#443 - Ghosts in the Machine with John Huyette and Omer Arshed @idacpodcast
#443 - Ghosts in the Machine with John Huyette and Omer Arshed  @idacpodcast
Uploaded August 2026 | Updated September 2026, 2 weeks ago
Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.






5 Laws of AI Risk: linkedin.com/feed/update/urn:li:activity:7487942457075257344


Connect with John: linkedin.com/in/john-huyette-1373906


Connect with Omer: linkedin.com/in/omerarshed














Connect with us on LinkedIn:






Jim McDonald: linkedin.com/in/jimmcdonaldpmp






Jeff Steadman: linkedin.com/in/jeffsteadman






Visit the show on the web at idacpodcast.com










Timestamps






00:00 Introduction, 3D printing, and conference updates


06:58 Introducing John Huyette and Omer Arshed


07:52 John’s path from technology risk to AI risk


12:11 Omer’s identity origin story


13:43 The five laws for managing AI risk


18:00 What “ghosts in the machine” means for identity


20:17 Governability and ownership of AI identities


25:17 Do you know what has access to what?


29:43 Applying decades of IAM lessons to AI


32:35 Lineage and integrity


35:20 Building an AI bill of materials


37:12 Trust boundaries and external data


38:36 Prompt injection and untrusted content


42:48 Applying zero trust principles to AI agents


47:26 Authority containment


49:56 PAM, least privilege, and just-in-time agent access


56:22 Human impact and accountability


58:41 Is agentic AI really a new identity problem?


01:02:35 Starting with lower-risk AI use cases


01:04:21 Where organizations should start


01:05:07 Shadow AI and zombie accounts


01:07:09 What excuses would an AI give during an access review?


01:12:20 Wrap-up










Keywords






IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring
#443 - Ghosts in the Machine with John Huyette and Omer ArshedAI, Tokens, and Identity Software: The Future Explained #shortsRome Explores IAM Identity Trends: Whats Next? #shortsAutomated Evidence: The Future of Permissions #shortsAI Wont Steal Jobs, Itll CREATE Them! Heres How #shortsAI Policy Evaluation and Action Suggestions #shortsReal-Time AI Threat Detection & Security #shortsNew Certification Program for Shared Signals & KAPE! #shortsBeyond Technical Skills: What Really Matters #shortsCasino Gambling: Risk Assessment vs. Fun #shortsCyber Attack Simulation: Defend a Nation in 30 Minutes! #shortsAgent like a child? Spending $2,000? #shorts
Identity at the Center |

#443 - Ghosts in the Machine with John Huyette and Omer Arshed

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER