Early-bird Discount
expires in
Register Now

Blog

Your Identity Fabric Wasn't Built for AI Agents

Blog Post

Your Identity Fabric Wasn't Built for AI Agents

Jonathan Care
Aug 24, 2026

IBM's 2026 Cost of a Data Breach report found that 13% of organizations had suffered a breach of an AI model or application. Of those, 97% reported having no proper AI access controls in place.

Almost every organization breached through its AI estate had failed to extend to its AI systems the control discipline the identity industry has spent decades building.

It is tempting to read those organizations as careless. More likely, the architecture most enterprises now call an Identity Fabric has simply never been tested by an actor that behaves like an AI agent. Agents are the first identity population your fabric was not designed for, and they will find every seam in it.

This post makes three arguments: that "non-human identity" has stopped being a single governable category, that agentic AI separates designed fabrics from accreted ones, and that identity is necessary but not where this gets decided.

"Non-human identity" stopped being one thing

The term did real work. It marked off a population that behaved nothing like human users: cloud workloads, ephemeral containers, service accounts, IoT devices, machine-to-machine traffic. Then AI agents arrived, and the population split.

The exact multiple varies by source. KuppingerCole Analysts puts machine identities at more than 50 for every human; Palo Alto Networks' 2026 Identity Security Landscape report puts it at 109 to 1, up from 82 to 1 a year earlier, and attributes the increase to AI agents rather than to growth in the older population of service accounts and workloads. Other published estimates range from 17:1 to 144:1 depending on how much of the estate gets counted, but none of them puts the older, non-agent population anywhere near a majority of the total.

Palo Alto's own breakdown makes the point directly: of the 109 machine identities per human, 79 are AI agents. That is the figure worth sitting with. Treat it with some care, since a census counting everything marketed as an agent will overstate how much of the population is genuinely autonomous, but even a conservative reading puts AI agents at most of the non-human estate already.

The useful cut runs along autonomy, not humanity. As Alexei Balaganski argues in From Identity to Access, dependent identities such as workloads and devices act only as extensions of the system that owns them. Autonomous identities act on their own behalf within a delegated mandate, which puts them closer to a privileged human than to a workload.

The two classes fail differently. Dependent identities fail through scale and credential sprawl. Autonomous identities fail through missing accountability and unbounded blast radius. A governance model tuned for the first leaves the second largely uncovered.

Agentic AI separates designed fabrics from accreted ones

Most organizations that say they have an Identity Fabric have not built one. They have accreted one: an IGA platform here, a PAM tool there, three IdPs from three acquisitions, a secrets manager the platform team bought quietly, and integrations that hold as long as nothing moves fast.

That arrangement survives human users because humans are slow. A person authenticates once, works at human speed, and generates access requests a review board can plausibly inspect.

Agents remove the cushion. A single high-level task spawns dozens of sub-actions across multiple systems at machine speed, and agents delegate to further agents as they go. Every seam becomes a place where accountability is lost, faster than anyone notices.

This is where the Identity Fabric earns its keep or fails to. A fabric is a deliberate capability model with governance attached, not a diagram drawn after the fact to explain what procurement happened to buy.

Two sessions at Identity Fabric Impact Day 2026 in Cologne address this question directly. Matthias Jarka of WACKER opens with "Steering Identity as a Fabric," on how WACKER structures, evolves and actively governs its IAM: the operative word is actively. Marco Venuti, Field CTO at SGNL, follows with the orchestration toolbox and the adoption patterns separating organizations that have moved from integration to orchestration from those still wiring point to point.

Identity is necessary, not sufficient

Knowing who or what is acting solves very little of the security problem on its own, because the risk lives in what the actor is permitted to do. Balaganski's conclusion is that access, not identity, is the control point, and that enforcement belongs at the resource: the API, the service, the database where the action lands. Authorization at a gateway is coarse, and authorization left to an agent's own instructions is not authorization at all.

Three consequences follow.

  • An API key is a secret, not an identity. Conflating entity, identity, account, credential and access is the most consequential mistake in the current vocabulary, and it is baked into many products that operate at one layer while carrying the name of another.
  • Every account traces to an accountable owner. Attestation proves only that the thing presenting a credential is the thing that was enrolled. It never proves the enrollment should have happened.
  • Pre-scripted access does not hold. Autonomous actors combine permissions in unplanned sequences and pursue intermediate steps nobody wrote down, which forces continuous evaluation, in context, at the moment of action.

Anmol Singh, Director and Global Head of IAM at Olympus Corporation, takes this on with a session on evolving the fabric for autonomous identities through delegation, governance and runtime authorization. Jonathan Neal, SVP and Field CTO at Saviynt, pushes further with "From Identity Fabric to AI Control Plane." Both are the right argument to be having; neither has a settled answer yet.

What to build, rather than what to buy

The vendor market is moving faster than the control problem is understood. My own advisory note, Navigating the Agentic AI Security Landscape, maps six categories across prevent, observe, detect/respond and govern, split into three procurement tracks with different buyers and budgets. Buying from the wrong track is a common and expensive error.

Architecture before procurement

In From AI Agents to Trusted Digital Workers, Martin Kuppinger sets out four pillars for governing agent identities: registration and lifecycle management, multi-tier authorization, governance and oversight, and auditability with provenance. The paper sequences them across three horizons, separating what enterprises can do now from what waits on standards that have not stabilized yet.

None of the four requires a new product category to begin. Registering agents as first-class identities with named owners is a lifecycle exercise your IGA platform can already model, badly at first. Establishing that every agent action resolves to an accountable human takes a policy decision, not a product. Both are unglamorous, and both are prerequisites for whatever the runtime authorization vendors sell you next year. Ownership is the harder gap: governance that belongs to no named team defaults to the platform teams shipping the agents, the one group with no incentive to constrain them.

Which is why Matthias Reinwarth closes the day with "The Fabric Is Not the Deliverable: What You Build on Monday." The fabric is the means. The governed access is the outcome.

The takeaway

The non-human category has split, and autonomous identities need a governance model closer to privileged human access than to infrastructure. And identity is the prerequisite, not the control point: enforcement has to reach the resource.

Identity Fabric Impact Day 2026 takes place on September 9 at the Hilton Cologne. It is a single day built for the people who own this problem rather than describe it. Register here, and come prepared to argue.


KuppingerCole Analysts AG
Mr. Care served as a Senior Director Analyst at Gartner until 2022, accumulating 33 years of industry experience. During his tenure, he was a top-rated analyst responsible for defining the Fraud market and leading Gartner’s Insider Threat and Risk research. Prior to his stint at Gartner, Mr Care worked as a Security Engineer at Sun Microsystems for two years, a Senior Consulting Manager at Verisign for two years, and in Product Risk Research at Visa Europe for four years. Mr. Care holds several industry accolades and certifications, including as a Certified Fraud Examiner, PCI DSS-qualified forensic Investigator, PCI DSS-qualified security Assessor, PCI Payment Applications-Qualified Security Assessor, U.K. Government-Accredited Penetration Tester, and U.K. Government-Listed Security Advisor.​ Mr. Care is a writer for Dark Reading.  In addition to his cybersecurity career, Mr. Care is also an independent composer and songwriter, producing tracks for film/TV productions as well as streaming works. His music studio is based in Ancora, Portugal.
Almost Ready for IF Impact Day 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.