THE IDENTITY GOVERNANCE TRIBUNE
How AI Agents Are Breaking Identity Governance Frameworks and What Practitioners Must Do About It
Agentic AI identity surges to the top of every analyst agenda, podcast feed, and vendor roadmap—as practitioners reckon with the uncomfortable truth that the frameworks they built weren't designed for this.
IDENTITY GOVERNANCE TRIBUNE
“2 out of 3 IGA programs already struggle to deliver on time. Now add AI agents that change their own behavior between certifications. We're not just behind—we're governing last week's identity in this week's environment.” That blunt assessment, delivered this week on the Radiant Logic podcast by identity analyst Simon Moffatt, landed like a stone in still water across the IGA community—and it captures a tension that every source, analyst, vendor, and podcast in this week's digest is circling from a different angle.
🎙️ THIS WEEK IN IDENTITY PODCASTS
Three podcast episodes are driving conversation this week, each approaching the agentic AI governance crisis from a different vantage point.
EPISODE SPOTLIGHT 1
Identity at the Center, Episode #441
Recorded live at Identiverse 2026, hosts Jeff Steadman and Jim McDonald welcomed two of the identity community's most respected figures: Sachini Siriwardene, winner of the prestigious Kim Cameron Award, and Ian Glazer, founder of the Digital Identity Advancement Foundation.
The conversation covered substantial ground: the AuthZen specification and what it means for externalized authorization; continuous access management as a replacement for point-in-time certifications; and—critically—how to separate genuine AI capability from the marketing hype now blanketing the identity industry. The episode also previewed a new industry honor, the Vittorio Bertocci Award, recognizing contributors to identity standards work.
"The question isn't whether AI belongs in identity," Glazer noted during the recording. "The question is whether the governance frameworks we're building today will still be meaningful in 18 months."
"The question isn't whether AI belongs in identity. The question is whether the governance frameworks we're building today will still be meaningful in 18 months." — IAN GLAZER, DIGITAL IDENTITY ADVANCEMENT FOUNDATION
EPISODE SPOTLIGHT 2
The Analyst Brief, E75: "Identiverse 2026"
Released June 30 and now circulating heavily on LinkedIn this week, Simon Moffatt and David Mahdi delivered what many practitioners are calling the sharpest post-Identiverse analysis of the year. The two analysts unpacked agentic identity, NHI security, and the wave of market consolidation reshaping the IGA landscape—including SailPoint's acquisition of Entro Security and Cisco's acquisition of WideField Security.
The thesis: market consolidation is not slowing down, and IGA+PAM+ITDR convergence is accelerating as vendors race to cover the AI agent governance gap. Organizations that are still running siloed identity programs are increasingly exposed.
EPISODE SPOTLIGHT 3 🔥 BONUS
Radio Logic feat. Simon Moffatt — Radiant Logic Podcast
Posted just two days ago on LinkedIn, this Radiant Logic podcast appearance by Simon Moffatt is already generating significant engagement. Moffatt opened with a statistic that stopped practitioners cold: 2 out of 3 IGA projects fail to finish on time or under budget—before adding that agentic AI layers an entirely new category of complexity on top of an already-strained discipline.
His core argument: most organizations are missing continuous, real-time observation of AI agent behavior—not just authentication. "You're not governing a static identity anymore," Moffatt said. "You're governing a moving target that is supposed to move—which breaks every assumption traditional IGA was built on."
"You're not governing a static identity anymore. You're governing a moving target that is supposed to move—which breaks every assumption traditional IGA was built on." — SIMON MOFFATT, IDENTITY ANALYST & RADIANT LOGIC PODCAST
🔥 HOT TOPIC: AGENTIC AI IDENTITY GOVERNANCE
This is the topic that won't quiet down—and this week, it is peaking.
Three converging forces are driving the urgency: massive market signals, documented governance gaps, and a crystallizing practitioner consensus that the old playbook is broken.
MARKET SIGNALS ARE LOUD
Saviynt launched Zuma—a purpose-built AI identity security platform—and followed it with a 12-city global roadshow (September 15 through November 20) with AWS as global sponsor. The roadshow's opening statistic is striking: 70% of organizations say AI systems hold more access than a human in an equivalent role.
Palo Alto Networks' new Idira platform, built from its acquisition of CyberArk's technology, explicitly targets agentic identity governance. SailPoint acquired Entro Security to close the NHI gap. These are not pilot programs or product experiments—they are billion-dollar strategic bets placed in a single quarter.
THE GOVERNANCE GAP IS DOCUMENTED
The NHI vendor map confirms that 92% of security teams are not confident that legacy IAM handles AI and NHI risks. The Identity Defined Security Alliance has announced a broadcast on September 23 specifically on AI agent identity protection—framing it as the fastest-growing, least-governed identity type in the enterprise.
PRACTITIONER CONSENSUS IS FORMING
Simon Moffatt's framing this week crystallized the problem in terms every IGA practitioner will recognize: you are not governing a static identity anymore. You are governing a moving target that is supposed to move—which breaks every assumption traditional IGA was built on.
📈 BY THE NUMBERS: AGENTIC AI IDENTITY IN 2026
- 92% — Security teams not confident legacy IAM handles AI/NHI risks
- 70% — Organizations where AI systems hold more access than equivalent human roles
- 80:1 — Ratio of non-human identities to human identities in the average enterprise
- 2 out of 3 — IGA projects that fail to finish on time or under budget
- $0 — Budget most organizations have allocated specifically for AI agent governance
- Sept. 23 — IDSA broadcast date: AI Agent Identity Protection
📅 MARK YOUR CALENDAR
📅 September 23, 2026 — IDSA Broadcast: AI Agent Identity Protection
The Identity Defined Security Alliance will host a focused broadcast on protecting AI agent identities—the fastest-growing and least-governed identity type in the modern enterprise.
Register at idsalliance.org
📅 September 15–November 20, 2026 — Saviynt UNLOCK 2026 Global Roadshow
12 cities. AWS as global sponsor. Anchored around the launch of the Zuma AI identity security platform and the statistic that 70% of enterprises say AI agents already hold more access than equivalent human roles.
Details at saviynt.com/unlock
📊 TRADITIONAL IGA VS. AGENTIC AI GOVERNANCE: THE GAP
DimensionTraditional IGA AssumptionAgentic AI RealityIdentity typeHuman users with stable rolesAI agents with dynamic, task-driven permissionsReview cadenceQuarterly or annual access certificationsContinuous, event-driven behavioral monitoringBehaviorPredictable; changes require provisioning ticketsSelf-modifying between certification cyclesOwnershipManager or role-based owner clearly definedOwnership often undefined at deploymentVolumeHundreds to thousands of human identities80:1 NHI-to-human ratio; scales exponentiallyAccess scopeRole-based, relatively static entitlementsBroad, often exceeds equivalent human role accessGovernance toolingPurpose-built IGA platforms (mature)Nascent; 92% of teams lack confidence in coverage