TL;DR: AI is compressing code review, deployment, and agent tool use into microseconds, exposing a mismatch between human-paced security controls and machine-speed operations, according to WorkOS’s panel discussion from Enterprise Ready Conference 2025. The result is a governance problem as much as a technical one: identity, authorization, and audit patterns must be rethought for AI-enabled execution.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Security in the Age of AI: Old Problems Meet New Risks”.
Key questions
Q: What breaks when AI agents can make code changes faster than humans can review them?
A: Manual review stops being a meaningful control if it cannot keep pace with change volume.
Q: Why do AI agents change identity and authorization risk more than simple automation does?
A: Because the risk is not only volume, but runtime decision-making.
Q: How should security teams govern employee AI use without blocking productivity?
A: Start with visibility into sanctioned and shadow AI use, then apply runtime policies that inspect intent and context rather than only keywords.
Practitioner guidance
- Map machine-speed workflows to runtime authorization boundaries Identify where AI systems can generate, review, and deploy within the same task chain, then move controls to the point where the tool or action is first granted rather than after execution has started.
- Constrain AI tool chaining by context Define which tools an agent may reach after each prior step so a permitted action cannot automatically unlock a higher-risk one in the same session.
- Separate review from execution authority Make sure code review, deployment approval, and production action are not all available to the same agent path, even if the workflow is highly automated.
Bottom line: AI changes the security problem by compressing action, review, and deployment into one machine-speed sequence that human controls cannot reliably interrupt.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Human-paced identity governance is no longer a safe design assumption. The panel’s most important implication is not that AI introduces new tools, but that it breaks the old assumption that access persists long enough for a human to review it. Access review, approval workflows, and change management were built for observable, interruptible activity. Once execution happens in microseconds, those controls can still exist, but they no longer govern the moment that matters. The practitioner conclusion is that governance has to move upstream to issuance and path constraint.
A question worth separating out:
Q: What does machine-speed AI mean for audit, accountability, and control design?
A: It means audit is still necessary, but not sufficient. Accountability has to be designed into the identity path before execution starts, because post-event logs cannot stop an action that already completed in microseconds. The control model should answer who allowed the action, what context was present, and which next steps were possible from that state.
👉 Read our full editorial: AI security and agent speed are reshaping identity controls