TL;DR –
A new IDC whitepaper, commissioned by GuidePoint Security, explores why identity is the foundational control plane for securing agentic AI and what organizations should prioritize as adoption accelerates.
Service accounts. Application identities. API keys. Machine workloads. These are just a few examples of non-human identities (NHIs) that already outnumber human identities in many environments. The rapidly increasing use of AI agents expands the imbalance. Respondents in a new IDC study said their NHIs are outpacing existing identity and access management (IAM) programs, with ratios of NHI to human identities cited as high as 75 to 1.
A new IDC whitepaper, Managing Agentic AI Through the Identity Control Plan: What Organizations Should Look For, examines challenges artificial intelligence (AI) has introduced to security and identity leaders and what they need from vendors today to close the security gap. The study draws on responses from a qualitative panel of senior security and identity leaders spanning across industries, corroborated with quantitative results from three IDC surveys covering more than 2,500 respondents.
“IAM became a board-level priority for me when my discovery report revealed that we have over 500 AI agents operating within our network and systems, far more than the handful I initially estimated.”
– Security Architect, Enterprise IT
AI is further shifting the security perimeter away from the network and identity is emerging as a new security perimeter and primary control plane. With that evolution,identity has solidified its position as a board-level and buying-center issue for mitigating enterprise risk.
Today, agentic AI runs through three control planes, the IDC study finds: identity, data and runtime. All three matter, but they are not peers. Data controls and runtime controls each depend on knowing, with confidence, which agent is acting. Therefore, identity is the foundational control plane that allows the other two to work.
IDC research shows that abused NHIs were the initial entry point in 19% of the most recent identity incidents among the 651 organizations who reported a confirmed incident, effectively tied with phished or stolen credentials at 19.5%.
NHI and AI agent security is now a top two IAM program priority for 43.7% of organizations over the next 12 to 24 months, alongside identity governance modernization (50.7%) and privileged access management (PAM) modernization (50.6%).
Interestingly, a substantial 77.3% of organizations report high or very high confidence that they can see all human identities and NHIs across on-premises, cloud and SaaS. Yet the same survey shows that only 18.5% run continuous identity discovery and inventory or ownership gaps rank among the most cited non-human identity challenges (42.0%). Additionally, bots, RPA and AI agents are the least covered non-human identity type in current management programs, secured by only 41.5% of organizations. High confidence built on quarterly snapshots of the categories that exclude agents is exactly the false assurance the study panel’s discovery stories puncture.
Governing AI agents is not the same as governing humans and that difference is producing a consistent set of pain points across organizations interviewed in the study:
“I cannot see or count my agents.” Most organizations cannot state an exact agent count. Every respondent flagged the inability to account for the total number of agents operating in their environment.
“Privilege is sprawling at machine speed.” Only 18% of organizations enforce least privilege through just-in-time (JIT) access with automated remediation; 34.4% use automated entitlement right-sizing and nearly half still rely on policy-driven or manual access reviews.
“I can no longer trust the human signal.” The threat model has shifted to synthetic trust. AI-generated impersonation means human signals such as a voice on the phone or a face on a video call can be fabricated. Identity-proofing that assumes a real person on the other end no longer holds.
“There is risk I do not control: shadow AI and vendor-embedded AI.” Third-party vendors are embedding AI agents into SaaS applications, creating exposure that existing identity programs do not reach.
The paper dives into more paint points and solutions to address them.
Among the security and identity leaders who participated in the research, there was strong consensus on the answer: every agent needs a named human sponsor and a managed lifecycle. Where organizations differ most is in how far they have matured in their approach to agent identity, not in the destination they are maturing toward: a purpose-built, distinctly governed identity class for every agent. The variation across organizations is a maturity gap, not a standing disagreement.
In Part 2 of this series, we will walk through IDC’s maturity model for agent identity management and the operating model organizations can adopt today.
IDC White Paper, sponsored by GuidePoint Security, Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look for, #US54897326-WP, September 2026
Integrated Marketing Campaigns Manager
GuidePoint Security
