AI Is an Identity, Not Just a Technology

AI Is an Identity, Not Just a Technology

This is the first post in a twelve-part series about a simple shift: organizations should treat AI not only as software, but as something that performs work. That makes AI a business conversation, not just a technology or cybersecurity one. Before AI is connected to everything, invited into every workflow, or handed the digital equivalent of a master key, it needs a role, an owner, and boundaries.

Let’s Set the Stage

For this series, an identity is anything the organization can recognize and grant access to information, systems, or actions. A user is usually a person; an identity can also be an application, service account, device, API token, automation, or AI agent. That distinction matters because AI often operates through non-human identities that still need the same basic questions answered: what is it, what can it do, who owns it, and when should its access end?

I was at a conference recently where someone framed AI in a way that stuck with me: it is not just another technology to deploy, but something organizations are beginning to “hire” to do work. I liked that framing because it moves the conversation away from tools and features and toward roles, ownership, access, and accountability.

AI is different because it does not just sit there waiting to be used. It can read information, answer questions, draft content, summarize conversations, recommend decisions, and in some cases take action inside business systems. At that point, it starts to look less like a tool and more like a very fast new coworker who does not sleep, does not take lunch, and somehow already knows where the old project files are buried.

Define the Job Before Granting Access

When a person joins an organization, ownership is clear. HR defines the relationship, the manager explains the job, IT provides tools, finance approves budget, legal and compliance set obligations, and the employee receives access, training, supervision, and feedback. AI should start the same way: with a clear job.

Employees do not receive access to everything simply because it would be convenient. A marketing employee does not automatically get payroll data, a developer does not need employee medical records, and a customer service representative should not be reading confidential merger documents between support calls. We understand those boundaries when people are involved.

When an AI platform arrives, the conversation often changes to capabilities: Can it search files, read email, summarize meetings, connect to ticketing systems, or help with code? Those are reasonable questions, but they should come after the more important one: what job is this AI supposed to do?

If an AI has access only because a connector exists, that is not strategy. That is shopping with better branding.

If It Can Act, It Needs Accountability

The word “identity” can sound technical, but the idea is simple. If something can get into company systems, read company information, or act on behalf of the organization, we need to know what it is, what it is allowed to do, who is responsible for it, and how to stop it if something goes wrong.

Once AI can read data, retrieve documents, call an application, send a message, modify a record, or trigger a workflow, it deserves the same kind of accountability we expect for any other worker. It should have a defined owner (Manager), a documented purpose, limited access, monitoring, periodic review, and a clear way to turn it off (Terminate).

AI Makes Poor Boundaries More Expensive

Poorly defined access is not only a cybersecurity problem. It can become a legal, privacy, compliance, customer trust, and financial problem. AI makes those problems more visible because it can search, summarize, compare, and correlate information much faster than a person can.

It can connect financial forecasts with internal strategy documents, compare customer complaints with legal correspondence, or summarize employee information alongside management notes. The issue is not that the AI has bad intentions. The issue is that it is efficient, and efficiency without boundaries can create very expensive surprises.

Instructions Are Not Boundaries

A lot of AI governance focuses on instructions: what users may ask, what the AI may say, and how to prevent bad prompts or outputs. Those controls matter, but they are not enough.

If an AI should not be using acquisition plans, employee records, customer contracts, or sensitive financial data, the stronger control is making sure it cannot reach information its role does not require.

Every AI Needs a Manager and an Offboarding Plan

Employees have managers because someone must be accountable for their work. AI needs ownership for the same reason. Someone must know who approved it, what it is supposed to accomplish, which data it uses, who reviews its results, who responds when it makes a mistake, and who decides whether it should gain new capabilities.

Without a clear owner, AI becomes a shared responsibility that everyone supports and no one manages — usually right up until something breaks.

AI systems will not remain in your environment forever. Vendors will change, projects will end, models will be replaced, and pilots will be abandoned. When an AI service is retired, its access and data connections should be retired too.

That means removing permissions, disconnecting data sources, disabling accounts or keys, reviewing retained information, and preserving records according to policy. In other words, offboard the AI like an employee.

Change the Conversation

The next time someone proposes a new AI deployment, do not begin only with the model, the features, or whether it integrates with everything. Start with better business questions: What job is this AI being hired to do? Who owns the outcome? What information does it need — and what should it never see? What decisions or actions can it influence? How will its access be removed when the work ends?

AI is often described as transformational technology. Inside the business, it increasingly behaves like a worker: it receives access, performs tasks, handles information, communicates with people, and sometimes acts on behalf of the organization. Once we recognize that, the path becomes clearer: define the role, assign an owner, limit access, monitor the work, review the results, and remove access when the role ends. Organizations should stop asking only how to deploy AI and start asking how to onboard it.

In the next post, Your Next Employee Doesn’t Have a Pulse, we will take the employee comparison more literally.