This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.
I was talking with a colleague recently about governance, and somewhere in the conversation, we realized we were using the same word to describe two very different problems.
In the identity world, governance usually means managing identities, entitlements, approvals, certifications, and access. Mention governance to someone working in AI, and the discussion quickly turns to transparency, accountability, model behavior, bias, and regulatory oversight.
Neither definition is wrong. They simply grew up in different communities.
What has struck me over the past year is how quickly those communities are beginning to overlap.
Governance Is Following the Architecture
Consider a fairly ordinary enterprise workflow. An employee approves a transaction. An AI assistant gathers information from several systems before making a recommendation. The recommendation triggers an automated workflow running under workload identities in the cloud. The final decision is recorded for audit, along with the policies that influenced it.
Where does identity governance end? Where does AI governance begin? I'm not convinced those boundaries are especially useful anymore.
For a long time, identity professionals have tended to treat governance as something that happens around identities: who should have access, who approved it, when should it be reviewed, and when should it be removed.
Those questions remain important. They also turn out to be only part of a much larger governance problem.
Organizations increasingly need to understand not only who or what participated in a transaction, but also under whose authority the action was taken, which policies governed it, and what evidence supported the action. Those questions apply whether the participant is a person, an application, an AI system, or another organization.
Identity is still part of the answer. It simply isn't the whole answer.
The Questions Haven't Changed, but the Systems Have
This is one reason I find some of the discussions around AI governance a little unsatisfying. They often imply that governance has suddenly become important because AI arrived.
Identity professionals know better.
We've been wrestling with accountability, delegated authority, least privilege, lifecycle management, and auditability for decades. Those concepts did not disappear when AI entered the conversation. They became relevant to a wider range of systems.
The opposite is true as well.
Identity governance can no longer assume that every meaningful action begins and ends with a human user authenticating to an application. Increasingly, important decisions involve software components, cloud workloads, organizational identities, automated services, and AI systems acting within defined boundaries.
AI agents add a further complication because they do not merely authenticate and execute predefined instructions. They may select tools, delegate tasks, adapt their behavior, and act across several systems under authority derived from a person or organization.
The governance challenge has expanded because the systems themselves have expanded.
Identity Becomes Part of a Trust Architecture
I don't think this means identity governance is becoming obsolete. If anything, it has become more foundational.
Strong identity remains one of the building blocks for trustworthy systems. But trustworthy systems also require policy, authorization, provenance, transparency, organizational accountability, and, increasingly, some way to understand how automated decisions were made and under what authority they were allowed to occur.
Those concerns don't belong exclusively to identity teams or AI teams. They also belong to architects, risk owners, and business leaders.
That may be the biggest change underway.
We're moving away from governance as a collection of specialized disciplines toward governance as an architectural property of the system itself. Identity remains an essential part of that architecture, but it no longer defines its boundaries.
Perhaps that's the wrong way to think about identity governance altogether. Rather than asking how governance is expanding beyond identity, we might instead ask whether identity has finally become integrated into the broader trust architecture it was always meant to support.
I suspect that's a healthier direction for both disciplines.