IT Brief US - Technology news for CIOs & IT decision-makers
United States
Most firms run AI agents without proper security tools

Most firms run AI agents without proper security tools

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

SailPoint has released research showing that most enterprises are running AI agents in production without security tools designed for them, highlighting a wide gap between AI adoption and identity security readiness.

The survey of 340 senior identity, IT, cybersecurity and risk leaders across North America, Europe, Asia Pacific and Latin America found that 79% of organisations are running AI agents in production, while only 2% are using identity security tools built specifically to manage and govern them. SailPoint described this as a 40-to-1 gap.

The report focuses on identity security, which covers the controls used to manage access for both people and non-human entities such as machines, software accounts and AI agents. AI agents now account for 22% of all non-human accounts, yet 85% of organisations still rely on older identity tools not designed for agentic identities.

SailPoint's maturity model ranks organisations from Horizon 1, where there is no formal programme, to Horizon 5, where identity security is integrated across the wider ecosystem. The study found that about 60% of organisations remain in Horizons 1 and 2, while less than 1% have reached Horizon 5.

The report suggests the main weakness lies in non-human identity management rather than controls for staff and other human users. While 87% of respondents rated their human identity and access management as capable or better, only 43% said they had mature processes for managing agentic access.

The same divide appeared in the maturity scores. The share of organisations at Horizon 1 for human security fell from 45% in 2022 to 23% in the latest study. By contrast, 54% of organisations remain at Horizon 1 for agent identity.

Awareness gap

The report also pointed to a mismatch between executive confidence and operational readiness. While 80% of leaders believe the gap in their current tooling is moderate or smaller, only 15% can provision non-human access in real time.

A similar pattern emerged in regulation and audit preparation. While 57% of respondents said they were confident they could meet regulatory requirements, only 43% said they were prepared to provide verifiable evidence in an AI-related audit.

Baseline tasks also remain a major obstacle for many organisations. Credential lifecycle management, discovery of shadow AI and real-time monitoring were all identified as severe operational hurdles.

Wendy Wu, Chief Marketing Officer at SailPoint, said: "Compressing a five-year maturity curve into a single year presents a massive operational challenge, starting with a fundamental awareness gap. Many organisations don't yet realise that they do not have the right tools purpose-built for the scale and velocity of agent and non-human identity security. You cannot bridge this gap by asking human-speed tools to work faster; security must be built for machine speed from the ground up, with discovery, ownership, and access decisions happening in real time rather than on a quarterly review cycle. Enterprises waiting for their agent programs to mature the way their human programs did are going to find out the hard way that they don't have five years."

ANZ focus

The findings have direct relevance for Australia and New Zealand as organisations in the region increase their use of AI tools. According to the research, Asia Pacific remains at an earlier stage of identity security maturity than some other markets.

Nam Lam, ANZ Group Vice President at SailPoint, said: "Australian and New Zealand organisations are rapidly embracing AI to drive innovation and efficiency, which is a testament to the region's agility. However, our latest report reveals that 79% of organisations globally are managing non-human identities including AI agents with legacy identity security controls. This isn't just a technical gap, it's a significant business risk that leaves the door wide open for breaches. In Asia Pacific, with 37% of organisations still at the earliest stage of identity maturity, the immediate priority for ANZ leaders must be to extend their identity security strategy to discover, govern, and protect every single identity; human and non-human, because when something goes wrong, the tough questions will come from the board and local regulators."

The report said stronger identity controls for non-human entities are linked to operational gains as well as lower risk. Among organisations that have invested in securing non-human identities, 62% reported measurable productivity gains and 46% reported safer, faster AI deployment.

Insurance was another area highlighted by respondents. The survey found that 76% of leaders expect stronger identity governance to improve their eligibility for cyber insurance or the terms attached to cover.

SailPoint argued that companies need to move away from separate approaches for people, machines and AI systems and toward a single identity framework covering all of them. Organisations that progress to higher maturity levels are twice as likely to report significant productivity gains and three times more likely to deploy AI safely.