As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a structural failure that legacy approaches cannot solve.
The data shows that while businesses have spent years maturing their identity programs for human employees, those same playbooks are fundamentally broken when applied to the ephemeral, autonomous, and rapidly multiplying world of non-human AI agents.
A Market Stalled at the Starting Line
Despite years of investment in identity and access management, the market's overall security maturity has hit a wall. According to the report, the center of gravity remains firmly planted in the foundational stages, with a combined 60% of organizations still in Horizon 1 ("No Formal Program") or Horizon 2 ("Manual, Tool-Assisted").
The multi-year persistence of this trend reveals a critical insight: the problem isn't a lack of effort, but an architectural ceiling. The operational playbooks built to govern human employees may not scale effectively to govern autonomous agents executing thousands of transactions per minute.
A Tale of Two Maturities: The Human vs. Non-Human Divide
The paradox becomes clearer when looking at the stark division between the maturity of human and non-human identity security. The report’s data reveals two entirely different timelines.
- Human Identity is Maturing: For human workforces, security programs are progressing. Five years ago, 45% of organizations were at the lowest maturity level (Horizon 1). Today, that number has been cut nearly in half to 23%.
- Agent Identity is Lagging Dramatically: The opposite is true for non-human and AI agent identities. Today, 54% of organizations sit at Horizon 1 for agent identity security—a worse starting point than for human security five years ago.
This disconnect shows that even organizations with strong capabilities for managing human access are struggling to extend those same standards to cloud workloads and agentic environments. It is a coverage gap, not a competence gap.
Why Old Security Playbooks Fail in the Agentic Era
The core of the velocity paradox is that processes designed for people do not work for machines. The report identifies key structural dynamics that cause this failure:
- The "Digitization Trap": Organizations in the middle-maturity tiers have successfully digitized human-centric processes like employee onboarding and periodic access reviews. However, applying these same scheduled review cycles to ephemeral machine identities—which may exist for only minutes or seconds—creates severe operational drag and is functionally useless.
- The Pivot to Machine-Speed Trust: Breaking into the upper horizons of maturity requires a fundamental paradigm shift. Advanced organizations have moved away from manual, ticket-based access decisions. They have replaced standing privileges with continuous, contextual, and automated policy enforcement that operates at machine speed.
The False Compromise: "Balance" Is Not a Strategy
When faced with the conflict between moving fast and staying secure, nearly half of the market (49%) claims to "balance both equally." However, the report’s data suggests this is a false compromise.
A stated posture of "balance" without the underlying operational capability to enforce it is not a strategy; it is a stall. Organizations are caught in the paradox: They have an AI-speed ambition but a human-speed foundation, leaving them unable to move decisively. This is where most of the market currently sits, waiting for an architectural shift that can resolve the paradox.
The ultimate conclusion is clear: Securing the autonomous enterprise does not require rebuilding from scratch. The immediate priority is for organizations to extend their proven governance disciplines to cover the unmanaged non-human identities operating across their digital estate, unifying them into a single fabric that can finally match the speed of AI.
For additional perspective on how identity maturity is evolving in the age of AI, SailPoint’s “Horizons of Identity Security” report explores the trends, gaps, and capabilities shaping the path forward.
Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
from The Hacker News https://ift.tt/Lj1k3ue
via IFTTT
No comments:
Post a Comment