ChannelLife UK - Industry insider news for technology resellers
United Kingdom
Interview: Cloudera says AI agents reshape zero trust

Interview: Cloudera says AI agents reshape zero trust

Thu, 1st Oct 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Cloudera says the rise of agentic AI is forcing enterprises to rethink identity, access controls and data governance as software agents make far more requests than human users and gain access to sensitive systems.

Carolyn Duby, Field CTO and Cyber Security GTM Lead at Cloudera, said security models for AI agents will need to move beyond controls designed primarily for human users. Her work spans real-time data analytics, AI and cybersecurity, helping customers apply Cloudera's platform to business and technical use cases. Duby has more than 30 years of experience across cybersecurity, data and AI, and joined Cloudera in 2021 after roles at Pathfinder Solutions, Dell Secureworks and Hortonworks.

Agent access

"It definitely underscores the need and the imperative for data governance and security. If your data is not secured properly, if you don't have the proper access permissions, you cannot use AI with it. It just won't work," said Carolyn Duby, Field CTO and Cyber Security GTM Lead, Cloudera.

AI agents can operate across systems at a scale and speed beyond human users. They may make far more requests, while many enterprise identity and security tools remain designed around human identities. That raises questions about how agents should be authenticated, what they should be allowed to access and how long those permissions should last.

"Security is going to have to evolve to take into account agents, because if you look at an agent, an agent's going to be making a lot more requests than a human would. A lot of the tools that we have are geared towards human use and human identities, and then looking at agents, agents are going to have different types of identities, and maybe transient ones. You give the agent the identity or the privileges for enough time so that they can do its work, and then you revoke it," said Duby.

Duby described zero trust as a set of security principles rather than a product, with minimal privileges, segmentation, identity and authentication at its core. Those controls become more important when an agent acts on a user's behalf and needs access to information that person is authorised to see.

Cloudera is building agent-focused capabilities into its platform. Its Agent Studio is designed to help customers build and run agents with an audit trail, supporting governed and explainable operations.

Sovereign AI

"I'm a firm believer in sovereign cloud and in being able to have your AI come to your data rather than your data going to the AI, because depending on what kind of data it is, the data is really your secret sauce. A model is just a model, but it's not intellectual property until you give it your data," said Duby.

For organisations handling sensitive or regulated information, keeping AI workloads close to enterprise data can reduce the risks of sending information to third parties. Cloudera supports integration with external AI services, but some use cases are better suited to running on-premises or within an organisation's own cloud environment.

"Whenever you send your data to a third party, it introduces risk, and I'm not saying that you shouldn't use those tools. You can if you want. We have plenty of integration where you can. But if you have use cases that are particularly sensitive, if you have data that needs to have certain requirements with it, then sovereign is really the way to go," added Duby.

Cloudera has customers running AI on-premises in their own data centres or in their own cloud environments, although Duby did not provide a percentage split between sovereign deployments and other approaches.

The location of AI workloads is closely tied to governance. Cloudera's customers span multiple industries and use cases, and security, governance and AI are typically addressed together rather than as separate projects.

Governance first

"You can't do AI without governance. Maybe you could, but the results would not be good," said Duby.

Enterprises still need to link AI investment to business outcomes rather than treat the technology as an end in itself. That means assessing whether AI produces better software, faster delivery, broader capabilities or an improved customer experience while maintaining trust in how systems handle data.

Cloud infrastructure can speed up provisioning, but governance, security checks, certifications and internal approval processes remain. In sectors such as banking, that due diligence can be necessary because software handling critical functions requires extensive review.

"With cloud things certainly go faster from a provisioning standpoint, but you still have all the security and the governance and the checklists and the certifications. The platform has changed, but the processes are the same, if not more," added Duby.

Enterprises therefore face pressure to adopt rapidly changing AI capabilities while working within established risk and compliance frameworks. Customers can begin implementing one technology only for another option to emerge before the first project is complete.

Faster change

"I would say it is, only because the pace at which things are changing," said Duby.

Keeping up with that pace requires sustained technical training across AI, cybersecurity and governance. Duby spends significant time reading, taking training and following developments from security events and organisations such as OWASP. Cloudera also runs an internal enablement programme for Solutions Engineers and other roles.

The ability to research, investigate and adapt is becoming more important as technologies and programming approaches fall out of use. AI can also help manage the volume of new information, although Duby described it as a thought partner rather than simply an accelerator.

The next wave of change may extend beyond generative and agentic AI. Duby pointed to quantum computing as an area she is watching from both a cybersecurity perspective, including quantum encryption, and for its longer-term potential alongside AI. She did not expect a combination of quantum and AI to become mainstream in the next year, but said the field was moving quickly.

Security controls will also need to account for increasingly capable cybersecurity tools. Such systems can be useful, but organisations need to constrain them so they cannot operate beyond their intended boundaries, including through properly secured sandboxes and secure-by-design architectures.

"For me, it's like how do you keep them in their box? How do you secure the sandbox and use them so that you're not going out and hacking another company? Security is more important than ever, having that foundation and being able to really build systems that are secured by design and that are sandboxed correctly," said Duby.