Sikkerhetsfestivalen 2026: AI security is a control problem
27.8.2026, 7 minutes read time
TL; DR: What Sikkerhetsfestivalen 2026 revealed about AI agents, identity, and the growing challenge of keeping enterprise AI under control.

AI agents, identity, and the growing challenge of keeping enterprise AI under control
Sikkerhetsfestivalen (the Security Festival) in Lillehammer, August 24th to 26th 2026, offered a clear view of how the security agenda is changing in 2026. The program covered themes ranging from offensive security, identity, and supplier risk to resilience, national security, AI, and governance, reflecting how difficult it has become to separate cybersecurity from the broader way organizations are run.
The larger theme was control.
Organizations are operating in a more demanding geopolitical environment, relying on increasingly complex technology ecosystems while introducing AI at a pace that existing governance models were never designed to handle.
For security leaders, the practical question is returning to basics: do you know what is operating inside your environment, what it can access, and who is responsible for it?
Security is moving closer to the business core
The concerns of both weaknesses in preventive security, pressure from state-sponsored attackers, and growing dependence on critical technology providers are vulnerabilities that NSM (Norsk Sikkerhetsmyndighet, the Norwegian security authority) continues to warn about, and these themes ran as a red thread through the whole program of Sikkerhetsfestivalen.
National security sessions addressed critical infrastructure and sovereignty, and the Supplier Security track examined technology dependencies.
The Cloud and Security Architecture track gravitated around discussions of cloud concentration and exit strategies, while the Risk and Security Management track focused on turning risk analysis into decisions that improve security in practice.
These may appear to be separate disciplines, but they increasingly lead to the same problems that management needs to handle and be on top of. Leadership and the board need sufficient visibility into their own technology environment to understand where risk sits, who owns it, and which controls can be applied when circumstances change. Agentic AI makes that requirement more urgent than ever.
What happens when software starts doing the work?
Generative AI was initially largely a user tool, now well known through chatbots like Gemini, ChatGPT, Copilot, and Claude. Organizations focused on which of the tools employees were allowed to use, what information they could share, and how AI output should be reviewed.
AI agents are changing the nature of the discussion because software can now participate directly in business processes. An agent can receive an objective, access information, call other systems, use tools, and carry out actions.
As these capabilities enter ordinary workflows, a new class of digital worker is being created, and this is where Fortytwo entered the discussion at Sikkerhetsfestivalen. Our session, Do you know how many workers you have?, examined what happens when organizations start accumulating agents, agent-like workflows, automations, and non-human identities faster than their governance structures can track them.
The overarching question is deliberately simple because the answer often is not. Most companies can produce a list of their employees and usually maintain inventories of applications and formal supplier relationships.
AI agents are not being controlled in the same way, and they emerge through Copilot environments, low-code platforms, integrations, and business-led automation on technologies that have already been approved by the business.
The platform these agents are built from may be sanctioned and well-known by the company, while the things being built on them remain largely invisible. That creates a new form of organizational blind spot that is no longer only about shadow IT: A whole new discipline of shadow engineering is arising, causing trouble.
Visibility comes before control
A useful way to approach the problem is to separate visibility, understanding, and control.
An organization first needs to know which AI applications, agents, automations, and agent-like workflows exist. The next step is to gather enough context to understand what all of them do, which systems they interact with, and who is responsible for them.
Control is not possible until the organization can govern the AI agent’s access, trace their actions, and intervene when their purpose or behavior changes.
This closely mirrors the messaging of the Identity track at Sikkerhetsfestivalen, where AI agents were discussed as a growing part of the workforce and as a new challenge for governance, visibility, and traceability. The connection to identity is fundamental. Any agent that performs useful work needs permission to act within set boundaries, as it may need to retrieve customer information, access a business application, call an API, or take an action on behalf of a user. Somewhere in that chain is an identity.
AI Universe
The way to control, build, and innovate with AI in a controlled, secure way.
Identity is an intimate part of AI governance
Once AI agents begin acting inside enterprise systems, identity and access management become part of the AI control model.
Organizations need to know which identity an agent uses, which permissions it holds, and whether those permissions match its purpose. If this has not been decided, and if there is no control, the agent automatically inherits the identity and broad permissions of its maker. There should be a joiner-mover-leaver logic surrounding the agent, and changes to the agent should be reflected in its access.
Retirement and decommissioning of an agent should lead to removal of all permissions and access, just like with a human terminating its position in the company. These are familiar identity principles applied to a rapidly expanding population of non-human actors.
Fortytwo’s Identity Universe is built to provide a unified view of identities across people, machines, and AI. It brings identity data, access, and lifecycle governance into a common model so organizations can understand who or what is operating across their environment. This becomes increasingly important as AI changes the scale at which non-human identities are created.
AI is also exposing a governance-speed gap
The other issue is speed. It takes relatively little effort to connect an AI model to a business process, build an automation, or deploy an agent through an existing platform. This lowers the cost of experimentation and can accelerate innovation, at the same time allowing deployment to outpace oversight.
Periodic inventories and annual governance exercises are poorly suited to an environment in which new AI-enabled workflows appear continuously.
Discovery therefore needs to become an ongoing capability. Organizations need to know what is being built while it is being built. That principle also sits behind Fortytwo’s AI Universe, a governed platform for building and operating AI applications in the customer’s own Azure environment.
It brings model access, identity, policy controls, logging, and infrastructure into a common operating model. The goal is to make governance part of the environment in which AI is developed rather than something added after deployment. AI Universe and Identity Universe therefore address two sides of the same challenge. One provides the foundation for governed AI development and operation. The other provides control over the identities and permissions that allow people, machines, and agents to act.
The real message from Lillehammer
Security Festival 2026 showed how closely security, AI, identity, supplier dependency, and governance are becoming connected.
The practical implication for leadership teams is straightforward. As more technology gains the ability to make decisions or perform work, organizations need a clearer picture of the digital actors operating inside them.
That is why the question Do you know how many workers you have? matters.
It is ultimately a question about whether you understand your digital organization well enough to govern it.
AI adoption will continue to accelerate. The organizations that scale it successfully will need governance mechanisms capable of moving at the same speed.
Fortytwo AI Universe provides a governed foundation for building and operating enterprise AI. Identity Universe provides the identity and access layer for managing people, machines, and AI consistently. Together, they help organizations scale AI while maintaining the visibility and control that security increasingly depends on.
Let’s talk
If you want a demonstration of AI Universe, or any of our other products, or you just want a chat, please fill out the form underneath, and we will contact you!
