Home Cyber Security

The AI Arms Race: Why Identity Security Is Now a Boardroom Issue

An interview with Karim Touba, CEO of LastPass, on Security Solutions TV

Cybersecurity used to live in the basement – the domain of IT departments, firewalls, and people no one else in the building quite understood. That era is over. In a wide-ranging conversation on Security Solutions TV, LastPass CEO Karim Touba made the case that security has not just risen up the corporate ladder; it has planted itself firmly in the boardroom, driven by a technology shift more disruptive than anything the industry has seen before: artificial intelligence.

Karim Touba, CEO, LastPass

From “Department of No” to Business Enabler

Touba’s first point was a reframing of what security is actually for. For years, he argued, security teams were seen as blockers – the people who said no to new tools, new platforms, new ways of working. Today, the pressure has inverted. Boards are demanding that security teams enable the rapid adoption of new technologies, particularly AI and SaaS applications, rather than constrain it.

“In the old world it used to be the department of no,” Touba said. “Today, organisations of all sizes are getting a tremendous amount of pressure to have security unlock capabilities for the business – but do so securely at scale.”

This shift is not cosmetic. It represents a fundamental change in how security is budgeted, staffed, and measured. The question is no longer simply “are we protected?” but “are we protected in a way that lets the business move fast?”

The AI Visibility Problem

One of the most pressing practical challenges Touba identified is one that many organisations haven’t fully confronted: they don’t actually know which AI tools their employees are using.

Because much of the early wave of AI tools arrived via the web – accessible through a browser without IT procurement or approval – employees across industries have been quietly adopting AI assistants, writing tools, code generators, and data tools on their own. For security teams, this is a significant blind spot.

“Most organisations today are really scrambling to try to understand both what the policy is internally, but also what technologies and tools to deploy to give them that level of visibility,” Touba explained. The challenge is twofold: establishing policy and deploying the tools to enforce it, and organisations are racing to do both at once.

An Arms Race with Real Stakes

The conversation took a sharper turn when the topic shifted to AI-powered cyberattacks. Host John raised the recent example of Anthropic developing a highly capable model – internally referred to in the interview as “Mythos” – designed specifically to detect software vulnerabilities, but considered too powerful to release publicly given its potential for misuse.

Touba didn’t shy away from the implications. “It is, as you described, absolutely an arms race,” he said. Attackers and defenders now have access to the same underlying AI capabilities, and the question of who moves faster may determine who wins.

LastPass, he noted, has already been building infrastructure using Anthropic’s Claude Opus model to proactively detect vulnerabilities in their own systems – specifically so they can move quickly when more powerful models become available. The strategic logic is straightforward: in an arms race, preparation time is everything.

Passwords Aren’t Dead — Yet

On the question of passkeys and biometrics making passwords obsolete, Touba was measured. Yes, the direction of travel is clear. But transitions in the security industry rarely happen cleanly or quickly, and organisations can’t simply abandon the infrastructure they have.

LastPass’s approach is to support both simultaneously. Their vault now stores traditional credentials alongside passkeys, with the user experience designed so that the end user doesn’t need to know – or care – which type of credential is being used behind the scenes. The complexity is absorbed by the platform, not the person.

The Coming Challenge: Agentic Identity

Perhaps the most forward-looking part of the conversation concerned what Touba described as the next major frontier for identity security: AI agents.

As organisations begin deploying autonomous AI agents to handle tasks – agents that operate continuously, spawn sub-agents, and act on behalf of users – the question of identity becomes dramatically more complex. Early projections, Touba noted, suggest that there could eventually be 90 to 100 AI agents for every human user within an organisation.

Each of those agents needs to authenticate. Each needs defined permissions. And when one agent spawns another, the question of how authority and authorisation pass through that chain is not yet answered – by the industry, by regulators, or by most organisations.

“They have to have the capability to understand the relationship between a user launching an agent and whether or not you actually delegate the authority of the user’s authorisation construct to the agent,” Touba said. It’s a problem that sounds abstract until you imagine a chain of autonomous agents with access to sensitive systems, each inheriting permissions from the last.

What Keeps the CEO Up at Night

Asked what worries him most, Touba pointed not to hackers or ransomware, but to something subtler: the risk that organisations will push sensitive data into AI systems without fully understanding what they’re doing.

Traditional cybersecurity is built around the assumption that attackers are trying to pull data out. AI inverts that model. The risk now is that users – with the best of intentions, chasing productivity – push proprietary, sensitive, or regulated data in to large language models. Once it’s there, the implications for privacy, compliance, and competitive advantage can be significant.

“It’s a very new model,” Touba said. “You are enabling a new set of tools at an extremely aggressive rate to the broader organisation, and really understanding how to secure AI holistically is the thing we have a lot of focus on.”

The Takeaway for Australian Organisations

For Australian businesses specifically, Touba offered two priorities for the next 12 to 24 months. First: get the foundational basics right. Full visibility into every application employees are using – AI-based or otherwise – and a clear policy framework for authentication and access. Without that foundation, building for the future is structurally unsound.

Second: start thinking now about agentic authentication. The organisations that will navigate the agentic AI era most successfully are those that begin laying the groundwork before agents are fully deployed – not after.

The message underlying the entire conversation was consistent: the pace of change in AI is outrunning most organisations’ security thinking. The gap between where AI capabilities are headed and where security programs currently sit is the defining challenge of the next few years – and it’s one that every board, not just every IT department, needs to be paying attention to.