Trending Topics

AI will force a rethink of identity security in 2026 – here’s how
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
In 2025, AI started to move beyond hype and into everyday use across enterprise environments. AI agents began taking on real operational tasks and, in doing so, exposed a major problem: tech has got identity wrong.
Existing identity management approaches were designed around humans and predictable software, but AI doesn’t fit neatly into either category. It makes non-deterministic decisions like a human, yet operates as software that requires persistent, wide-ranging access to systems and data.
That autonomy is exactly what makes AI valuable – and challenging to secure. To function independently, AI must interact across cloud platforms, Kubernetes environments, identity systems, and even other AI agents. Each of these interactions requires an identity.
Continuing to treat every new identity type as a separate problem adds complexity, creating silos that become harder to manage with every new system introduced. In 2026, the consequences of this approach will become increasingly hard to ignore.
Here are my thoughts on how organisations will demand a unified approach to identity management.
Non-human identity will become part of larger markets
As AI continues to learn human behaviour and tasks, the separation between identity types will blur further. In fact, this distinction will become obsolete, as organisations stop deploying security strategies that treat identities separately and instead tackle identity from a unified perspective.
This means there will no longer be a need for tools that address non-human identities in isolation. In 2026, we’ll see increased identity-related market consolidation as different identity types (human, AI, software and machine) converge into a single identity layer. This identity convergence will spill into adjacent security categories, accelerating consolidation across the cybersecurity stack.
The role of engineering in cybersecurity will expand
Security ownership is also beginning to shift as AI adds new complexity to modern infrastructure. Identity was historically managed mainly by IT teams, but this is increasingly shaped by how systems are designed, deployed and maintained.
In 2026, securing identity will require closer collaboration between IT and engineering. Protecting infrastructure from attacks that exploit AI-driven complexity will depend on shared responsibility, with identity embedded into engineering workflows rather than handled in isolation.
Agentic AI will be defined in more granular terms
In 2025, “AI agent” became a catch-all term for any software using LLMs to make decisions, which in turn has hidden important differences in how these systems operate. Some agents run in data centres, others are fully local, others act on behalf of a human owner, and some have their own independent identity.
Bringing all identity types into a single source of truth reduces governance complexity and improves visibility. This makes it easier for organisations to understand how different forms of agentic AI operate, and how they should be secured based on where and how they’re deployed.
While AI has definitely left its mark in the identity space, the implications will go far beyond cybersecurity.
Here are a few other predictions I have for the industry next year…
AI-native talent is going to be in short supply
It’s no secret that AI is reaching across industries and job roles. While many see this as a threat, the real challenge is the shortage of highly skilled, AI-native professionals.
This gap will be especially pronounced in security and security-engineering roles as AI becomes embedded directly into infrastructure. Identity complexity is already a significant challenge in modern environments, and as AI continues to automate decisions around access, threat detection and remediation, organisations will most likely see a rise in misconfigurations and privilege creep.
To counter this, CEOs will need to prioritise recruiting and developing AI-native security engineers who understand how models behave, where automation should stop, and how to design effective guardrails.
SaaS companies feeling threatened by AI are likely to tighten restrictions on their APIs
As AI agents get smarter, traditional user interfaces will matter less, letting AI tap directly into SaaS data. This risks sidelining legacy vendors, reducing them to little more than data storage. To protect their role, many will limit AI access to their APIs, trying to slow or even stop this disintermediation.
To summarise, identity is on the verge of its most significant transformation since IAM was first introduced decades ago. AI has exposed just how fragmented today’s identity systems have become, and 2026 will be the year organisations are forced to tackle the problem head-on – by shifting away from siloed tools toward a single, unified identity layer that governs humans, machines, software and AI agents as variations of the same core concept.
