SailPoint Report Reveals Major Identity Security Gap for AI Agents

0
SailPoint has released its fifth annual Horizons of Identity Security report, finding a significant gap between enterprise AI adoption and the identity security controls needed to govern AI agents. While 79% of organizations are running AI agents in production, only 2% use identity security tools specifically designed to manage and govern them, creating what SailPoint describes as a 40-to-1 governance gap.

This gap is driven by a stark divergence in security maturity between human and non-human identities. While organizations have made impressive strides with human security—nearly halving those at Horizon 1 maturity from 45% in 2022 to just 23% today—the explosion of autonomous AI agents has introduced a new deficit.

Agent identity starts from a steep lag, with 54% of organizations currently sitting at Horizon 1. With AI agents already active in production, enterprises do not have the luxury of a five-year runway to catch up; they must compress a five-year human security curve into a one-year agent timeline.

Wendy Wu, Chief Marketing Officer at SailPoint, said:

“Compressing a five-year maturity curve into a single year presents a massive operational challenge, starting with a fundamental awareness gap. Many organizations don’t yet realize that they do not have the right tools purpose-built for the scale and velocity of agent and non-human identity security. You cannot bridge this gap by asking human-speed tools to work faster; security must be built for machine speed from the ground up, with discovery, ownership, and access decisions happening in real time rather than on a quarterly review cycle. Enterprises waiting for their agent programs to mature the way their human programs did are going to find out the hard way that they don’t have five years.”

Key findings:

  • AI adoption has severely outpaced security controls: AI agents now represent 22% of all non-human accounts, yet 85% of organizations continue to rely on legacy identity tools not designed for agentic identities.
  • Overall maturity remains anchored at foundational levels. Roughly sixty percent of organizations remain in Horizons 1 and 2, while less than 1% have achieved Horizon 5. This lag is overwhelmingly driven by non-human identity deficits: 87% rate their human IAM capabilities as capable or better, while only 43% report mature processes for agentic access.
  • A pronounced awareness gap masks operational vulnerability: 80% of leaders believe the gap in their current tooling is moderate or smaller, yet the operational reality is that only 15% can provision non-human access in real time. Similarly, 57% express confidence in meeting regulatory requirements, while only 43% feel prepared to produce verifiable evidence in an AI-related audit.
  • Foundations remain the primary operational roadblock. Before enterprises can realize dynamic, intent-based security, they must first master baseline hygiene and visibility. Credential lifecycle management, shadow AI discovery, and real-time monitoring are rated as severe operational hurdles across the market.
  • The business value of non-human identity security is immediate and measurable: Mature identity programs deliver significant business velocity. 62% of organizations that have invested in securing non-human identities report measurable productivity gains, and 46% report safer, faster AI deployment. Looking ahead, 76% of leaders expect stronger identity governance to improve their eligibility for — or the terms of — cyber insurance.

The report concludes that the mandate for security leaders is to move from a fragmented, human-centric approach to a unified identity fabric that governs all identity types—human, machine, and AI agent—with continuous, context-aware automation. By advancing from foundational tiers (Horizons 1-2)—where organizations struggle with manual controls and lack basic visibility—to advanced maturity (Horizons 4-5), enterprises gain the real-time visibility and automated policy enforcement needed to secure autonomous agents.

This transition pays off well beyond basic compliance; mature organizations are twice as likely to realize significant productivity gains and three times more successful at deploying AI safely, effectively transforming compliance from a reactive audit scramble into a state of automated, continuous assurance. This is the only path to closing the security gap while enabling the full velocity of the autonomous enterprise.

To read the full 2026-2027 “Horizons of Identity Security” report, please visit here. 

Related News:

SailPoint Expands Identity Security Platform with Human Fabric and IdentityIQ 9.0

Cowbell Launches Risk Advisor for AI-Powered Cyber Risk Guidance

Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.