Early-bird Discount
expires in
Register Now

Blog

Innovating Identity: Ten Next-Gen Trends to Watch

Blog Post

Innovating Identity: Ten Next-Gen Trends to Watch

Martin Kuppinger
Aug 27, 2025

The next wave of identity innovation is already underway. It’s big. Bigger than most of the innovation we have seen over the past two decades. Bigger than a new authentication method and getting rid of passwords. Bigger than another Zero Trust checklist. What we’re seeing is a long-overdue modernization of the identity foundations that digital business depends on. This change won’t happen overnight, but the building blocks are here. They are already reshaping architectures well into 2040.

Let’s look at the ten key trends that are shaping the future of IAM and digital identity.

1. PBAC and beyond: The Comeback of a 50-Year-Old Concept

Policy-Based Access Control (PBAC) is not new. It has been around for decades. IBM RACF (Resource Access Control Facility) came to market back in 1976. It has been taken seriously as a scalable and dynamic alternative to static entitlements for long but didn’t really succeed. Why? IAM environments are too complex for simple (and even complex) role models. PBAC brings in context: Who is the user? What are they doing? What’s the risk level?

But PBAC in its earlier incarnations, such as around XACML (eXtensible Access Control Markup Language) also was too complex. New approaches such as OPA or Cedar are way more widely used.

PBAC enables precise, real-time decisions, but still depends on well-maintained policies and attributes. While not a silver bullet, it’s an essential step towards smarter access control. Bringing together PBAC and the AI potential will make it more of a silver bullet. Dynamic, AI-managed policies can deal with scale even in highly dynamic environments.

2. Modular Architectures: IAM Without the Monolith

IAM no longer comes in a shrink-wrapped box. Today’s platforms are increasingly modular: loosely coupled services orchestrated through APIs, workflows, and integration layers.

This modularity accelerates onboarding, reduces duplication, and allows for replacing or upgrading individual components without rewriting everything. In an era where agility is key, monoliths don’t scale. Modular IAM is what scales. That is what identity fabrics are about.

3. Orchestration as the New Control Plane

Orchestration is more than workflow. It’s a structural layer that decouples business logic, data, and user experience. That makes it the control plane of modern IAM.

A good orchestration platform does more than connect services. It enables identity journeys to evolve continuously without changing the underlying infrastructure. Think of it as the “brain” coordinating a flexible, ever-adapting identity fabric.

4. Decentralized Identity: Beyond the Hype

Yes, Decentralized Identity (DCI) has been hyped. But it’s also real and ready for enterprise use. Its biggest value? Solving the single source of truth problem.

In federated environments, DCI reduces the need for constant synchronization and data replication. It allows organizations to issue and verify credentials in real time. That’s a game-changer, especially in scenarios like IGA, dynamic access, and CIAM, where identity silos are a recurring pain point.

And let’s not forget the broader implications: portable credentials, reduced attack surfaces, and finally, user-controlled identity at scale.

5. Signal Sharing and Enrichment: From Static to Adaptive

Static decisions are out. Real-time signals are in. Standards such as CAEP (Continuous Access Evaluation Protocol) and the Shared Signals Framework (SSF) are enabling adaptive access based on shared context and dynamic risk levels.

The benefit? Continuous enforcement. A device that becomes risky can trigger access revocation. A change in location or behavior can lower confidence. This isn’t theoretical. It’s already happening, and it’s essential for any Zero Trust implementation worth the name.

6. Autonomous Identity: AI Doing the Heavy Lifting

AI is finally coming to IAM in a useful way, not to replace humans, but to support them where scale and speed matter most. We call this AIdentity, the intersection of AI and Identity.

Autonomous identity systems use AI models to spot anomalies, propose entitlements, and even grant or revoke access based on behavioral baselines. This is especially useful in high-volume or fast-changing environments, such as machine-to-machine (M2M) access, operational technology (OT), or large-scale IoT deployments.

Humans can’t write rules fast enough for these use cases. AI can.

7. AIdentity: Not Just for People Anymore

AI systems themselves are becoming digital actors. They make decisions, access resources, and trigger transactions. That raises a simple but critical question: Who governs their identity lifecycle?

Managing AI agents like users, with identity proofing, access controls, and lifecycle governance, is becoming a necessity. Identity is no longer just about humans or devices. It’s also about software that thinks and acts.

8. Beyond Passwordless: Toward Passive Authentication

We’ve talked for years about killing passwords. But just replacing them with biometrics or passkeys doesn’t go far enough. The real shift is from active to passive authentication.

Using contextual and biometric signals such as typing speed, location, usage patterns, but also behavioral data, systems can authenticate users continuously and invisibly. This improves both security and user experience.

In fact, frictionless security becomes possible when the system knows enough about you that it doesn’t have to ask.

9. Identity Meets Security: A Strategic Convergence

The lines between IAM and cybersecurity are blurring and that’s a good thing. Identity data is being used for threat detection. Access management is becoming part of incident response. The integration is already happening and should be encouraged.

This convergence doesn’t mean one platform for everything. It means common signals, shared context, and joint control logic. Identity security is not a buzzword. It’s the next layer of defense.

10. Machine Identities: The Quiet Explosion

Non-human identities are exploding. Devices, APIs, containers, bots, microservices – all these entities need credentials, governance, and lifecycle management. Yet most IAM programs still focus almost exclusively on humans.

This imbalance is unsustainable. Machine identity management must be elevated to a first-class citizen in IAM programs. Without it, we leave the back door open and we won’t even know it.

What Comes Next

These ten trends are not isolated. They are converging. Modular IAM supports orchestration. Orchestration powers DCI. DCI simplifies adaptive access. Adaptive access relies on signal sharing. Signal sharing is made possible by AI and policy-based controls. And all of this only works when human and non-human identities are managed equally well.

In short: the future of IAM is modular, intelligent, and decentralized. Identity is no longer just about access. It’s becoming the digital backbone of trust.

And that’s why it matters. 

Identity Fabric Impact Day

These trends aren’t just shaping the future in theory, they are being explored and tested in practice. At the Identity Fabric Impact Day, a hands-on event taking place on September 18, 2025, in Munich, these topics will be front and center. It’s an opportunity for practitioners and decision-makers to dive deep into modular IAM, orchestration, decentralized identity, AI-driven identity management and more - translating vision into practice.


KuppingerCole Analysts AG
Roles & Responsibilities at KuppingerCole As Founder and Distinguished Analyst, Martin Kuppinger oversees the KuppingerCole research, provides own research, engages in Customer Advisories in his role as Trusted Advisor, and acts as a Member of the Board. Background & Education Martin wrote more than 50 IT-related books and is known as a widely-read columnist and author of technical articles and reviews in some of the most prestigious IT magazines in Germany, Austria and Switzerland. He is a renowned global leader in Identity Management and Digital Identity and is among the top 10 experts in this field globally. He is also a well-established speaker and moderator at seminars and congresses. Martin holds a Bachelor in Economics. Areas of coverage Martin Kuppinger oversees all areas of KuppingerCole research and has outstanding expertise in areas such as cybersecurity, blockchain, and AI. Professional experience His interest in Identity Management dates back to the 80s, when he also gained considerable experience in software architecture development. Over the years, he added several other fields of research, including virtualization, cloud computing, overall IT security, and others. Having studied economies, he combines in-depth IT knowledge with a strong business perspective.
Almost Ready for IFID 2025?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.