TL;DR: Tumult Labs operationalised differential privacy for sensitive analytics, with mathematical guarantees, privacy accounting, and large-scale Spark deployments, but its own scope stops short of authentication, authorisation, directory sync, and audit trails needed for production AI agent systems, according to WorkOS. Privacy protection and identity control solve different problems, so teams building agents still need the latter first.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Tumult Labs: Differential Privacy for AI Agents”.
Key questions
Q: What fails when teams treat differential privacy as a substitute for AI agent identity controls?
A: The control that fails is identity governance, not statistical privacy.
Q: Why do AI agents still need authorization if their workloads run on encrypted data?
A: Because authorization decides what the agent can query, modify, or export, and encryption does not make that decision for you.
Q: How do security teams know whether an AI agent control stack is actually working?
A: Look for three things: every agent has a traceable identity, permissions are narrow enough to explain in operational terms, and actions can be audited end to end.
Practitioner guidance
- Separate privacy controls from identity controls Document which AI agent risks are about inference, which are about access, and which require auditability so controls are not overloaded with the wrong job.
- Require authenticated agent identities Ensure every production agent presents a verifiable identity that can be tied to a directory, service account, or delegated principal before it touches sensitive data.
- Scope permissions before deployment Define the minimum action set each agent needs, and reject designs that rely on privacy guarantees to compensate for broad or ambiguous access.
Bottom line: Differential privacy protects sensitive analysis, but it does not govern AI agent identity, access, or accountability.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privacy is not identity governance. Differential privacy answers how much information a dataset can reveal, not who may access it or how their actions are governed. For AI agents, that gap is decisive because the control failure is not disclosure alone, it is unmanaged execution by an identified or delegated actor. Practitioners should treat privacy as one layer in a broader identity security stack, not as a replacement for it.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations prioritise identity governance before expanding agentic AI?
A: Yes. Organisations should establish ownership, least privilege, monitoring, and revocation for machine identities before broadening agentic AI use. Without those controls, each new agent can multiply blast radius and create shadow access that is hard to unwind after an incident.
👉 Read our full editorial: Differential privacy for AI agents does not replace identity controls