Embracing Digital Transformation

← Embracing Digital Transformation24 jul · 47 min

#370 How to Control AI Agents with Formal Methods and Ephemeral Access

#370 How to Control AI Agents with Formal Methods and Ephemeral Access24 jul47 min

Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.

AI isn’t just generating content anymore — it’s becoming an operational actor inside enterprise systems. Doctor Darren sits down with Ev Kontsevoy to unpack how AI agents, formal methods, ephemeral access, and action-based governance can help technologists and business leaders keep control as automation speeds up and scales out.

## Key Takeaways

- **AI changes the risk model:** fast, probabilistic systems can make mistakes at machine speed, so old “critical vs. non-critical” thinking no longer works.

- **Role-based access control (RBAC) is straining at scale:** as organizations grow, roles multiply faster than employees, making policy management harder to govern.

- **Move from identity-based to action-based control:** define what the business action is, then bind permissions to that action instead of to a long-lived role.

- **Ephemeral access improves security:** grant access only for the duration of the task, then let it disappear when the work is complete.

- **Formal methods matter again:** if AI agents are going to act on infrastructure, workflows need to be precise, verifiable, and impossible to misinterpret.

- **Treat AI like a first-class operating force:** the winners won’t just deploy more AI — they’ll govern it with stronger, more scalable controls.

## Chapters

- **00:00** Opening thoughts on AI risk, speed, and governance

- **02:15** EV’s background in engineering and building for engineers