This was my seventh EIC as a KuppingerCole Analysts employee. And there are people in this community who have been coming for all nineteen years. What brings both groups back, and what draws new people in every year, is the same thing. This conference feels less like an industry event and more like a reunion of people who are genuinely working on the same hard problems.
What I notice year over year is simple. The conversations are getting more substantive, more cross-functional, and increasingly focused on the hardest aspects of IAM. And when you run into someone you worked with twelve years ago and spend ten minutes catching up on where those IAM programs stand today, that conversation alone tells you more about the state of the industry than most analyst reports.
Here is my take on EIC 2026 from where I sat. The short version: AI is setting the agenda, but the baseline work is setting the pace.
Agentic AI Was Everywhere. And Rightly so.
Agentic AI dominated the agenda this year, and rightly so. The implications for identity, authorization, and governance are profound. Martin Kuppinger's keynote extended the Fabric concept beyond identity, introducing the Cybersecurity Fabric and the AI Fabric as related but distinct architectures that share capabilities while serving different purposes. The same structured thinking that makes the Identity Fabric a useful tool for IAM architects now applies across a broader security and AI governance landscape.
That framing matters. Because what we see in Advisory conversations is exactly that challenge: organizations trying to make sense of overlapping capabilities, overlapping tools, and overlapping responsibilities across identity, security, and AI. The Fabric model gives them a way to think about that without starting from scratch.
There is a deeper tension here though. IAM has always been a slow-moving discipline by nature. But for roughly the last three to five years, the pace of change has fundamentally shifted. AI, non-human identities, agentic systems: these are not incremental developments. They are structural shifts arriving faster than most IAM teams can absorb. The technology is already in production. The governance frameworks, the best practices, the full lifecycle solutions: they are still catching up. That gap is real, and it was present in almost every serious conversation at the EIC. And it hits hardest where it was already difficult: IAM teams that were understaffed before AI arrived are now at serious risk of falling so far behind that catching up becomes structurally impossible.
But here is the Advisory observation: the organizations we talked to are not yet at the point of governing AI agents. Most of them are still working through foundational IAM challenges. CIAM strategy, IGA tool choices, target operating models, organizational alignment. Which raises the question that nobody has fully answered yet: how do we bring together where organizations actually are in their IAM maturity with what governing AI agents will require? That gap is the defining challenge the industry is now walking into.
The Identity Fabric Is Not Yet Common Knowledge
We opened our Tuesday workshop with a simple question: how many of you are familiar with the Identity Fabric concept?
More than half of the room had not encountered it before.
This is not a failure. It is a signal. The EIC community is growing. New people are entering the field, facing identity challenges for the first time, looking for frameworks that help them make sense of complexity. What landed was not a sales pitch but a structured way of thinking: the Identity Fabric, and our Reference Architecture combined with our Maturity Assessment as a practical starting point that gives organizations a clear path from where they are to where they need to be.
The workshop was full. And when Fressnapf's Lisa Zimmermann took the stage to walk through how we applied the Identity Fabric and the Maturity Assessment in a real project, the room got very quiet. That is what a real reference customer does. It turns a methodology into proof.
When Practice Meets Theory
One of the highlights of the week was Patrick Teichmann together with Oliver Schluga from Erste Digital on stage. What they presented was not a polished success story. It was an unfiltered account of what a large-scale IAM transformation actually looks like in practice, inside one of the biggest banking groups in Central and Eastern Europe.
The message they brought to the stage was one that resonates with almost every organization we work with: IAM has to fit the organization, accounting for its specific context and constraints, without becoming a collection of isolated solutions. That sounds obvious. In practice, it is one of the hardest things to get right. Erste Digital had started where almost every organization starts, with a clean top-down concept, business roles neatly aligned to processes, everything mapped out on paper. But when that concept met the actual environment, with eighty thousand users spread across different authorization systems ranging from SAP and Office 365 to AWS, GCP, and proprietary layers that had grown organically over years, the gap between theory and reality became impossible to ignore. The only viable path forward was the combined approach: understand what actually exists, identify what works, and build from there rather than trying to impose a structure the environment could not support.
What made this land was seeing a real project, with real complexity, presented without a filter. That kind of practitioner transparency is rare and exactly what a room full of people dealing with the same challenges needs to hear.
This connects to one of the sharpest recurring questions from the week: RBAC is dead, yes, but how does an organization actually move toward dynamic authorization in a way that fits its reality? What does that transformation look like in practice, not in a whitepaper? Erste Digital's journey is one of the most concrete answers to that question available right now.
For Advisory, this is exactly the conversation we have with clients every week. The technology is rarely the bottleneck. The organizational alignment, the business involvement, the ownership model: that is where projects succeed or fail. Seeing it confirmed live by a practitioner, in front of a room full of people dealing with the same challenges, is the kind of moment that makes the EIC worth attending.
What Organizations Are Actually Asking For
The Luncheon this year ran as an open dialogue around questions that turned out to be more loaded than they sound: what does the IAM professional look like in the future, given AI? And how do you actually operationalize all of these topics in practice? Both triggered long conversations. Because the straightforward answer to both is: nobody really knows yet, and most organizations are figuring it out as they go.
Nowhere was this more visible than in the governance debates around AI. The spectrum of positions in the room ran from "humans must have the final word on everything and must understand every decision" all the way to "agents need to run fully autonomously, with independent models validating each other's actions." Both positions have logic behind them. The reality will be somewhere in the middle. But the open question, the one that nobody could answer clearly, is whether that middle ground will satisfy auditors and regulators. That question is not rhetorical. It is one of the most consequential open problems in the field right now. On AIdentity specifically, intent security emerged repeatedly as the topic generating the most uncertainty. Not because people lacked opinions, but because the existing frameworks and best practices only partially apply. The field is still crystallizing what good looks like.
CIAM is a major topic. Multiple organizations, across banking, retail, and manufacturing, are in the middle of tool selections, implementation projects, or strategic realignments. The questions being asked are very concrete and operational. Organizations want to know whether a tool will actually cover their authorization requirements, what the target operating model looks like once it is live, and who owns and runs it three years down the line.
IGA governance is the other recurring thread. Some are carrying self-built solutions that have outgrown their original design and need a strategic path forward. Others are mid-implementation and realizing that the governance model was never properly defined to begin with. And in more cases than one might expect, the tooling is actually working fine, but the organizational alignment around it is not.
A third pattern was AI and Identity. Organizations across industries came in asking about AI and identity, and what quickly became clear was how much uncertainty still exists. Not about whether AI matters for IAM, but about how to actually approach it. How do you manage machine identities in practice? How do you think about access for AI systems? How does any of this integrate into an IAM program that is already in flight? The questions were real. The answers, in most cases, are still being worked out.
The Value of Being Present
What stood out this year was where the best conversations actually happened. Rarely at the booth, more often at the side events, over dinner, or in the corridors between sessions. The informal setting changes the dynamic completely.
The EIC creates a concentration of the right people in the right place that simply does not exist anywhere else in Europe for this domain. CISOs, IAM leads, architects, and decision makers, all in one building for four days, all focused on the same set of challenges.
For Advisory, that density translates directly into meaningful engagement across financial services, retail, manufacturing, energy, and the public sector, with organizations working through the same core questions from very different starting points.
The Bottom Line
EIC 2026 confirmed what we see in project work every week. The identity market is maturing, but unevenly. Agentic AI is the headline topic, and the underlying research and thinking from KuppingerCole is strong. But for most organizations, the path to governing AI agents runs straight through the IAM fundamentals they have not yet fully solved.
That is exactly what Advisory is for. Helping organizations understand where they actually stand, where they need to go, and what a realistic path between the two looks like.
See you at EIC 2027.