As Black Hat USA 2026 approaches, the conversation around identity security is undergoing its most significant shift in two decades. For years, “identity is the new perimeter” was the guiding principle for defending infrastructure — but the rise of autonomous AI agents operating at machine speed, in parallel, and non-deterministically is forcing security leaders to rethink that assumption entirely. Few executives are better positioned to speak to this transition than Ev Kontsevoy, Co-founder and CEO of Teleport, whose Infrastructure Identity platform already secures more than 650 customers spanning cloud hyperscalers, autonomous fleets, ecommerce marketplaces, and payment providers.
In this pre-show Q&A with VMblog, Kontsevoy makes the case that static credentials, vaulted passwords, and periodic access reviews — the tools that have governed human and machine identities for years — are fundamentally unequipped for an agentic era where non-human identities already outnumber human ones. He unpacks Teleport’s approach to what he calls “agent trust,” built on three principles the company outlines in its own research: enforcing continuously, bounding collective autonomy, and assuming misalignment. Ahead of the show floor, Kontsevoy previews how capabilities like trusted runtimes, session risk scoring, and agentic classifiers are designed to contain AI agents in real time — addressing a threat model where an agent can stay entirely within its permissions and still become the vector for catastrophic, undetectable compromise.
++
VMblog: For readers who may not be familiar, give us the elevator pitch — who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.
Ev Kontsevoy: Teleport establishes a unified identity layer for modern infrastructure. Within this unified identity layer, every actor in your environment — humans, machines, workloads, and now AI agents — receives a cryptographic identity anchored to a hardware root of trust, with just-in-time privileges, and governed by policy that can reason about what each actor can do within this environment.
This approach, which eliminates static credentials and standing privileges, and all of the attendant risk and complexity of fragmented identity systems, allows our customers to remove complexity for their engineering teams while simultaneously improving resiliency of infrastructure operations.
Now, as we set forth into the agentic era, we are extending zero trust principles to accommodate the behavioral characteristics of agents. Zero trust principles – verify explicitly, least privilege, assume breach — have been durable for the last two decades for machines and humans, but AI agents break the foundational underlying assumptions of speed and scale and autonomy – they act continuously, at speed, in parallel, and non-deterministically.
We are now extending our platform, grounded in zero trust principles, to the agentic trust principles needed to govern these new actors, with capabilities such as trusted runtimes, session summaries, and agentic classifiers that enable continuous enforcement and protection against misalignment. It is not enough to verify an agentic identity – you now need to be able to bound its behavior and ensure in real time that its behavior is consistent with its intended objective.
Teleport serves more than 650 customers with its Infrastructure Identity platform, from GPU/cloud hyperscalers and datacenters, to autonomous fleets, ecommerce marketplaces, payment providers, and more.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors — whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else — is your solution most directly built to address?
Kontsevoy: Teleport is designed architecturally to protect against many of the common identity threat vectors, enabling defense in depth for infrastructure even when identities are compromised. Identities that are backed cryptographically cannot be lost, stolen, or phished, while access requests with least privileges that expire prevent lateral movement, shrink the blast radius, and eliminate policy violations. These capabilities, combined with other features such as MFA for administrative actions, thwart actors who are targeting identity as an entry point to sensitive data and prevent violations from occurring due to human error.
With the rapid adoption of AI, companies must now protect against a new set of potential failure modes. Agents can act in misalignment from their intended objectives. Swarms of agents might make autonomous decisions that are individually permitted but collectively destructive. Or, agents might break free from intended boundaries and gain access to sensitive data or take unintended actions.
At Black Hat, we’ll be showing the operational harness we are developing to protect against these new types of identity threats. In these cases, the consequences may not be the result of an outside threat actor, but rather an unintended outcome of an agentic deployment.
We will be showing how trusted runtimes, which continuously enforce boundaries of identity and privileges, couple with session timelines, risk scoring, and agentic classifiers to introduce the operational harness needed to ensure agent containment.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Kontsevoy: We are seeing companies often embarking on agentic deployments before they have implemented a strong zero trust foundation, or are actually giving agents more privileges than they would give a human responsible for the same task. Agents are able to move at speed and with autonomy, so an environment that exposes static credentials or that permits unintended lateral movement may see agent-related security incidents as a result.
Implementing a solid zero trust foundation, based on infrastructure identity, is an important step towards creating a secure environment for agentic deployments. This eliminates the static credentials and standing privileges that agents can inadvertently exploit, and creates a unified identity layer where you can properly reason about policy between the human, machine, and agentic actors in your environment.
We are then addressing the unique characteristics of agents with our trusted runtime solution – Beams – and Identity Security for AI in order to bound what autonomous actors can do in the environment, continuously enforce and monitor their behavior, and flag unintended drift from the original objective.
VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?
Kontsevoy: So first, let me explain what AI-native security should NOT mean.
It should not mean an AI silo, where you are adopting yet another fragmented identity solution that you then have to integrate with different pieces of your identity architecture.
Your AI solution should also not be bolted onto a system that is designed for the way humans operate. Most companies, for example, use observability as a way to identity security breaches “after the fact.” Agents move quickly. Flagging and intervening in them manually is too slow.
AI-native security means security that is designed for how agents behave, for the specific types of failure modes that they can introduce, that is architecturally connected to your other first-class actors in a unified identity layer. You have to have your humans, machines, and agents all represented cryptographically as first-class actors within the same system in order to be able to control and contain what they can do in your infrastructure.
VMblog: Identity has become the new perimeter — and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?
Kontsevoy: “Identity is the new perimeter” is a concept that works well for humans and machines – if you implement a zero trust foundation such as infrastructure identity, you can implement defense in depth where identities can no longer be compromised by common “breach and pivot” or impersonation strategies.
The dangerous mistake many organizations are still making is trying to protect credentials at all — vaulting passwords, rotating API keys, hoping tokens don’t leak. You don’t protect a credential. You eliminate it. Despite accelerating identity breaches, many companies still have static credentials everywhere. Or, the complexity of access paths may obscure potential pathways for lateral movement. It is critical that companies invest now in a solid zero trust foundation that eliminates these risk vectors from their environments.
In the agentic era, “identity as the new perimeter” may already be a dated concept. Agentic identity and access control now need to be continually enforced, not just verified. In this sense, it is the combination of identity, privileges, actions, and intent governed together with continuous monitoring that is required to ensure that agents are operating according to their original objective. In this sense, “runtime is the new perimeter” might be a better description for how we now need to control and contain agents in the field, not just their identity.
VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?
Kontsevoy: The biggest blind spot isn’t human. You can account for every person in seconds — who’s in Okta, what they’re entitled to, when it gets reviewed. But people are the minority now. The machines, workloads, and agents in your infrastructure outnumber them, carry broader privileges, and get almost none of that scrutiny. Most organizations can’t produce a live inventory of what those non-human identities can actually reach — let alone prove which one took a given action after the fact.
So the real question isn’t who has access. It’s this: right now, which agent can run a raw query against your production database — and if one did, could you even tell which?
The fix is almost boring: put every identity, human or not, in one system governed the same way — so “what can this reach” and “who did that” finally have a single answer.
VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?
Kontsevoy: The thing the industry still isn’t taking seriously: non-human identities used to be predictable. Service accounts, machines — boring by design. Now a fast-growing share of them are agents: non-deterministic, and already outnumbering the humans. They already outnumber human identities, and we still govern them with human-scale habits: static credentials, periodic rotation, point-in-time reviews. That’s straining under microservices already. Autonomous agents will break it.
The failure mode people underestimate: an agent can stay entirely within its privileges, produce nothing anomalous, and still be how your environment gets compromised. A swarm of agents, each acting rationally, converges on a catastrophic outcome — with no log entry that looks wrong. Zero trust says assume breach. It doesn’t tell you what to do when the breach never touches a permission boundary.
That’s the inflection point, and it’s why we wrote “From Zero Trust to Agent Trust.” It lays out three principles for the agentic era: Enforce Continuously, Bound Collective Autonomy, and Assume Misalignment. The third is the one the industry is furthest behind on — designing for the reality that an agent will drift from what you intended, whether through prompt injection or just context shift over time, without ever tripping a traditional control.
Build that foundation now and you’ll be ready when agents hit production at scale. Wait, and you’ll spend 2027 bolting governance onto systems that were never built to carry it.
VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?
Kontsevoy: I was an engineer before I ran a company, so I’ll say this plainly: stop treating security as a tax on velocity
Friction is what creates shadow IT, and shadow IT is where your worst incidents live. Make a developer clear three legacy VPNs and pull a token from a vault every time they debug a production database, and they’ll find a way around it — a still-active SSH key, a static credential hardcoded in a local script, whatever it takes to get the job done. You haven’t bought control. You’ve bought an audit log you’ll never read.
So make the secure path the fastest path. Eliminate static keys, give engineers just-in-time access that’s faster than the workaround, and compliance goes to 100% — not because you enforced it harder, but because you removed the reason to route around it.
The same principle now has to extend to agents. Our Agent Trust framework starts here: Enforce Continuously is about architecture, not written policy an agent can ignore. You can’t tell a non-deterministic actor to comply. You build a runtime where non-compliance is impossible — ephemeral execution, zero standing privileges, communication boundaries enforced in the infrastructure itself. The agent can only do what its environment allows. Full stop. That’s the agentic version of making the secure path the only path.
##






