SailPoint Finds AI Agent Adoption Far Outpacing Identity Security

SailPoint research finds 79% of organizations run AI agents in production, but just 2% use purpose-built identity security tools to govern them.

Written By
Jordan Smith
Jordan Smith
Oct 7, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Enterprise adoption of AI agents is moving significantly faster than organizations’ ability to secure their identities, with new SailPoint research finding that 79% of organizations are already running AI agents in production, yet only 2% use purpose-built identity security tools to govern them.

The gap is emerging as enterprises give autonomous agents greater access to applications, data, and workflows. SailPoint found that 65% of organizations have made AI agents available to more than a quarter of their workforce, while only 23% report operating a fully modern identity stack.

The findings, published in SailPoint’s 2026-27 Horizons of Identity Security report, highlight a growing challenge for organizations—and potentially a significant opportunity for MSPs, MSSPs, security providers, and identity specialists—as businesses look to extend identity governance beyond employees to AI agents, service accounts, workloads, and other non-human identities.

AI agent adoption races ahead of identity controls

SailPoint describes the disconnect as an “AI velocity paradox”: enterprises are deploying autonomous technology capable of operating at machine speed while continuing to rely largely on identity architectures designed around human users and human-speed access decisions.

“Identity architectures built for humans cannot govern autonomous agents executing thousands of transactions per second,” the report states.

That does not mean most organizations have no controls around AI agents. Rather, SailPoint found that 85% continue to rely on legacy, general-purpose identity tools or platform-native controls to manage machine and AI agent identities. 

Only 4% use separate tools specifically for agent identities, and just 2% have implemented purpose-built identity security technology for AI agents.

The result is an expanding governance gap as non-human identities become a larger part of enterprise environments. Organizations that have spent years building controls around employee access now face the challenge of applying similar visibility, ownership, access, and lifecycle policies to autonomous systems operating at far greater speed and scale.

Advertisement

Confidence in AI identity security exceeds readiness

SailPoint’s research also points to a disconnect between how prepared organizations believe they are and the capabilities they can actually demonstrate.

While 57% of respondents expressed confidence in their ability to meet regulatory requirements, only 43% said they were highly prepared to produce the evidence needed for an AI-related audit. 

Similarly, 88% identified their human identity strategy as either a focus area or strategic enabler, but only 41% have a non-human identity strategy explicitly aligned with their enterprise AI roadmap.

The technology sector illustrates that divide particularly clearly: 80% of surveyed technology leaders believe the gap between their current identity tooling and what they need is moderate or smaller, yet only 15% can provision non-human access in real time.

SailPoint outlines a path to autonomous identity security

The report finds that organizations do not necessarily need to create a separate security architecture for autonomous agents.

It found that 64% of organizations surveyed already govern emerging machine and agent identities through centralized identity platforms. It indicates that the primary differentiator is not the adoption of disconnected niche tools but the establishment of a centralized governance framework that covers employees, third parties, service accounts, machines, and autonomous agents.

The report recommends extending the governance disciplines already established for human identities to the broader non-human identity estate.

This identity architecture converges around four foundational pillars:

  • Access: Zero standing privilege, dynamic policy enforcement, and machine-speed authorization.
  • Governance: Automated discovery and registration, ephemeral credentials, explicit ownership, and a unified control plan spanning human and non-human identities. 
  • Data and fabric: A unified identity graph linking human, service, and AI agent identities, with continuous behavioral telemetry and context-rich intelligence.
  • Security: Real-time integration with security operations, automated containment, closed-loop remediation, and preparation for post-quantum protection of machine identities.
Advertisement

These capabilities combine to create what the report describes as an autonomous identity fabric: a continuously operating layer connecting access, governance, data, and security across the enterprise.

Additionally, SailPoint outlined a three-stage roadmap to autonomous identity based on the maturity findings:

  • Stage 1: Discover – Organizations should establish complete visibility across human and machine identities. Priorities include cataloging service accounts, API tokens, scripts, and autonomous agents; detecting shadow AI; assigning explicit owners and business purposes to machine identities; and bringing non-human accounts into regular access reviews and audit assessments.
  • Stage 2: Govern – Organizations should standardize controls and automate identity lifecycles, including automating provisioning, privilege adjustments, and decommissioning for machine identities; enforcing credential rotations; aligning identity governance with enterprise AI roadmaps; and connecting human and agent signals through a unified identity graph.
  • Stage 3: Protect – Advanced organizations should move to machine-speed enforcement and continuous assurance. Capabilities include combining human and agent context in real time, implementing zero-standing-privilege and just-in-time access, applying dynamic, context-aware authorization, and integrating identity telemetry with security operations to support automated containment.

Ultimately, the objective of the roadmap is a continuous and largely invisible trust architecture in which identity security operates in the background rather than relying on periodic reviews and human-speed approval processes.

What the AI identity gap means for channel partners

For channel partners, the gap creates an opportunity to make identity security part of broader enterprise AI deployments. MSPs, MSSPs, integrators, and identity specialists can help customers discover and inventory non-human identities, establish ownership and access policies, and bring AI agents, service accounts, and other machine identities under the same governance frameworks already used for employees.

That opportunity extends beyond initial AI deployments. SailPoint’s roadmap calls for organizations to progress from discovering non-human identities to automating provisioning, privilege changes, credential rotation, and decommissioning before ultimately moving toward real-time authorization and automated containment. 

For partners, that could translate into ongoing identity modernization, AI governance, security operations integration, and compliance services as customers deploy AI agents more deeply into production environments.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.