NIS2 obliges essential and important entities to implement risk management measures for their network and information systems — identity and access management is one of the areas where these obligations become concrete and auditable in practice. At the same time, the EU AI Act introduces accountability requirements for high-risk AI systems that raise questions identity governance has so far only had to answer for human users.
This talk examines identity management from two angles. First, as a regulatory requirement under NIS2: what the directive actually demands of organizations with regard to access control, and why this is a compliance question rather than merely a technical one. Second, as a field increasingly shaped by artificial intelligence: as AI systems and autonomous agents take on tasks previously carried out by people, enterprise identity management has to account for actions it was never designed to attribute.
The presentation closes with concrete recommendations for organizations seeking to align their identity strategy with both regulatory frameworks.