The classical IAM model is elegant precisely because it is linear. Subject A is granted access to resource B for purpose C. Everything traces back to an explicit, human-made decision. Roles, hierarchies, entitlements - all of it deterministic, all of it directed, all of it auditable.
It worked well for human actors, predictable workflows, and perimeters you could draw a line around. That combination no longer describes the enterprise environment for most organizations.
“We didn’t build IAM for a world where the actor, the path, and the destination are all unknown until the moment of access.”
What Agentic AI Actually Breaks
Two assumptions have underpinned every IAM framework, tool, and governance process ever built. First: we know the identity of the actor needing access. Second: we can define in advance what they are allowed to do. Agentic AI breaks both simultaneously.
When an AI agent is deployed to accomplish a goal, it does not follow a predefined script. It navigates. It creates sub-agents on the fly. It chains tools, systems, and APIs in sequences no one mapped out in advance - because that mapping is precisely what the agent is there to avoid doing for you. Access is no longer granted by an administrator to a defined target. It emerges from the agent’s reasoning process.
The result is two structural breaks with the traditional model. Access becomes non-directed - the agent decides which systems it needs, not a human administrator. Behavior becomes non-deterministic - deploy the same agent for the same task twice and it may follow a different path, touch different systems, assume different identities along the way. There is no access matrix that captures what an agent will do, only constraints on what it should do.
Underneath both: the shift from single-party to multi-party identity. A human instructs an agent that invokes a sub-agent that calls a tool that accesses a system. Who is accountable? Who is authorized? At which point in that chain does trust need to be verified?

“Traditional IAM asks: who has access? Agentic AI forces us to ask: who is acting, on whose behalf, through which chain, right now?”
The Uncomfortable Truth About Determinism
Here is something the IAM community has been reluctant to say clearly: the assumption of determinism was always a useful fiction.
Authentication events have always carried risk signals, soft factors, contextual inference. A successful login was never a guarantee of a verified, fully-known identity - it was a practical simplification. AI does not introduce uncertainty into IAM. It makes the existing uncertainty impossible to continue ignoring.
“AI doesn’t bring non-determinism to IAM. It just makes our previous assumptions about determinism untenable.”
This is actually productive news. It means the conceptual groundwork was already being laid - in continuous authentication, passive risk assessment, step-up flows based on real-time signals. The thinking exists. What is needed now is scale, and extension from single principals to entire identity graphs.
Four Things a New Model Must Do
The new model is not a single tool or standard. It is a set of capabilities that must work together - and that must work at every point in the graph, not just at its edges.
Maintain trust continuously, not momentarily. Identity assertions cannot be made once at login and assumed valid thereafter. They must be continuously re-evaluated against risk and recognition signals - not as an exception process, but as the operational baseline.
Authorize dynamically at every hop. Static role assignments and entitlement lists fail in a world where the access path is emergent. Authorization must be policy-based, attribute-aware, and context-sensitive - evaluable at any point in a transaction chain, not just at its start.
Govern relationship graphs, not individual principals. The unit of IAM governance is no longer a single user or workload. It is the chain of humans, agents, sub-agents, tools, and delegations that together constitute a real-world access event. Frameworks must be able to represent and govern that entire graph.
Treat assurance as a continuous outcome. The goal is not to check a box at provisioning time. It is to maintain a quantifiable, continuously updated level of assurance across every actor, at every point, throughout every transaction.
The building blocks of the new model already exist: continuous authentication, policy-based authorization, identity fabrics, Zero Trust. What is missing is their integration into a coherent framework that explicitly addresses the transition from directed to networked, and from deterministic to non-deterministic access. That framework needs to be built now, because agentic AI is already in production, already moving faster than any governance process was designed to handle.
The IAM framework most organizations rely on today was designed for a different problem: known actors, predictable paths, auditable decisions. It solved that problem well. Agentic AI is simply a different problem. Organizations that recognize this now will govern their AI deployments. The ones that wait are still running on a simplification that agentic AI has long since made untenable.
KuppingerCole will continue developing the directed-to-networked, deterministic-to-non-deterministic IAM framework in research, advisory, and at EIC 2026 in Berlin. If these questions are live in your organization now, we would be glad to talk.