Logo

Who Let the AI Agents In? Raza Sharif Provides the Identity Check

1 min read
Who Let the AI Agents In? Raza Sharif Provides the Identity Check  image

Artificial intelligence is beginning to move beyond the role of assistant. In more organisations, AI agents are being designed to discover services, communicate across systems, make decisions and execute actions with less direct human involvement. That shift carries enormous promise, but it also unsettles one of cybersecurity’s oldest assumptions: that identity, authority and accountability can be organised primarily around human users.

The next question for enterprise AI is therefore not only what these systems can do, but how they can be trusted to act. Existing security protocols were built for a world of people, devices, applications and defined networks. Autonomous agents introduce a different problem. They need identities that can be verified, boundaries that can be governed and communication that can be trusted across organisations and technologies. This is the terrain in which Raza Al Rehman Sharif’s work has become especially relevant: building the security foundations for an AI ecosystem that is moving faster than the trust models surrounding it.

When Identity Stops Being Human

For decades, cybersecurity has been organised around familiar subjects. A user logs in. A device is recognised. An application requests access. A network boundary is defended. Even as cloud computing, APIs and distributed systems changed the shape of enterprise technology, security still largely assumed that the main actor could be traced back to a human or a known system operating within a managed environment.

Agentic AI complicates that structure. Autonomous agents may operate across tools, data sources and workflows, interacting with systems at speed and scale. They may not simply retrieve information, but initiate actions. In that setting, traditional controls can begin to look incomplete. The question is no longer only whether a person should have access, but whether a machine agent should be trusted to act, under what conditions, on whose authority and with what limits.

Sharif’s work starts from that gap. Rather than treating AI security as an extension of existing practice, he sees it as a shift in the underlying trust model. Applying old controls to new autonomous behaviour may offer temporary comfort, but it does not answer the harder enterprise question: how do organisations govern machine-to-machine decision-making when the agent itself becomes an actor inside the business?

Finding the Fault Line

That question is not theoretical for Sharif. His work has established him as an active contributor to the security of the emerging AI ecosystem through original vulnerability research, secure architecture and industry collaboration. He has discovered and responsibly disclosed multiple Common Vulnerabilities and Exposures affecting AI technologies, including research across Model Context Protocol frameworks, software development kits and enterprise AI infrastructure.

One example is CVE-2026-39313, a critical denial-of-service vulnerability in an MCP framework. In that case, a single oversized HTTP request could exhaust server memory and disrupt AI services. The detail is technical, but the implication is broader. As enterprises begin to rely on AI infrastructure for important workflows, small weaknesses in emerging protocols can carry operational consequence.

This is where Sharif’s approach becomes more than vulnerability discovery. He looks for the architectural weakness that allows the vulnerability to exist in the first place. That distinction matters. A patch may close one opening, but a stronger security model asks why the opening was there, what assumption failed and how the system should be designed differently before similar weaknesses become common across the market.

His background gives that view further weight. Sharif’s career has included work protecting critical national infrastructure, government and global enterprises against advanced cyber threats, including defensive efforts surrounding the Estonia cyber attacks, widely recognised as a defining moment in modern cybersecurity. That experience sits behind his current work in AI: the understanding that new technologies become critical long before the rules around them feel settled.

Building Before the Standard Arrives

The practical expression of that thinking is CyberSecAI, which Sharif founded to address the security problems emerging around agentic AI. Its work includes AgentPass, an AI agent identity platform designed to establish trusted, verifiable identities for autonomous AI agents, and Agentic Enterprise Boundary Architecture, or AEBA, a framework for governing agents operating across enterprise trust boundaries.

The importance of these ideas lies in their timing. Many organisations are still deciding how to deploy AI agents. Sharif is focused on what must be true for those agents to be trusted once they begin operating across systems, departments and organisations. Identity, authorisation, communication and governance cannot remain afterthoughts. They have to be built into the conditions under which AI agents act.

AgentPass addresses one part of that problem by giving autonomous agents a trusted identity model. AEBA addresses another: the boundary problem created when agents move across enterprise environments. Together, they reflect a first-principles approach. Instead of accepting existing security architecture as fixed, Sharif asks what the architecture would need to look like if it were designed for autonomous machine actors from the outset.

The New Discipline of AI Security

Sharif’s work extends beyond his own organisation. As a former project Co-Lead of Artificial Intelligence Security Verification Standard v1.0, he has helped shape practical guidance for secure AI systems. Through advanced AI security advisory and enterprise roadmapping across EMEA, responsible vulnerability disclosure and industry collaboration, he is also contributing to the wider process by which AI security becomes more disciplined, shared and usable with emphasis on AI Accountability as well as forensics grade evidence ledgers to support legal mandates across sovereign regions.

That matters because the AI security field is entering a formative period. Protocols such as MCP and emerging real-time communication technologies are accelerating the adoption of agentic AI, but they are also creating new attack surfaces. The risk is not simply that individual systems may fail. It is that enterprises may scale autonomous AI before they have reliable standards for identity, trust, governance and secure communication.

Sharif frames the challenge by looking back at the trust foundations that made the modern internet usable for human users. Standards such as TLS, OAuth and OpenID Connect helped secure communication, delegated access and digital identity across systems. His argument is that agentic AI now needs an equivalent foundation of its own. Autonomous agents will have to authenticate, authorise, communicate and act across organisational boundaries, but they cannot be governed safely by standards designed for a less autonomous world.

For Sharif, the work is not about slowing AI adoption. It is about making adoption possible with confidence. His leadership sits at the point where technical research, enterprise architecture, open standards and practical implementation meet. In the AI era, trust will not be created by ambition alone. It will have to be engineered into the systems, protocols and boundaries through which autonomous agents operate. CyberSecAI’s relevance lies in working on those foundations now, before they become the risks every organisation is forced to confront later.

For more information, visit: linkedin.com/in/raza-sharif-286a5762

Share this article: