Breaking
SecurityDeveloping Story

AI Speed, Human-Speed Guardrails

A SailPoint report finds most organizations still run identity security at human speed even as they deploy AI agents that operate far faster.

··3 hours ago·6 min read
closeup photo of turned-on blue and white laptop computer
Photo by Philipp Katzenberger on Unsplash

Enterprises are pushing autonomous AI agents into production to move faster, but the controls meant to keep those agents in check were designed for a workforce that logs in, works a shift, and logs out. A report from identity security vendor SailPoint describes that mismatch as a "velocity paradox": AI-speed operations running on human-speed governance. The gap is not about effort, the report argues, but about architecture — and the data it cites suggests most organizations haven't begun to close it.

A Market Stuck Near the Start

Identity and access management has absorbed years of investment, yet the report finds the market's overall maturity has plateaued. The center of gravity remains in the foundational tiers: a combined 60% of organizations sit in Horizon 1 ("No Formal Program") or Horizon 2 ("Manual, Tool-Assisted").

That persistence matters because it points to a structural ceiling rather than a spending problem. Playbooks built to govern human employees — onboarding, periodic reviews, ticketed approvals — may not scale to autonomous agents executing thousands of transactions per minute.

The report's framing is blunt: the operational models that worked for a human workforce were never designed for identities that appear, act, and disappear faster than any review cycle can track.

Two Timelines, One Organization

The paradox shows up most clearly when human and non-human identity programs are measured side by side. According to the report, the two are moving in opposite directions.

For human workforces, maturity is improving. Five years ago, 45% of organizations sat at the lowest maturity level (Horizon 1). Today that figure has been cut nearly in half, to 23%.

For non-human and AI agent identities, the picture reverses. Today, 54% of organizations sit at Horizon 1 for agent identity security — a worse starting point than human security had five years ago.

The report calls this a coverage gap, not a competence gap. Organizations with solid human-access programs are still struggling to extend those same standards to cloud workloads and agentic environments.

Where Human Playbooks Break Down

The mechanics of the failure are familiar to anyone who has tried to apply employee-style governance to machine identities. The report identifies a "digitization trap" for organizations in the middle maturity tiers: they have successfully digitized human-centric processes such as employee onboarding and periodic access reviews, then applied the same scheduled review cycles to ephemeral machine identities that may exist for only minutes or seconds.

The result is operational drag at best and functional uselessness at worst — a review that arrives after the identity it was meant to govern has already been retired.

Breaking into the upper horizons requires a different approach. Advanced organizations, the report says, have moved away from manual, ticket-based access decisions and replaced standing privileges with continuous, contextual, and automated policy enforcement that operates at machine speed.

The 'Balance' That Isn't a Strategy

Asked to weigh speed against security, nearly half the market — 49% — claims to balance both equally. The report treats that answer with skepticism.

A stated posture of balance without the underlying operational capability to enforce it is not a strategy, according to the report's analysis. It is a stall.

That is where much of the market currently sits: an AI-speed ambition resting on a human-speed foundation, unable to move decisively in either direction while it waits for an architectural shift to resolve the tension.

Why This Reads as a Coverage Problem

The report's central claim is that the issue is not rebuilding identity programs from scratch. The immediate priority it identifies is extending proven governance disciplines to cover the unmanaged non-human identities already operating across a company's digital estate, and unifying them into a single fabric that can match the speed of AI.

That framing matters because it shifts the conversation away from replacing everything. If the diagnosis is a coverage gap, the remedy is extension and unification rather than wholesale replacement — a distinction that changes both the cost and the timeline of any fix.

The report does not put a date on when organizations are expected to close the gap, and the data it presents describes where the market stands rather than projecting where it will land.

What the Numbers Show at a Glance

  • 60% of organizations remain in Horizon 1 or Horizon 2 — the two foundational maturity stages
  • 45% were at Horizon 1 for human identity five years ago, a figure that has fallen to 23% today
  • 54% of organizations sit at Horizon 1 for agent identity security today
  • 49% of the market claims to "balance both equally" when weighing speed against security

Taken together, the figures describe a market that has made measurable progress on the human side and almost none on the machine side — and that has largely settled into a position it cannot defend operationally.

Non-Human Identities Outnumber the Playbooks

The report's argument rests on a simple asymmetry: human identity programs have had years of iteration, tooling, and institutional attention. Agent identity security is being asked to inherit none of that head start.

Agents are described as ephemeral, autonomous, and rapidly multiplying — three properties that sit awkwardly beside governance models built around scheduled reviews and standing access. When identities exist for minutes or seconds, a quarterly review cycle is not a slower version of the right answer; it is the wrong instrument entirely.

The report's prescription follows from that: continuous, contextual, automated enforcement rather than periodic human approval. It is a model that assumes no one is available to click "approve."

The Cost of Waiting

The report's most pointed observation is about the middle of the market. Organizations that digitized human processes successfully now find those same processes generating drag rather than control when applied to machines.

That is a different kind of problem than neglect. It is the cost of doing the reasonable thing — maturing human identity governance — and then discovering the same discipline does not transfer.

SailPoint's recommendation is to fold unmanaged non-human identities into the same governance fabric rather than treat them as a separate, later project. Whether the market moves that direction is not something the report attempts to predict.

What This Means for Security Teams

The practical takeaway for security leaders is that the AI deployment curve and the identity governance curve are not running on the same schedule. Organizations are adding agents faster than they are adding the controls to govern them, and the report's data suggests this is a market-wide pattern rather than an outlier problem.

For teams planning AI rollouts, that gap could become the binding constraint. An agent that can execute thousands of transactions per minute inherits whatever access it is granted, and the report's findings imply that many organizations have not yet built the machinery to grant, review, or revoke that access at the speed the agent operates.

The report frames the fix as an extension of existing governance rather than a rebuild — which suggests the organizations best positioned to close the gap may be the ones that already invested in human identity maturity, provided they can translate those disciplines to machine-speed enforcement. That is an inference, not a forecast in the report, but it follows from its own diagnosis of where the failure lives.

Reporting based on original coverage from The Hacker News.

#identity security#ai agents#access management#security maturity#non-human identities

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories