Spencer Young, SVP International at Delinea: “The most impressive AI demonstrations typically involve a clearly defined task in a controlled environment”

Spencer Young has seen a thing or two when it comes to businesses building and deploy software. With his three-decade career spanning hardware, networks, software and cybersecurity, his pragmatic approach makes him perfectly suited for his role as Senior Vice President at Delinea. Now, he’s helping organisations in highly regulated industries address the inevitable security challenges they currently face.

He’s now the 11th interviewee in our Conversations on AI series. For Spencer, when it comes to AI implementation, the question is not about whether AI can perform a task, but rather what happens when it is given permission to act without human supervision. He believes the industry overestimates how quickly AI will replace already well established applications, given how much messier real world operations are compared to the pristine and controlled environments that AI demonstrations typically exist in.

All of which is neatly summarised in one quote: “human judgment will always remain essential”.

Despite human judgment remaining so critical, Spencer believes that the industry may be underestimating a more fundamental change: the capability for software to meaningfully act rather than simply report. Often this ability means AI agents are able to “query a database and change a configuration or move information between several systems in seconds,” a pace that’s simply too fast for humans to review every step.

That speed is precisely why Spencer believes AI adoption needs to be accompanied by a more appropriately disciplined approach to security. While most often conversation is largely dominated by which model to use, Spencer points out that this is “only one part of the equation”. The real risk, he explains, is determined by “the data it can reach, what permissions it has and the actions it is authorised to take”. This leaves AI as perfectly capable of low-risk, repetitive work that is ripe for automation, but the higher-impact decisions need to retain human involvement.

So, while the ability for AI to act autonomously could well be transformative, it also raises questions about how wide-reaching that transformation can realistically be. Which takes us neatly to the topic of overestimating AI’s capabilities…

Everyone says AI is transforming software, but where do you believe the industry is still overestimating its impact and where is it underestimating it?

I think the industry is slightly overestimating just how quickly AI will replace entire applications, established workflows and human decision-making. The most impressive AI demonstrations typically involve a clearly defined task in a controlled environment. Enterprise software sits in a much messier world given there are higher expectations, regulatory requirements, legacy systems and decisions that carry serious consequences. That is all to say that human judgment will always remain essential.

In my view, what the industry is underestimating about AI is more serious; it’s the shift from systems that provide information to systems that can take action. An AI agent can query a database and change a configuration or move information between several systems  in seconds. It happens so fast the humans simply cannot review every step, and that changes the security model to a worrying degree. What seems to be overlooked is that an agent is effectively a new digital identity, with permissions and access that need to be governed as carefully as those of an employee or administrator.

Much of the current industry conversation has been about what AI can create, but far less of that time is spent considering what it should actually be permitted to do.

 The transformative benefits of autonomous AI are huge, they can only be fully realised if the technology is deployed responsibly and with carefully controlled permission. The real transformation will come from AI being embedded across software and quietly carrying out more of the more behind the scene work. At the same time, this will amplify the importance of identity security.

What is the biggest misconception enterprise customers still have about adopting AI within business-critical software?

Most people think that choosing a reputable AI model automatically makes its use across a business secure. The truth is that the model is only one part of the equation. Once AI is embedded across business-critical software, the level of risk is determined more so by the data it can reach, what permissions it has and the actions it is authorised to take.

Recent high profile incidents of AI from the likes of Meta and OpenAI going “rogue” have shown that an agent does not need malicious intent to cause harm. It may be able to follow exact instructions, but there’s always a risk it might interpret them too broadly, chain tools together in an unexpected way or act on incomplete information. If the technology has continuous access to sensitive systems, the risk is that one small error can quickly escalate into a serious incident. When AI agents can operate at speeds faster than a human can even think, taking hundreds of actions before a security team has time to respond, it’s especially important that their access is carefully controlled.

Across the industry, there’s also a clear gap between how prepared organisations feel and the controls they actually have in place. Our recent research found that 87% of organisations believe their identity security is ready for AI-driven automation, yet nearly half of those acknowledge that their governance around AI identities remains inadequate. This has created a paradox whereby businesses are moving quickly from experimentation to full-scale deployment, but their security controls aren’t keeping pace. In turn, this leaves organisations are risk of agents gaining excessive access, with the capability of causing large scale security incidents without security teams even realising.

What has been the hardest challenge in bringing AI capabilities into your products? Technology, data quality, customer trust, regulation, pricing or something else?

The hardest challenge is earning customer trust, but technology and data quality sit within that. In identity security, an AI output can influence whether someone gains access to a sensitive system or whether an activity is treated as a potential threat. A response that sounds convincing is simply not enough. It needs to be accurate, explainable and supported by clear evidence.

That approach has been instrumental in shaping how we implement AI in our platform. Our focus is based on practical use cases like evidence-based access decisions, identifying unusual or risky activity and helping security teams to review privileged sessions more efficiently. The end goal is to give teams better information and help them to make decisions at a quicker rate without impacting their level of control.

Trust also comes from being disciplined about where we allow AI to act autonomously. For example, lower-risk, repetitive work can often be automated safely without too much human oversight. However, higher-risk decision making should always have a Human in the Loop based approach so that someone is there to review the evidence or approve the action. Bringing AI into a security product involves a lot more than technical accuracy alone. It requires transparency, governance and a design that allows customers to question or override an output when necessary. In my view, this is what build genuine customer trust in a product whilst allowing organisations to benefit from the speed and efficiency that AI can deliver.

There’s growing discussion around AI agents replacing traditional software workflows. Do you see the future as applications becoming collections of intelligent agents, or will conventional interfaces remain central?

I expect a hybrid future, where AI agents work behind the scenes to gather information and complete routine tasks. However, conventional interfaces will remain central to visibility, oversight and higher impact decisions.

The balance really depends on the task at hand and the level of risk associated with it. For example, an agent arranging a meeting or summarising a document can usually operate with independence, whereas an agent changing a production environment or accessing employee data requires much tighter controls. In those situations, an interface gives people a clear view of what is happening and the control to approve an action and manage workflows.

There’s also a possibility that the role of the interface may change. For example, instead of asking a user to navigate every process manually, software may be able to suggest a proposed outcome and the evidence behind it, so that the agent can do a lot of the more administrative work and the human retains authority over the most consequential steps. From a security perspective, the most important part of all of that is governance. Every agent must have a clear identity, access that reflects the specific task at hand and have a clear record of the steps it took and why. As part of that, organisations will also need to decide which actions they trust agents to carry out autonomously and which ones should go through a more rigorous authorisation process.

My take is that agents should definitely make software more proactive, but that doesn’t remove the need for human involvement or accountability.

How do you balance innovation with responsible AI? Where do you draw the line between moving quickly and ensuring customers can trust the outputs?

At no point can moving quickly mean lowering security standards, given speed and trust are closely connected. Moving quickly allows businesses to launch a capability sooner, but if your customers can’t understand or rely on its outputs, any short-term advantage is lost more or less instantly. For security teams, the stakes are particularly high given any AI-supported decision has the potential to affect access to critical systems.

For me, trustworthy AI means that outputs should be grounded in clear evidence, explainable to another colleague or customer and, most importantly, subject to clear controls. What’s key is that a security team should be able to understand exactly why a recommendation was made, which factors influenced it and what action followed. There also needs to be a reliable audit trail so that an organisation can review the decision and demonstrate accountability.

You mustn’t end up with situations where an output cannot be explained, checked or challenged. Businesses should never underestimate the importance of human review and approval, especially when it comes to higher-impact actions. Trust also depends on being honest about the limitations of the technology. Customers should be aware of when AI is being used and have the ability to question or override its recommendation.

Responsible AI is therefore an ongoing process rather than a one-off assessment before launch. Organisations must monitor how systems perform, test whether their controls are working and be able to adapt quickly as the threat landscape continues to change. That approach allows organisations to keep innovating without expecting customers to trust AI-driven decisions that cannot understand, check or challenge.

If you could give one piece of advice to another SaaS executive planning their AI strategy today, what would it be?

Above all, your AI strategy should start with identity security. Whether an identity belongs to a person, a machine or an AI agent, organisations need to understand and control what it can access, what it can do and whether those permissions are appropriate. The key thing to consider is that controls need to be in full operation when an agent requests access and whilst they are taking action. On top of that, businesses must only give agents access that is required for a certain task, then remove the access as soon as the task ends and immediately bring a human into the loop for approval, particularly for any higher-risk decisions. Being disciplined with those controls from the outset will allow businesses to innovate with more confidence and avoid a costly security retrofit later down the line.

Start with permissions before prompts, and decide what the overall business outcomes are that agents should deliver, which systems and data they genuinely need access to and which resources should remain completely off limits. One thing to keep in mind is that agents are dynamic and can appear, disappear and duplicate quickly. An agent inventory alone will never provide sufficient protection, nor is it really feasible with how quickly they proliferate.

Finally, AI strategy must be seen as a business-wide responsibility given product, security, legal and operational teams all play a unique role in deciding how AI is deployed and governed. As well as this, companywide alignment will give teams the confidence to move more swiftly and accurately given they will know where the boundaries are.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.