Back to Webinars

Navigating Leadership & Security in the Age of AI

Date Aired: June 12, 2026

What You’ll Learn

Leadership and security in the age of AI are running into an older, unsolved problem: most organizations don't know who actually owns identity. The CISO holds part of it, the product org holds another part, fraud holds a third, and none of their KPIs point in the same direction. Eve Maler, author of Mastering Digital Identity and founder of Venn Factory, joins FusionAuth's Dan Moore to work through that structural failure and what it means now that AI agents are calling APIs at runtime with privilege requirements nobody anticipated. The conversation covers the real difference between intent and authorization, what FusionAuth's AI readiness data shows about organizations that move fast, and why the OAuth scope model that served the API economy is a poor fit for agents that need contextual, purpose-specific access.

Key Takeaways:

  • Ownership of identity is genuinely contested in most enterprises. The CISO, the product org, and the fraud team each hold pieces of it, with KPIs that have little in common. Until someone is accountable for identity as a strategic function with a real backlog and board-relevant metrics, the alignment conversations will stay performative.
  • Treating identity as shared IT infrastructure is what makes every downstream decision harder. Product thinking forces you to treat stakeholders as customers, measure outcomes rather than inputs, and prioritize deliberately. None of that happens naturally when identity belongs to whoever keeps the lights on.
  • The CIAM metrics that get reported upward are usually the easiest to collect, not the most revealing. Authentication success rates are input metrics. Pairing time-on-task with year-over-year fraud rates gives you a compound picture of whether your UX and security posture are trading off against each other or whether you've managed to not compromise one for the other.
  • Not every AI development deserves equal attention. Eve's framework separates trends (real directional shifts), transients (things that look significant but pass), tropes (concepts repeated so often they've lost meaning), and transparents (things so foundational they become invisible). Knowing which category something falls into before you invest saves real engineering time.
  • Intent and authorization are not the same problem. Authorization asks whether an entity is permitted to take an action. Intent asks what the entity actually plans to do with that access. Current authorization frameworks can get more fine-grained, but they cannot solve meaning injection: the ability to describe a harmful action through analogy or indirection in a way a language model parses as benign.
  • AI agents function as most-privileged engines by design. They don't know what they'll need until runtime, and the systems they call were not built with the granularity to scope that access appropriately. The marriage of LLM-driven behavior and the API economy is what creates the privilege explosion, and the OAuth scope model was built for a different problem.
  • FusionAuth's AI readiness data is counterintuitive: organizations with higher AI use experience more security incidents. That's not evidence that AI causes breaches directly; it's evidence that confidence outpaces understanding in organizations moving fast.
  • Fine-grained authorization is inherently application-specific. Salesforce semantics are not Gmail semantics, and no universal answer exists for scoping agent access to a slice of one application. Standards work like Authzen and Rich Authorization Requests (RAR) are building vocabulary for describing those semantics, but adoption depends on application owners deciding it's no longer differentiating to withhold the granularity.
  • Responsible AI innovation resolves into a question of who absorbs the risk. Organizations treating security incidents as the cost of moving fast may not yet grasp how large that cost could get.
View Transcript

Who Should Watch This Webinar?

  • CISOs
  • CTOs
  • CIOs
  • Product managers (CIAM ownership)
  • Identity architects
  • Platform engineers
  • Fraud and risk teams

Topics Discussed:

  • Identity ownership fragmentation across security, product, and fraud teams
  • Identity as product vs. shared IT infrastructure
  • CIAM outcome metrics vs. input metrics
  • Framework for classifying AI developments as trends, transients, tropes, or transparents
  • Intent-based access and why it differs structurally from fine-grained authorization
  • AI agents, privilege explosion, and the limits of OAuth scopes
  • FusionAuth AI readiness data and the Dunning-Kruger effect in AI adoption
  • Authzen and Rich Authorization Requests (RAR) as emerging vocabulary for fine-grained access
  • Responsible AI innovation and organizational risk tolerance

Speakers:

Eve Maler Photo
Eve Maler
Author, Founder and President of Venn Factory
Eve Maler is one of the most influential figures in digital identity. She co-invented SAML, XML, and UMA, standards that power identity systems across the internet every day. As a former Forrester Research security analyst and CTO of ForgeRock, she's examined identity from every angle: technical architecture, market dynamics, and board-level strategy. She provided expert testimony on API security to the US Department of Health and Human Services and advised the UK Open Banking initiative on technology adoption. Her book, Mastering Digital Identity: From Risk to Revenue, reframes identity as a business advantage rather than an IT burden. Eve speaks regularly at Identiverse, KuppingerCole events, and SecureWorld, always with a consistent message: identity done right isn't a cost, it's a capability.
Dan Moore Photo
Dan Moore
Sr. Director of CIAM Strategy, FusionAuth
Dan Moore has spent his career across the full stack of software leadership, from back-end developer and engineering manager to CTO and AWS certification instructor at organizations including Oracle and Culture Foundry. He holds AWS and identity certifications and has contributed to 97 Things Every Cloud Engineer Should Know. His speaking reflects where his interests have landed: Identiverse sessions on CIAM, OAuth compliance, and decentralized authentication; Devnexus workshops on enterprise authentication and microservice architectures; and webinars on passkeys, modern MFA, and identity challenges in agentic AI workflows. He's also been a featured guest on Corey Quinn's Screaming in the Cloud.
Featured Ebook
The 2026 State of AI and Identity Report
get ebook
The 2026 State of AI and Identity Report cover
Share this post
Watch  On-Demand
Subscribe to The FusionAuth Newsletter
Get updates on techniques, technical guides, and the latest product innovations coming from FusionAuth.