AI Agent Identity Security Trails Adoption 40 to 1, SailPoint Finds
SailPoint data shows 79% of enterprises run AI agents in production while only 2% deploy AI agent identity security, a 40-to-1 governance gap.
SailPoint's latest identity research puts a hard number on something enterprise security teams have described anecdotally for two years. In its fifth annual Horizons of Identity Security report, published on October 6, 2026, the Nasdaq-listed vendor found that 79% of organizations now run AI agents in production, while only 2% have deployed AI agent identity security built specifically to govern those agents. That works out to a deployment-to-control ratio of roughly 40 to 1.
The second statistic in the same research explains the first. SailPoint also reports that just 15% of organizations can provision non-human identities, the mechanical step that gives an autonomous agent a scoped, revocable set of permissions. Where that capability is missing, agent access is typically inherited from a human account, a shared service account or a long-lived API key that nobody rotates.
| Metric | SailPoint Horizons of Identity Security (Oct 2026) |
|---|---|
| Organizations running AI agents in production | 79% |
| Organizations using purpose-built agent identity security | 2% |
| Organizations able to provision non-human identities | 15% |
| Implied deployment-to-governance ratio | ~40:1 |
Read together, the figures describe a deployment curve that has separated from its control curve. SailPoint frames agent identity, entitlement and oversight as the emerging control layer for enterprise AI, and its argument is that autonomous agents have outrun the governance tooling meant to constrain them. SailPoint also sells into the gap it has measured, a commercial interest worth keeping in view. The measurement problem holds on its own terms.
Discovery is the first obstacle. Identity governance workflows are triggered by lifecycle events that agents do not generate: an agent has no hire date, no manager and no termination notice in the HR system. Security teams that cannot enumerate their agents cannot scope their permissions. The 2% figure therefore measures deployment of tooling rather than awareness of exposure, and the true share of organisations without effective agent controls is likely higher.
Why AI agent identity security lags
Every agent that can read a database, call an API and write a record is an identity with entitlements. The lifecycle tooling enterprises already own was designed for people, and it assumes identities that persist, respond to prompts and have a manager who can approve or revoke access. An agent created for a single task breaks all three assumptions.
Standing privilege compounds the problem. An agent built for a narrow job often keeps its credentials long after that job ends, and multi-agent workflows let one agent invoke another, so permissions propagate along a chain no human explicitly approved. The practical effect is that the attack surface is no longer measured by the number of employees holding privileged accounts. It is measured by the number of autonomous processes holding credentials that can act without a person in the loop.
Two kinds of AI risk, one security team
Enterprises are running generative and agentic AI at the same time, which leaves the same security group handling two distinct categories of exposure. A generative assistant that produces a flawed summary is a quality problem. An agent with write access to a finance system that produces a flawed transaction is an entitlement problem, and it requires controls the first category does not. Most security organisations were staffed before either workload existed.
Incident response is where the gap becomes visible outside the security function. When an agent takes an unauthorised action, the first questions are which identity it used, who approved those entitlements and what else that identity could reach. Without provisioning and audit records, those answers typically arrive days later through log forensics.
Vendors are shipping, but the category is young
SailPoint's answer arrived alongside the report: capabilities it groups under autonomous identity security, covering discovery of agents already running in an environment, temporary and just-in-time access for those agents, and compliance automation for what they do. Geordie AI's $30 million Series A points to the same conclusion from the investment side, namely that agent security is being priced as a standalone budget line rather than a feature of an existing platform.
Independent evidence points the same way. NeuralTrust's State of Agentic AI Security 2026 report found that 48% of AI agents in enterprise production environments run without meaningful security controls. Set beside SailPoint's 2%, the two datasets describe one condition from different angles: product and business teams ship agents, and the security function learns about them afterwards.
Incumbent identity vendors hold a distribution advantage and an architectural disadvantage. Agent governance needs credentials issued and retired at machine speed, which is a different design from periodic certification of a human workforce. Pricing for the young category is unsettled, with purpose-built agent security sold per agent or per non-human identity, which ties the bill to the same count most customers cannot yet produce accurately.
Extend, buy or build
Security leaders facing the 40-to-1 gap have three routes, and each carries a different cost.
- Extend existing identity governance. Reuses approval workflows and audit trails already in place, but the underlying model assumes persistent human identities with managers, which agents do not have. Lowest procurement friction, slowest to close the gap.
- Buy purpose-built agent security. Delivers agent discovery, non-human identity provisioning and short-lived credentials out of the box. The category is young, overlaps with incumbent governance suites, and adds a console and an integration to operate.
- Build in-house. Platform teams assemble their own credential broker and audit pipeline. Maximum control, maximum maintenance, and the resulting evidence still has to satisfy the same auditors.
The cost comparison is not straightforward. Extending an existing platform avoids a new procurement cycle but requires the vendor to model non-human identity objects, which not all do. A purpose-built product adds licence spend while cutting the engineering time needed to broker credentials. Building in-house concentrates risk in a small platform team that becomes a single point of failure when it turns over.
The choice usually tracks agent volume. A handful of experiments can be governed by extending what exists, provided long-lived keys are banned outright. Hundreds of agents in production, particularly in regulated processes, pushes toward a dedicated control plane, because quarterly access reviews were built for identity populations that change slowly. Agent populations can double inside a sprint, which turns a quarterly certification cycle into a lagging indicator.
The question for the board
The 40-to-1 ratio belongs on a board agenda because, unlike most security gaps, it can be answered. How many non-human identities exist in the environment? Who owns each one? When was each last reviewed, and what happens to its credentials when the agent behind it is decommissioned? Most organisations can answer the first question approximately and cannot answer the last at all.
Useful metrics are measurable. Agent inventory completeness, the share of agents holding scoped rather than inherited credentials, the median lifetime of an agent credential, and the lag between an agent's last action and the revocation of its access. Those four numbers turn an abstract governance gap into something a security team can be held to quarter over quarter.
Budget allocation follows the same split. Agent programmes are typically funded from product and engineering budgets, while identity governance sits in security. The gap SailPoint measured is partly an artifact of that structure: the team creating the identities is not the team accountable for governing them.
Why this matters
Adoption counts measure the wrong thing. A 79% deployment rate reads like leadership, but with governance at 2%, most of those agents operate on credentials that were never granted for that purpose, so the exposure grows with every agent added. The productivity case for agents holds; the control debt accumulates in parallel. Organisations that treat identity provisioning as part of the deployment checklist will be able to add agents without adding unmanaged privilege. Those that do not will spend the next budget cycle remediating access they cannot enumerate. The number worth tracking is the share of agents that can be named, scoped and revoked on demand.
Related Articles
- Global Workforce Study Reveals Critical AI Readiness Gap as Agentic Adoption Accelerates
- Enterprise AI Governance Failures Force Rollbacks for 74% of Live Agents
- Deloitte's 89% AI Agent Pilot Failure Rate Exposes the Enterprise Production Gap
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.