# The Best Podcast Episodes on Non-Human and Agentic AI Identity

Source: https://startwithidentity.com/articles/best-podcast-episodes-non-human-agentic-ai-identity/
Last updated: 2026-10-01
License: content by Start with Identity. Cite the source URL.

---

The most useful podcast episodes on [non-human identity](https://startwithidentity.com/guides/fundamentals/what-is-non-human-identity/) and [AI agent identity](https://startwithidentity.com/glossary/agentic-identity/) agree on one point before they disagree on anything else: the risk sits in credentials nobody owns. Service accounts, API keys, service principals, and now AI agents accumulate standing access because no person is accountable for them. The 12 episodes below, chosen from about 3,000 across the identity shows we track, take an architect or security lead from that problem to the current answers: workload identity, short-lived credentials, OAuth-based delegation for agents, and authorization for MCP.

Most of this field's podcast content comes from vendors selling NHI products, so we name each guest's employer. All 12 entries were checked against a transcript.

## Part 1: The problem, stated plainly

**1. [#365 Exploring the Future of Machine Identity with Felix Gaehtgens](https://podcasts.apple.com/us/podcast/365-exploring-the-future-of-machine-identity/id1471899975?i=1000720573614)** (Identity at the Center, 62 min, 2025). A former Gartner analyst on how machine identities differ from human ones, why static credentials such as API keys and service accounts become technical debt, and the case for dynamic, ephemeral credentials. He argues most organizations still do this wrong, which makes it the right first listen.

**2. [NHI Workshop: What Are NHIs, Criticality, Risks and Challenges](https://podcasts.apple.com/us/podcast/nhi-workshop-what-are-nhis-criticality-risks-and/id1868664013?i=1000744978708)** (The Non-Human & AI Identity Podcast, 23 min). A recorded panel with guests from [SailPoint](https://startwithidentity.com/vendors/iga/sailpoint/) and [P0 Security](https://startwithidentity.com/vendors/ai-identity/p0-security/) that defines non-human identities, explains why they matter, and lists the main risks. Short and introductory.

Read alongside: [What is non-human identity?](https://startwithidentity.com/guides/fundamentals/what-is-non-human-identity/) and [the credentials nobody owns](https://startwithidentity.com/blog/credentials-nobody-owns/), our analysis of five September 2026 incidents built on unowned credentials.

## Part 2: Secrets and the hidden admins

**3. [Discovering and Stealing Secrets with Mackenzie Jackson](https://podcasts.apple.com/us/podcast/401-access-denied-podcast-ep-76-discovering-and/id1485295700?i=1000605272827)** (401 Access Denied, 33 min). A [GitGuardian](https://startwithidentity.com/vendors/secrets/gitguardian/) researcher on the main ways attackers find and use secrets leaked in source code, and how developers defend against it. The talk names other vendors' tools and does not pitch.

**4. [Shadow Admins: The Non-Human Identities Hiding in Your Entra Tenant](https://entra.news/p/shadow-admins-the-non-human-identities)** (Entra.Chat, 69 min, 2026). The most practical episode on this list. How service principals, app registrations, and agent identities in [Microsoft Entra](https://startwithidentity.com/vendors/iam/microsoft-entra/) become hidden administrators, which API permissions to hunt for, and why to replace secrets with managed identities. If you run Entra, act on this one first.

Read alongside: [secrets management](https://startwithidentity.com/glossary/secrets-management/), [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/), and our [best secrets management tools](https://startwithidentity.com/rankings/best-secrets-management-tools/).

## Part 3: Workload identity instead of stored secrets

**5. [Analyst Chat #264: Persistent Identity, Ephemeral Secrets](https://www.kuppingercole.com/watch/persistent-identity-ephemeral-secrets)** (KuppingerCole Analyst Chat, 22 min). Martin Kuppinger on treating workload identities as privileged, why long-lived secrets widen the attack surface, and how ephemeral secrets, SPIFFE and SPIRE, and policy-as-code help. The clearest short statement of the target architecture.

**6. [Root Causes 640: What is SPIFFE?](https://www.sectigo.com/root-causes/root-causes-640-what-is-spiffe)** (Root Causes, 2026). A short explainer from two certificate industry veterans at [Sectigo](https://startwithidentity.com/vendors/pki/sectigo/) on how [SPIFFE](https://startwithidentity.com/glossary/spiffe/) puts a workload or AI agent identifier inside a certificate, and how policy engines can allow-list those identifiers.

**7. [The Co-Inventor of Tor on Why Your NHI Strategy Is Already Behind](https://podcasts.apple.com/us/podcast/the-co-inventor-of-tor-on-why-your-nhi-strategy/id1683228982?i=1000769664864)** (The Identity Jedi Show, 63 min, 2026). David Goldschlag of [Aembit](https://startwithidentity.com/vendors/ai-identity/aembit/), a workload identity vendor, on why non-human identity risk built up while human identity matured: unrotated keys, hardcoded credentials, and applying zero trust to agents. Useful for the strategic argument; weigh the product context.

Read alongside: [workload identity](https://startwithidentity.com/glossary/workload-identity/), [workload identity federation](https://startwithidentity.com/glossary/workload-identity-federation/), and [Workload identity 101](https://startwithidentity.com/guides/machine-identity/workload-identity-101/).

## Part 4: AI agents and delegation

**8. [#422 Decoded: Securing AI Agents with Standards You Already Have](https://podcasters.spotify.com/pod/show/identity-at-the-center/episodes/422---Decoded---Securing-AI-Agents-with-Standards-You-Already-Have-e3j8ncb)** (Identity at the Center, 78 min, 2026). The single best episode on this topic. Pieter Kasselman, who chairs the IETF WIMSE working group, explains how SPIFFE and existing OAuth specifications (token exchange, the JWT authorization grant, client ID metadata, transaction tokens) secure AI agents treated as workloads. The message: you can start now.

**9. [#390 Identity Management for Agentic AI with Tobin South](https://podcasts.apple.com/us/podcast/390-identity-management-for-agentic-ai-with-tobin-south/id1471899975?i=1000740200992)** (Identity at the Center, 56 min). Drawing on the OpenID Foundation's agentic AI whitepaper, this covers the hard parts that existing specs leave open: recursive delegation, scope attenuation as an agent hands work to another agent, and where MCP fits.

**10. [Agentic AI and the Authorization Gap No One Closed](https://www.hipconf.com/podcast/agentic-ai-authorization-gap-geoffrey-mattson/)** (Hybrid Identity Protection Podcast, 35 min, 2026). [SecureAuth](https://startwithidentity.com/vendors/iam/secureauth/)'s chief executive on why agents need each action authorized in real time, why few MCP servers implement the OAuth the MCP specification requires, and how to roll agents out from zero privileges.

Read alongside: [Securing AI agent identities](https://startwithidentity.com/guides/machine-identity/securing-ai-agent-identities/) and [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/).

## Part 5: MCP and attack research

**11. [Analyst Chat #317: MCP Is Just Another API, and That's the Bad News](https://www.kuppingercole.com/watch/mcp-just-another-api)** (KuppingerCole Analyst Chat, 52 min, September 2026). Alexei Balaganski frames MCP security as an API, identity, and authorization problem: unauthenticated MCP servers, tool poisoning, prompt injection, and practical next steps. Pairs naturally with episode 10.

**12. [One Compromised Agent ID Blueprint Can Cross Tenant Boundaries](https://entra.news/p/one-compromised-agent-id-blueprint)** (Entra.Chat, 54 min, 2026). Datadog researcher Katie Knowles on how Entra Agent ID blueprints, agent identities, and agent users relate, and how stolen blueprint credentials could reach agent identities in other tenants. A concrete reminder that new agent identity features bring new attack paths.

## The show to subscribe to

If you want a feed rather than a list, [The Non-Human & AI Identity Podcast](https://startwithidentity.com/podcasts/non-human-ai-identity-podcast/) is the only show dedicated to the topic, publishing interviews, conference panels, and short Q&A several times a week. Many guests sell NHI products, so use it to track the conversation and this list for the fundamentals. [KuppingerCole Analyst Chat](https://startwithidentity.com/podcasts/kuppingercole-analyst-chat/) and [Identity at the Center](https://startwithidentity.com/podcasts/identity-at-the-center/)'s Decoded episodes are the strongest general shows on agent identity.

## What no episode covers well yet

Two subjects that matter to architects lack a strong dedicated episode on any identity show we track: [workload identity federation](https://startwithidentity.com/glossary/workload-identity-federation/) in practice across clouds, and governance of agent identities over their lifecycle (who approves an agent, who owns it, when it is retired). Both are covered in part by episodes 5 and 8.

The full ordered list, with 15 episodes and a note on which were checked against transcripts, is our [non-human and AI agent identity learning path](https://startwithidentity.com/podcasts/learn/non-human-identity/). For vendors in this space, see our [AI identity](https://startwithidentity.com/vendors/ai-identity/) and [machine identity](https://startwithidentity.com/vendors/machine-identity/) categories.
