The next wave of identity innovation is already underway. It’s big. Bigger than most of the innovation we have seen over the past two decades. Bigger than a new authentication method and getting rid of passwords. Bigger than another Zero Trust checklist. What we’re seeing is a long-overdue modernization of the identity foundations that digital business depends on. This change won’t happen overnight, but the building blocks are here. They are already reshaping architectures well into 2040.
Let’s look at the ten key trends that are shaping the future of IAM and digital identity.
1. PBAC and beyond: The Comeback of a 50-Year-Old Concept
Policy-Based Access Control (PBAC) is not new. It has been around for decades. IBM RACF (Resource Access Control Facility) came to market back in 1976. It has been taken seriously as a scalable and dynamic alternative to static entitlements for long but didn’t really succeed. Why? IAM environments are too complex for simple (and even complex) role models. PBAC brings in context: Who is the user? What are they doing? What’s the risk level?
But PBAC in its earlier incarnations, such as around XACML (eXtensible Access Control Markup Language) also was too complex. New approaches such as OPA or Cedar are way more widely used.
PBAC enables precise, real-time decisions, but still depends on well-maintained policies and attributes. While not a silver bullet, it’s an essential step towards smarter access control. Bringing together PBAC and the AI potential will make it more of a silver bullet. Dynamic, AI-managed policies can deal with scale even in highly dynamic environments.
2. Modular Architectures: IAM Without the Monolith
IAM no longer comes in a shrink-wrapped box. Today’s platforms are increasingly modular: loosely coupled services orchestrated through APIs, workflows, and integration layers.
This modularity accelerates onboarding, reduces duplication, and allows for replacing or upgrading individual components without rewriting everything. In an era where agility is key, monoliths don’t scale. Modular IAM is what scales. That is what identity fabrics are about.
3. Orchestration as the New Control Plane
Orchestration is more than workflow. It’s a structural layer that decouples business logic, data, and user experience. That makes it the control plane of modern IAM.
A good orchestration platform does more than connect services. It enables identity journeys to evolve continuously without changing the underlying infrastructure. Think of it as the “brain” coordinating a flexible, ever-adapting identity fabric.
4. Decentralized Identity: Beyond the Hype
Yes, Decentralized Identity (DCI) has been hyped. But it’s also real and ready for enterprise use. Its biggest value? Solving the single source of truth problem.
In federated environments, DCI reduces the need for constant synchronization and data replication. It allows organizations to issue and verify credentials in real time. That’s a game-changer, especially in scenarios like IGA, dynamic access, and CIAM, where identity silos are a recurring pain point.
And let’s not forget the broader implications: portable credentials, reduced attack surfaces, and finally, user-controlled identity at scale.
5. Signal Sharing and Enrichment: From Static to Adaptive
Static decisions are out. Real-time signals are in. Standards such as CAEP (Continuous Access Evaluation Protocol) and the Shared Signals Framework (SSF) are enabling adaptive access based on shared context and dynamic risk levels.
The benefit? Continuous enforcement. A device that becomes risky can trigger access revocation. A change in location or behavior can lower confidence. This isn’t theoretical. It’s already happening, and it’s essential for any Zero Trust implementation worth the name.
6. Autonomous Identity: AI Doing the Heavy Lifting
AI is finally coming to IAM in a useful way, not to replace humans, but to support them where scale and speed matter most. We call this AIdentity, the intersection of AI and Identity.
Autonomous identity systems use AI models to spot anomalies, propose entitlements, and even grant or revoke access based on behavioral baselines. This is especially useful in high-volume or fast-changing environments, such as machine-to-machine (M2M) access, operational technology (OT), or large-scale IoT deployments.
Humans can’t write rules fast enough for these use cases. AI can.
7. AIdentity: Not Just for People Anymore
AI systems themselves are becoming digital actors. They make decisions, access resources, and trigger transactions. That raises a simple but critical question: Who governs their identity lifecycle?
Managing AI agents like users, with identity proofing, access controls, and lifecycle governance, is becoming a necessity. Identity is no longer just about humans or devices. It’s also about software that thinks and acts.
8. Beyond Passwordless: Toward Passive Authentication
We’ve talked for years about killing passwords. But just replacing them with biometrics or passkeys doesn’t go far enough. The real shift is from active to passive authentication.
Using contextual and biometric signals such as typing speed, location, usage patterns, but also behavioral data, systems can authenticate users continuously and invisibly. This improves both security and user experience.
In fact, frictionless security becomes possible when the system knows enough about you that it doesn’t have to ask.
9. Identity Meets Security: A Strategic Convergence
The lines between IAM and cybersecurity are blurring and that’s a good thing. Identity data is being used for threat detection. Access management is becoming part of incident response. The integration is already happening and should be encouraged.
This convergence doesn’t mean one platform for everything. It means common signals, shared context, and joint control logic. Identity security is not a buzzword. It’s the next layer of defense.
10. Machine Identities: The Quiet Explosion
Non-human identities are exploding. Devices, APIs, containers, bots, microservices – all these entities need credentials, governance, and lifecycle management. Yet most IAM programs still focus almost exclusively on humans.
This imbalance is unsustainable. Machine identity management must be elevated to a first-class citizen in IAM programs. Without it, we leave the back door open and we won’t even know it.
What Comes Next
These ten trends are not isolated. They are converging. Modular IAM supports orchestration. Orchestration powers DCI. DCI simplifies adaptive access. Adaptive access relies on signal sharing. Signal sharing is made possible by AI and policy-based controls. And all of this only works when human and non-human identities are managed equally well.
In short: the future of IAM is modular, intelligent, and decentralized. Identity is no longer just about access. It’s becoming the digital backbone of trust.
And that’s why it matters.
Identity Fabric Impact Day
These trends aren’t just shaping the future in theory, they are being explored and tested in practice. At the Identity Fabric Impact Day, a hands-on event taking place on September 18, 2025, in Munich, these topics will be front and center. It’s an opportunity for practitioners and decision-makers to dive deep into modular IAM, orchestration, decentralized identity, AI-driven identity management and more - translating vision into practice.