Delinea reporting that confidence in India’s ability to secure AI is running ahead of identity governance reality highlights a familiar problem for security leaders: optimism about AI adoption is expanding faster than the privileged access controls needed to make that adoption safe. For CISOs, the gap is fundamentally a privileged access management (PAM) issue.
AI systems do not merely process information. They invoke APIs, access cloud consoles, query sensitive data and sometimes initiate operational changes. When those actions are not tied to a governed identity, organisations can have strong confidence in their AI strategy while lacking basic visibility into which agents, service accounts or operators can reach privileged systems. That disconnect turns AI enthusiasm into an access-risk multiplier.
The first control challenge is identity inventory. PAM programmes traditionally focused on administrators and high-value human accounts, but AI adoption creates a growing population of non-human actors. Each agent may have credentials, delegated permissions, tokens and pathways into infrastructure. Without discovery and ownership metadata, security teams cannot determine whether an identity is still required, whether its privileges are excessive or whether its activity is being reviewed.
The second challenge is privilege design. AI workloads often begin with broad permissions because teams are moving quickly and do not yet understand every action an agent will need to perform. A modern PAM architecture should replace that standing access with just-in-time elevation, short-lived credentials and explicit approval for high-impact actions. Privileged account security is strongest when access is granted for a defined task and automatically revoked when the task ends.
Session management also becomes more important. Recording and analysing human administrator sessions is no longer enough; PAM teams need usable telemetry for automated actions, including the initiating identity, requested operation, target resource, policy decision and resulting change. That evidence supports incident response and gives governance teams a defensible audit trail for AI-related access.
For Indian enterprises scaling AI, the practical lesson is to treat PAM as an enabling control rather than a deployment that follows innovation. Confidence in AI security should be measured against the organisation’s ability to discover privileged identities, constrain their actions and prove what happened after every sensitive operation.
Source: This Week India