Crowded technology conference with humanoid robots and professionals discussing AI and secure identity solutions

Identiverse 2026 Recap: Identity Security For Agentic AI Dominates

Agentic AI changes identity from a perimeter control into an operating discipline. For CIOs and security leaders, the management challenge is no longer whether agents can authenticate, but who owns their lifecycle, what decisions they can make, and how those decisions are audited across business processes. That pushes IAM out of a narrow security function and into shared governance with product, legal, procurement and platform teams.

The trade-off is speed versus control. Pre-approved autonomy can reduce friction in procurement, customer service and internal operations, but every increase in delegation expands the blast radius of errors, fraud and policy drift. Leaders should expect pressure to move faster than standards mature, which makes a clear approval model essential: which agent types are allowed, which actions require human escalation, and which use cases are prohibited until controls prove effective.

Accountability is the first design decision, not the last. If an agent acts on behalf of a person, a team or a supplier, enterprises need a documented ownership chain that links intent, identity, entitlements, telemetry and remediation. Without that chain, incident response becomes guesswork and auditability collapses. The practical next question is whether existing IAM, GRC and service-management workflows can represent agent behavior cleanly, or whether a separate control layer is needed.

Standards will matter, but waiting for perfect convergence is a governance choice with cost. Early adopters face technical debt if they assemble one-off controls, yet delaying implementation leaves exposed business processes unmanaged. Decision-makers should ask: which standards are already supported by current vendors, what minimum telemetry is required to detect misuse, and how will risk be measured in business terms rather than technical events alone? The winners will be those that treat agent governance as a portfolio decision, not a point product purchase.


Last weekโ€™s Identiverse conference in Las Vegas left no doubt that the scope and importance of identity security is now magnified. Identiverse 2026 underscored the current transition in identity security as organizations grapple with an expanding universe of identities beyond humans. As Ping Identity CEO Andre Durand framed it in his opening keynote, the industry is shifting toward โ€œactions, not accessโ€ โ€“ a move from static access control to continuous, real-time identity decisions that govern what entities can do.

Conversations across the event highlighted the growing importance of governing non-human identities (NHIs), AI agents, and machine-driven interactions as first-class security concerns. NHI and AI security was also the predominant theme across the 200+ booths in the expo hall. ย Amidst the crush of AI-infused presentations and vendor messaging, the conference also stood out as a testament to the range of identityโ€™s reach, featuring breakout sessions spanning mobile driverโ€™s licenses (mDLs), data and privacy, fraud, FIDO passkeys, cybersecurity architecture, software development practices, industry standards, threat detection and response, and operational resiliency.

AI agentsโ€™ adoption is unstoppable, during the conference we heard presenter estimates that 75-85% of organizations have already started adopting AI agents. Security, and in particular Identity and Access Management, continue to play an oversized role in securing AI agents.

AI agents represent an autonomous, non-deterministic, and numerous non-human identity type but also present a new channel for user interaction (e.g.: human users can spawn their own enterprise data collection, and consumer purchase agents). Here are our main takeaways from Identiverse 2026:

  • New discovery and governance methods are required. AI agents do not fit into the existing mold of static and human time horizon Identity Management and Governance (IMG/IGA) tooling and processes. AI agent governance is more real time, context aware, and build-time intent aware. Delegation to a uniquely identified agent, and not impersonation is the recommended design pattern. AI governance should also look at agent provenance and reputation using repositories, agent suppliers (e.g.: Amazon shopping agents).
  • AI Agents Require new access policy decision frameworks. AI agentsโ€™ authentication to MCP servers is the easier, more mature part: they use OAuth 2.1 OIDC tokens to authenticate to MCP servers and other resources. AI Agent authorization is where we are seeing the greatest paradigm shift from simple static, ABAC/RBAC authorization policies to much more contextual, intent-verified, boundary constrained (โ€œthis agent can only spend up to $300 on buying kitchenware from an eCommerce siteโ€). Authorization is just-in-time, context (network, jurisdiction, resource) and must happen in real time. The conference reinforced the growing momentum behind more dynamic, fine-grained authorization.
  • Risk definition and measurement is still unclear. AI agentsโ€™ actions represent financial and reputational risk to organizations. For example, in a B2C use case, a purchasing AI agent may 1) scrape a website and hoard a cart, 2) make fraudulent purchases, and 3) perform actions that cause dissatisfaction for the agentโ€™s human owner. Defining, keeping track of and abating these risks does not yet have a mature product solution.ย  End user organizations are currently using in-house built telemetry and solutions for this purpose.
  • IAM for AI agents must fit into an organizationโ€™s IAM mesh. AI agent identities must be tied and correlated to human identitiesโ€™ access management in enterprise IAM. IAM for human and deterministic machine identities remains an organizational challenge โ€“ adding IAM requirements for AI agents further complicates the landscape. Trying to cobble together a non-standards based IAM solution to manage AI Agents can quickly create technical debt. Okta, Microsoft and Ping Identity have just introduced frameworks for IAM for AI agentsโ€“ their ready to deploy blueprints with examples are overdue and solid starting points for managing AI Agent identities.
  • Identity standards is ongoing but not unified. Auth.md, ID-JAG, SPIFFE, AUIC-1, IETFโ€™s RFCs and other standards are either not final, work in progress or are less than 12 months old. Commercial and in-product support is still scarce but rapidly improving. Anecdotally, we found that organizations are still waiting for AI agent security standards to solidify, mature, and become commercially supported before fully implementing them.

Overall, Identiverse 2026 underscored that the next phase of identity security will be defined by how effectively organizations extend governance to autonomous systems, unify identity data across silos, and operationalize identity intelligence in real time.

Forrester clients who want to dive deeper into this topic and discuss how they should implement IAM for agents shouldย schedule an inquiry or guidance sessionย with us.

ย 

ย 

ย 

ย 

https://www.forrester.com/blogs/identiverse-2026-recap-identity-security-for-agentic-ai-dominates/

Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.