Oct 9
/
Latest News
SailPoint Report Warns of “Velocity Paradox” as AI Agents Outpace Legacy Identity Security
A new SailPoint report warns that enterprises racing to deploy autonomous AI agents are still relying on identity security architectures built for a different era. The “velocity paradox” described in the Horizons of Identity Security report shows organizations pushing AI‑speed operations while depending on human‑speed security controls that cannot scale.
The findings reveal that while businesses have spent years maturing identity programs for human employees, those same playbooks break down when applied to ephemeral, autonomous, and rapidly multiplying non‑human identities. Despite heavy investment in IAM, 60% of organizations remain stuck in Horizon 1 (“No Formal Program”) or Horizon 2 (“Manual, Tool‑Assisted”), showing that the market has hit an architectural ceiling rather than a lack of effort.
The maturity gap between human and non‑human identities is stark. Human identity programs have progressed significantly: five years ago, 45% of organizations were at Horizon 1, but today that number has dropped to 23%. In contrast, 54% of organizations sit at Horizon 1 for agent identity security — a worse starting point than human identity security half a decade ago. This is a coverage gap, not a competence gap, as enterprises struggle to extend proven governance disciplines to cloud workloads and autonomous agents.
The report outlines why legacy playbooks fail in the agentic era. Mid‑maturity organizations fall into the “digitization trap,” where human‑centric processes like onboarding and periodic access reviews are digitized but still operate on scheduled cycles. These cycles are useless for machine identities that may exist for minutes or seconds. Advanced organizations are shifting to machine‑speed trust models, replacing standing privileges with continuous, contextual, automated policy enforcement.
Nearly half of the market (49%) claims to “balance” speed and security, but the report argues this is a false compromise. Without machine‑speed operational capability, balance becomes stagnation. Organizations remain stuck between AI‑speed ambition and human‑speed foundations, waiting for an architectural shift that can resolve the paradox.
The report concludes that securing autonomous enterprises does not require rebuilding from scratch. Instead, organizations must extend their governance frameworks to cover unmanaged non‑human identities and unify them into a single fabric capable of matching AI velocity. For deeper insights, SailPoint’s full Horizons of Identity Security report is available here.
The findings reveal that while businesses have spent years maturing identity programs for human employees, those same playbooks break down when applied to ephemeral, autonomous, and rapidly multiplying non‑human identities. Despite heavy investment in IAM, 60% of organizations remain stuck in Horizon 1 (“No Formal Program”) or Horizon 2 (“Manual, Tool‑Assisted”), showing that the market has hit an architectural ceiling rather than a lack of effort.
The maturity gap between human and non‑human identities is stark. Human identity programs have progressed significantly: five years ago, 45% of organizations were at Horizon 1, but today that number has dropped to 23%. In contrast, 54% of organizations sit at Horizon 1 for agent identity security — a worse starting point than human identity security half a decade ago. This is a coverage gap, not a competence gap, as enterprises struggle to extend proven governance disciplines to cloud workloads and autonomous agents.
The report outlines why legacy playbooks fail in the agentic era. Mid‑maturity organizations fall into the “digitization trap,” where human‑centric processes like onboarding and periodic access reviews are digitized but still operate on scheduled cycles. These cycles are useless for machine identities that may exist for minutes or seconds. Advanced organizations are shifting to machine‑speed trust models, replacing standing privileges with continuous, contextual, automated policy enforcement.
Nearly half of the market (49%) claims to “balance” speed and security, but the report argues this is a false compromise. Without machine‑speed operational capability, balance becomes stagnation. Organizations remain stuck between AI‑speed ambition and human‑speed foundations, waiting for an architectural shift that can resolve the paradox.
The report concludes that securing autonomous enterprises does not require rebuilding from scratch. Instead, organizations must extend their governance frameworks to cover unmanaged non‑human identities and unify them into a single fabric capable of matching AI velocity. For deeper insights, SailPoint’s full Horizons of Identity Security report is available here.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.