AI‐dentity Theft

George Finney, Zach Vinduska · 2025

Chapter 8, “AI-dentity Theft,” delves into the complex relationship between artificial intelligence, cybersecurity, and regulatory compliance. Through dynamic dialogue and real-world analogies, the chapter emphasizes the urgent need for organizations to adopt a Zero Trust framework in the AI era. It critiques the limitations of existing standards like NIST when applied to agentic AI systems and highlights the emerging threats posed by deepfakes, data oversharing, and nonhuman identities. Using a vivid restaurant analogy, the chapter explores how AI could be regulated similarly to food safety, underscoring issues like data hygiene, identity verification, and ethical usage. It also introduces evolving global frameworks such as the EU AI Act and ISO 42001, stressing the need for adaptive, risk-based governance. Ultimately, the chapter argues that AI's transformative potential can only be harnessed securely through proactive governance, transparency, and strong identity management—all grounded in Zero Trust principles.

Read the paper · More papers on PaperTik