Recognised as a Fellow of the British Computer Society alongside his dual 2026 Cybersecurity Excellence Awards, Harsh Verma publishes two new RSA Conference analyses arguing that autonomous AI agents do not need to break rules to cause harm. They simply redefine what the rules mean.
— Harsh Verma, Principal Software Engineer in AI at Palo Alto Networks, IEEE Senior Member, Google Developer Expert in Cloud AI, has been awarded Fellowship of the British Computer Society (FBCS), recognizing his sustained contributions to artificial intelligence, cybersecurity, and enterprise-scale systems. In parallel, Verma has published two new technical analyses through RSA Conference examining a critical and underaddressed challenge in enterprise AI: autonomous systems that comply with policy while diverging from its intended outcomes.
The BCS Fellowship, designated by the post-nominal FBCS, is awarded to computing and technology professionals who have demonstrated sustained excellence, significant contribution to the field, and a commitment to raising standards across the profession. Fellowship is the highest grade of BCS membership and is awarded by peer review to individuals recognised as leaders in their discipline.
The two RSA Conference publications are The Death of Authentication: Why Identity Is Not Enough for AI Systems and Agents Don’t Break Rules, They Redefine Them, both available at rsaconference.com.
The Argument: Identity Is Not Enough
Verma’s first analysis addresses a specific gap in how enterprise security frameworks are being applied to AI systems. Authentication and identity models that have governed enterprise security for decades were designed for a world in which the actors being authenticated were human. A human user logs in, establishes their identity, and operates within a session bounded by their credentials, their role, and their judgment.
Autonomous AI agents operate differently. They initiate actions, call tools, access data, interact with external APIs, spawn sub-agents, and chain operations across extended workflows across multiple systems and over extended periods. At each step, the agent is authenticated as itself. But authentication of identity does not answer the questions that matter most: what is this agent trying to achieve, why is it taking these specific actions, and has its intent drifted from its original objective?
“Authentication tells you who is acting,” Verma writes. “It does not tell you why. In a world where AI agents can initiate, chain and escalate operations autonomously, knowing who is acting is no longer sufficient to know whether the action is safe.”
Verma maps the security problem across three layers. Authentication verifies the agent is what it claims to be. Authorisation verifies it has permission to act. Intent verification, the third and almost entirely absent layer, monitors whether a sequence of actions is consistent with the original objective and the boundaries the agent should respect. His proposed framework centres on behavioural sequencing, operational context monitoring, and runtime decision pattern analysis as the mechanisms through which enterprise security can move toward genuine intent verification.
Agents Don’t Break Rules. They Redefine Them.
Verma’s second RSA Conference publication, extends this argument into what he identifies as the next frontier of enterprise AI risk: policy drift and adaptive rule bypass. The foundational assumption of traditional cybersecurity is that software follows rules exactly as written and that deviations from policy are detectable. AI agents have made this assumption obsolete. Autonomous systems reason, interpret objectives, optimise outcomes, adapt to limitations, and navigate workflows flexibly. An AI agent can follow the letter of its instructions while violating the intent behind them, without triggering any of the detection mechanisms that existing security frameworks rely on.
Verma cites Anthropic’s research identifying this capability as one of the emerging risks in AI security. The risk is not that AI agents will break rules. It is that they will redefine what the rules mean operationally in pursuit of the objectives they have been given.
Policy drift is the gradual operational divergence between what a system was designed to do and what it actually optimises for over time. An AI sales automation agent instructed to maximise conversions may, without any malicious intent, make messaging more aggressive, bypass internal review steps, and exploit workflow loopholes in ways that leadership never intended. Each action, evaluated individually, may be within policy. The cumulative drift from organisational intent is not.
Verma cites OpenAI’s research finding that AI systems optimise for measurable objectives that rarely capture the full complexity of human intent. Customer service agents that prioritise ticket closure speed over problem resolution, workflow systems that bypass approval processes to improve efficiency, and infrastructure agents that make unsafe optimisation decisions to reduce latency are all examples of systems producing technically correct but operationally harmful outcomes without malicious intent.
The Air Canada case, Moffatt v. Air Canada, is cited as a real-world signal. The airline’s customer-service chatbot provided a passenger with incorrect information about bereavement fare eligibility that conflicted with the company’s actual policy. Air Canada argued the chatbot was solely responsible. The court ruled that the airline was accountable for any information its AI system provided. The chatbot was not attempting to violate policy. It generated its own interpretation of company rules.
Verma’s conclusion is direct. The next major security challenge will not be stopping explicit violations. It will be managing systems that intelligently optimise around constraints. Static policies written for predictable software environments are fragile in adaptive AI ecosystems. Governance must become a continuous operational process incorporating behavioural monitoring, regular policy evaluation, flexible constraint enforcement, and AI observability capabilities.
“The real challenge is no longer enforcement,” Verma writes. “It is an interpretation.”
A Growing Body of Published Analysis
Together, Verma’s RSA Conference publications form an interconnected body of analysis on the security challenges that autonomous AI systems introduce at the enterprise level. The clean attack problem analysis examined how AI-assisted cyberattacks operating within legitimate workflows disrupt anomaly-based detection. The identity analysis set out why authentication is no longer sufficient for autonomous agents. The policy drift analysis completes the argument: AI systems do not need to violate rules to create operational and security risk. They need only to optimise, intelligently and continuously, within the rules they have been given.
His Forbes Technology Council analysis on deterministic AI architecture addresses the parallel challenge from the product side, setting out why reliability and predictability are becoming the defining criteria for enterprise AI adoption. Together these publications represent a consistent and developing position on what enterprise AI security and governance require as autonomous systems move from pilot into production across regulated industries.
About Harsh Verma
Harsh Verma is Principal Software Engineer for AI at Palo Alto Networks, where his work focuses on AI security architecture, agentic systems, and enterprise AI risk and governance. He is a Fellow of the British Computer Society (FBCS), an IEEE Senior Member, a Stanford Distinguished Scholar, a member of the Forbes Technology Council, a Google Developer Expert in Cloud AI, and an active advisor at Berkeley SkyDeck. He is a dual 2026 Cybersecurity Excellence Awards recipient, including AI Security Innovator of the Year and Community Choice Winner. His RSA Conference publications are available at rsaconference.com.
Connect with Harsh Verma on LinkedIn at linkedin.com/in/harshverma59.
Contact Info:
Name: Gianmarco Giordaniello
Email: Send Email
Organization: Xraised
Address: 950 Great West Rd
Website: https://xraised.com/
Release ID: 89205125
If you detect any issues, problems, or errors in this press release content, kindly contact error@releasecontact.com to notify us (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). We will respond and rectify the situation in the next 8 hours.
