This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.
How artificial intelligence rewired identity management job postings, and turned three specialized concerns into distinct IAM hiring categories
Three years ago, if you searched an IAM job description for the word "AI," you mostly found it in the acronym soup around "AIM" typos and vendor marketing decks. Today it's a line item: required skill, and not a nice-to-have. Somewhere between those two states, the identity market went through a structural shift. I wanted to trace it in detail, with numbers.
This piece looks at how AI moved through identity management hiring in stages: where it started, how the job market absorbed it year by year, which vendors led and which are still catching up, how M&A reshaped who owns what, which entirely new IAM specializations exist only because of AI, and where this is heading through 2027.
A note before the data: I've used cybersecurity-wide figures as the closest available proxy where IAM-specific numbers don't exist, and I've flagged every place where that substitution happens.
Where This Actually Started
AI in identity did not begin with ChatGPT. It started years earlier, inside a completely different acronym: UEBA, User and Entity Behavior Analytics. Gartner coined the underlying concept in its 2015 Market Guide, explicitly extending the model to cover non-human actors like servers, routers, and endpoints. In practice, this meant IAM and SIEM vendors were bolting machine-learning risk scoring onto access management by the mid-to-late 2010s: flag the login that doesn't match the user's usual pattern, flag the access request that doesn't match the role. Nobody called this "AI" in a job posting. It was "analytics." It was a quiet phase, and it matters because it means the technical groundwork for AI-driven identity governance predates the current hype cycle by the better part of a decade.
The visible break came in 2022-2023, for the same reason it hit every other corner of tech hiring: generative AI. Lightcast's tracking shows job postings requiring generative-AI skills growing roughly ninefold in non-IT roles and 35-fold in other IT roles between 2022 and 2024. IAM rode that same wave, but with a lag. Identity vendors needed a product cycle before "AI" became a sellable, then hirable, feature.
That product cycle landed in 2023-2024. SailPoint began marketing "AI-Driven Identity Security" as a platform pillar and launched AI-powered application onboarding on June 13, 2024, followed by GenAI-generated entitlement descriptions. Okta introduced AI-based identity threat signals under the "Okta AI" label. This is the point where "AI" starts showing up as a named requirement in IAM job descriptions rather than being folded into generic "automation" language.
2024 is also when a second, more consequential shift began: non-human identity. AI agents are themselves non-human identities, and every enterprise now generating AI agents is generating a governance problem that didn't exist at this scale before. By 2025-2026, "agentic AI" became its own tracked skill cluster in labor-market data, and NHI/agent governance graduated from a side note to a genuine new hiring category. (More on exactly which vendors moved here, and how, in the M&A section.)
AI in IAM Jobs, Year by Year
Before 2021, the quiet baseline. AI-tagged skill demand in security roles is negligible and largely unlabeled. Generative-AI-specific job postings in the US are essentially a rounding error: Lightcast counted 55 unique generative-AI postings in January 2021, the closest baseline data point, climbing toward the low thousands by 2023.
2023, the inflection year. CyberSeek data, per secondary reporting puts AI-skill requirements at roughly 6.5% of all cybersecurity postings. This is the first year the number becomes a trackable line rather than noise. (Cybersecurity-wide)
2024, vendor branding meets job descriptions. CyberSeek's data release puts the figure at approximately 10% of employers recruiting for cybersecurity positions citing AI as a requirement over the twelve months to April 2025. Separately, Cisco's AI Workforce Consortium report (a different methodology and time window, covering Cornerstone/Indeed job-posting data) shows 14.2% of cybersecurity postings requiring AI skills in the twelve months to March 2025. That gap between the two figures is a useful reminder of how much the number moves depending on which slice of the year and which underlying dataset you use. This is also the year SailPoint's and CyberArk's machine-identity moves start generating job requirements rather than press releases. (Cybersecurity-wide)
2025, doubling and a new skill cluster. The same Cisco AI Workforce Consortium report shows AI-skill requirements in cybersecurity postings reaching 28.5% for the period October 2025 to March 2026, roughly double the year before. Five skills recur across AI-tagged postings: Python, prompt/context engineering, AI security, agent orchestration, and MLOps. Meanwhile, Stanford's AI Index added "Agentic AI" as its own tracked skill cluster for the first time, showing it jump from 0.06% of US postings in 2024 to 0.23% in 2025: a 280%+ increase, representing roughly 90,000 postings. Non-human identity volume grew 44% year-over-year through this period, and the NHI-to-human identity ratio estimates range from 45:1 to 82:1 depending on whose methodology you use (Rubrik Zero Labs vs. CyberArk's 2025 Identity Security Landscape study). (Cybersecurity-wide plus identity-specific NHI data)
2026, governance becomes the hiring story. This is the year the conversation shifts from "does the platform use AI" to "who governs what the AI agents are allowed to do." Teleport's 2026 Infrastructure Identity Survey found that 92% of organizations already have near-term AI initiatives in production infrastructure, 79% are evaluating or deploying agentic AI specifically, but only 13% feel "extremely prepared" for it. That gap, widespread deployment paired with minimal readiness, is exactly the kind of gap that generates job requisitions. AI governance postings specifically (a broader category than IAM but heavily overlapping with it) grew 150% year-over-year according to LinkedIn's 2026 Skills on the Rise report, among the fastest-growing skill categories LinkedIn tracks in any field.
2027, the projection. One hard deadline makes 2027 predictable in a way most labor-market projections aren't. The European Commission's enforcement timeline confirms the EU AI Act's high-risk system requirements (Annex III) become enforceable on December 2, 2027: a compliance deadline with the same structural effect on IAM/AI-governance hiring that GDPR had on IAM hiring in 2017-2018. Worth noting this date is itself a delay: the original deadline was August 2, 2026, pushed back to December 2027 via the EU's "Digital Omnibus" simplification package, finalized in mid-2026. And Gartner's projection that 33% of enterprise applications will incorporate agentic AI by 2028 (up from under 1% in 2024) implies that by 2027, NHI and agent governance stops being a specialization and starts being a baseline expectation for mid-to-senior IAM roles, the same way cloud IAM knowledge became non-optional a few years earlier. If the 2024-to-2025 doubling pattern in AI-skill cybersecurity postings holds even at half that rate through 2026-2027, AI/agent-governance literacy moves from "differentiator" to "assumed" for the majority of IGA, PAM, and access management postings by the time the EU AI Act deadline lands.
Three Fields AI Turned into Hiring Categories
IAM has absorbed new technologies before: cloud, mobile, zero trust. But those were adaptations of existing IAM work to a new environment. The following three were either absent or niche concerns until AI turned them into standing hiring categories.
ITDR (Identity Threat Detection and Response). ITDR platforms use behavioral analytics and anomaly detection, the direct descendants of that mid-2010s UEBA groundwork, to detect identity-based attacks continuously and in real time, rather than relying on periodic log review or investigation after a breach has already been reported. It draws heavily on existing PAM and SIEM practice, but it is organized around a different assumption: that AI-speed attacks require AI-speed detection, and that traditional, batch-oriented monitoring cycles cannot keep up.
NHI / Machine Identity Governance. Service accounts and API keys existed long before AI. What's new is the scale and the actor: AI agents now generate, use, and discard machine identities autonomously, at a volume no manual process can track. The job category, governing credentials that no human requested, uses, or remembers to revoke, is a direct consequence of agentic AI operating at machine scale and machine speed.
Agentic AI Governance. This is the newest and least standardized of the three. It covers the specific problem of what an autonomous AI agent is allowed to access, under what conditions, and with what accountability trail when something goes wrong: a governance question that literally could not exist before agents capable of independent action existed. Purpose-built products now cover parts of this directly, such as Ping Identity's "Identity for AI," which reached general availability on March 24, 2026, and Okta's Cross App Access, which became a stable, official MCP authorization extension on June 18, 2026, with early MCP-provider partners including Asana, Atlassian, Canva, Figma, and Supabase. When a new product category forms around a problem this specific, hiring for that problem usually follows a year or two later.
How Vendors Bought Their Way Into AI
Organic product development explains part of the shift above. The faster part of the story is acquisition, and the dates tell a specific story: AI wasn't the driver from the start. It became one partway through 2024, and by 2026 it was the dominant rationale in the space.
2022-2023: consolidation, not AI. The defining moves of this period were Thoma Bravo's take-privates of SailPoint (April 2022, $6.9B), Ping Identity (October 2022, $2.8B), and ForgeRock (August 2023, $2.3B) (Identity Management Institute). None of the announcements from this period, across dozens of smaller deals as well, framed the rationale around AI. This was financial and capability consolidation in a fragmented market, plain and simple.
2024: the first genuinely AI-adjacent deal, framed as "machine identity," not "AI." CyberArk acquired Venafi (signed May 20, 2024; closed October 1, 2024; approximately $1.54 billion). The announcement framed the deal around securing "every identity, human and machine." Worth flagging precisely: this deal predates the agentic-AI framing entirely. It's about cloud and DevOps-driven machine identity growth, not AI agents specifically. I'd classify it as AI-adjacent infrastructure rather than AI-motivated in the strict sense, and it's the closest thing to a bridge between the old consolidation logic and what comes next.
2025: AI framing becomes explicit, and the pace picks up.
- CyberArk acquired Zilla Security (announced February 13, 2025; approximately $165 million cash plus a $10 million earnout, per TechCrunch). AI-motivated, though less explicitly than the framing suggests at first glance: TechCrunch reports that CyberArk sought tools "purpose-built for the cloud, with AI at its core," and describes Zilla as having spent recent years "adding more automation and AI-enabled features" to its platform. CyberArk CEO Matt Cohen's quoted rationale, however, centers on governance and scale rather than AI specifically: "we will reshape identity governance with scalable automation that delivers compliance and helps maximize security for the modern enterprise."
- Palo Alto Networks acquired CyberArk (announced July 30, 2025; approximately $25 billion equity value; closed February 11, 2026). Also explicitly AI-motivated: the press release states the deal will "deliver Identity Security for agentic AI by securing autonomous AI agents." This is the largest deal in the space and the clearest single signal of AI as the strategic driver behind identity M&A. The combined business has since been rebranded Idira under Palo Alto.
- Okta acquired Axiom Security (announced August 26, 2025; closed September 4, 2025; reportedly around $75 million per Israeli press). AI-motivated per Okta's framing: Computer Weekly headlined its coverage "Okta makes AI identity play," and Okta's CTO cited AI-related risk explicitly as a driver.
- Zscaler acquired SPLX (announced November 3, 2025; terms undisclosed). Explicitly AI-motivated: SPLX specializes in AI red-teaming and AI asset discovery.
2026: AI and non-human identity become the dominant M&A rationale in the entire identity sector.
- CrowdStrike acquired SGNL (announced January 8, 2026; reportedly around $740 million). AI-motivated: the press release is titled "Transform Identity Security for the AI Era," with CrowdStrike's CEO stating, "AI agents operate with superhuman speed and access, making every agent a privileged identity that must be protected."
- Silverfort acquired Fabrix Security (announced April 28, 2026; terms undisclosed). AI-motivated: Fabrix is described as "AI-native," and the deal is framed around delivering "autonomous Identity Security at runtime" for the AI era.
- Cisco acquired Astrix Security (announced May 4, 2026; reportedly $300-400 million per press estimates, undisclosed officially). Explicitly AI-motivated: Cisco's blog post announcing the deal is titled "Securing the Agentic Workforce" and frames AI agents as "an entirely new class of coworker."
- Zscaler acquired Symmetry Systems (announced May 21, 2026). AI-motivated: explicitly described as "identity mapping and data access for AI security".
- Snowflake acquired Natoma (announced May 27, 2026; terms undisclosed). AI-motivated, and notable because Snowflake isn't a traditional IAM vendor: this is a data-platform company buying an MCP and agent-identity governance layer specifically to control what AI agents can do with enterprise data.
- SailPoint acquired Entro Security (announced June 15, 2026; closed June 29, 2026; reportedly around $200 million per SecurityWeek). AI-motivated: framed explicitly around securing "agentic identities" as non-human identity volume "has eclipsed human identities"
- 1Password acquired Apono (announced June 15, 2026; reportedly $250-300 million per Israeli press). AI-motivated: described as "just-in-time access governance for humans, machines, and AI agents".
- Okta acquired Permiso Security (announced July 30, 2026; deal terms undisclosed by either company). Per TechCrunch's original reporting, a person with knowledge of the deal put the price at just under $200 million, almost all cash; Okta's spokesperson did not dispute the figure when asked. Closing was expected within Okta's fiscal Q3 2027 (by end of October 2026), per the same report. AI-motivated: Okta's press release describes Permiso as "a cloud-native identity security platform that detects and mitigates threats across human, non-human, and agentic identities in multi-cloud environments."
The pattern across all these deals is unambiguous once you line them up by date. Zero AI-framed IAM acquisitions in 2022 or 2023. One AI-adjacent deal in 2024, framed around machine identity rather than AI specifically. Four deals in 2025 with AI stated explicitly as the rationale. Eight AI or NHI-motivated deals in 2026 alone, more than the entire prior two years combined. Whatever else is uncertain about how this market develops, the acquisition timeline itself is a clean, dated record of exactly when "AI" stopped being marketing language and started being the reason boards approve nine and ten-figure checks.
Underneath this wave sits the older consolidation wave that gave several of these buyers the balance sheet to go shopping in the first place: Thoma Bravo's ownership of both SailPoint and Ping Identity is a good example (hhhypergrowth; MajorKey Tech). Private-equity and platform-scale ownership structures across the sector are part of what made rapid, repeated AI-capability acquisition financially possible rather than something every vendor had to build from scratch.
What this means for hiring: vendor consolidation is deciding which AI capabilities get bundled into a single platform versus sold as a point solution, and that decision shapes the job posting itself. An employer that just absorbed an NHI acquisition is more likely to hire for "NHI governance" as a platform-agnostic skill than for a single vendor's feature set. Expect that framing to keep growing in job postings as more of these deals close and the acquired teams get folded into bigger platforms.
Who Moved First & Who's New
Early movers. SailPoint has the most consistent public AI positioning of the established IGA vendors. "AI-Driven Identity Security" is framed as foundational to its platform, and it shipped agent-identity connectors for Copilot, Bedrock, Vertex, Foundry, Agentforce, ServiceNow, and Snowflake Cortex in March 2026, followed by Agentic Fabric, launched May 11, 2026. CyberArk's 2024 Venafi acquisition (see M&A section above) was the clearest early single-vendor signal that machine and AI-identity security was becoming core business rather than an add-on.
The new players. Before being acquired, the pure-play NHI and agentic security vendors (Entro Security, Astrix Security, Oasis Security, SGNL, and others named in the M&A section) didn't exist as a category two years ago. Several generated original research that is now cited across the industry (Entro's NHI ratio tracking is a good example) before being folded into larger platforms. Oasis Security, notably, moved from a standing letter of intent with Cyera to a closed deal in September 2026, which leaves almost no independent vendor in this category. This is the fastest-consolidating corner of the vendor landscape, and correspondingly the one with the thinnest available talent pool for anyone hiring against it directly.
Where AI-in-IAM Skill Demand Concentrates
By sub-domain. IGA has the most mature AI integration: KuppingerCole's 2026 research agenda states that "IGA purchasing decisions will be driven by measurable AI outcomes such as less access review effort, reduced toxic access, and more automation" by 2026, with AI-driven access recommendations and anomaly detection now a standard evaluation criterion. PAM's AI story is increasingly about machine-credential rotation and monitoring rather than human privileged-account management. Access Management/SSO's AI story is narrower, mostly adaptive, risk-based authentication. NHI/agentic governance is the newest and least mature domain, and the one growing fastest from a small base.
By skill type: "use AI" versus "build/govern AI." The majority of current IAM postings ask candidates to use AI: interpret vendor risk-scoring output, work inside AI-assisted certification workflows, understand what the copilot-style interface is recommending and why. A smaller, faster-growing, better-paid segment asks candidates to build or govern AI: NHI/machine identity governance specifically, agent orchestration, AI governance frameworks (NIST AI RMF, EU AI Act readiness), and AI security for identity systems themselves rather than AI as a tool inside them. This is the same build-versus-use distinction that shows up in every broader AI labor-market study, and it's sharpening inside IAM specifically as agent governance moves from theoretical to mandatory.
By country. The cleanest available signal is Stanford HAI's 2026 AI Index, via Lightcast's contributor page, which measures the share of all job postings (not IAM-specific) mentioning AI skills: Singapore leads at roughly 4.7%, followed by Hong Kong (3.5%), Luxembourg (3.4%), and Spain (3.3%), with the United States at 2.6%, just ahead of Chile (2.4%) and the United Kingdom (1.9%). Separately, Eurostat's December 2025 release of its enterprise AI-adoption survey (a different methodology, measuring organizational use rather than job-posting language) puts Denmark (42.0%) and Finland (37.8%) at the top of the EU, against an EU average of 20.0%. These two rankings disagree because they're measuring different things: job-posting concentration versus enterprise deployment.
What This Means, Practically
For IAM professionals: the AI skill that pays is not "I used a chatbot." It's non-human identity governance, agent orchestration, and AI-specific security and compliance knowledge: the build/govern track, not the use track. If you're a DevOps engineer who already manages secrets, or an ML practitioner curious about identity, you are closer to the fastest-growing part of this market than most traditional IAM job titles suggest.
For hiring organizations: the data shows a consistent pattern of widespread deployment paired with minimal readiness: 79% of organizations are evaluating or deploying agentic AI, while only 13% describe themselves as extremely prepared for it. That gap closes on its own timeline regardless of budget cycles, and the EU AI Act's December 2027 enforcement date puts a hard floor under how long it can stay open.