SailPoint report highlights identity security gap for AI agents

SailPoint’s Horizons of Identity Security report describes a widening identity security gap as enterprises deploy autonomous AI agents. While organizations aim to operate at AI speed, many still use controls designed around human users. The report calls this mismatch the “velocity paradox”: AI-enabled business operations are accelerating while security decisions remain dependent on human-speed processes.
The figures point to a market still concentrated in its earliest maturity stages. A combined 60% of organizations fall into Horizon 1, defined as having no formal program, or Horizon 2, where practices are manual and tool-assisted. SailPoint argues that this persistent pattern reflects an architectural limit rather than a simple lack of investment or effort.
Human identity progress has not carried over to agents
Identity security for human workforces has advanced over the past five years. The share of organizations at Horizon 1 for human identity fell from 45% to 23%. That improvement does not extend to non-human identities, including AI agents and cloud workloads. For agent identity security, 54% of organizations are currently at Horizon 1.
The contrast matters because a mature human identity programme does not automatically secure an agentic environment. Human-oriented controls are built around comparatively stable employees, defined onboarding steps and periodic reviews. Autonomous agents can be short-lived, operate at scale and multiply quickly, making those established workflows a poor fit for their identity lifecycle.
Scheduled governance cannot keep pace with ephemeral identities
SailPoint identifies a “digitization trap” in middle-maturity organisations. They may have digitised human processes such as employee onboarding and recurring access certification, yet applying scheduled reviews to machine identities that exist for seconds or minutes adds operational drag without providing effective governance.
The report contrasts that approach with the model used by organisations in the upper maturity horizons. Instead of manual ticketing and standing privileges, they apply continuous, contextual and automated policy enforcement. This shifts access decisions towards machine-speed trust, where governance can respond to the activity and conditions of non-human identities as they operate.
Nearly half of respondents, 49%, say they balance speed and security equally. SailPoint’s analysis warns that such a posture is insufficient without the operating capability to enforce it. The immediate business implication is to extend established identity governance disciplines across unmanaged non-human identities and unify them in a control fabric that can operate at the speed of AI.

