Securing AI Agents: Identity, Authorization, and the DPACT Framework
InfoQ, Monday, September 21st, 2026
InfoQ podcast unpacks the DPACT framework for securing autonomous AI agents' identity and authority.
In this InfoQ podcast, guest Sahil Agarwal discusses how AI agents are shifting from passive chatbots to autonomous actors that need real security frameworks, noting teams often chase capability while forgetting identity, accountability, and trust.
He introduces the five-pillar DPACT framework: Delegation (agents act on behalf of users, never impersonating them), Policy, Auditability, Context, and Time-bound authority.
The discussion stresses agents must never impersonate users, to prevent privilege escalation, and recommends incremental governance: inventory agents, add audit trails, separate agent from human identities, and gradually add review for high-impact actions.
Cautionary examples include prompt injection causing unintended code generation and bots issuing unauthorized refunds.