted AI in the context of machine identity governance has several requirements. First, explainability: the system must articulate its reasoning for access decisions in human-understandable terms. Second, auditability: every decision must be logged and traceable, enabling forensic analysis if something goes wrong. Third, verifiability: the model’s outputs must be validated against ground truth before being applied to production systems.

For non-human identity security, the WALLIX-Inria partnership signals that the future of machine identity governance lies not in pure automation or pure manual control, but in human-in-the-loop intelligent systems. As machine identity risks grow, organisations will increasingly rely on AI to identify anomalies, flag risky configurations, and suggest remediation — but only if that AI is transparent enough to be trusted.