Skip to main content

Access the full white paper

Read now

In a recent blog, Alasdair Murray, CTPO explored how organisations are racing ahead with AI adoption, yet struggling to translate that momentum into sustained, secure business value. That tension between ambition and execution is now playing out very visibly in identity and security.

Across enterprises, we’re seeing a consistent pattern:

  • AI adoption is outpacing control
  • Usage is accelerating faster than visibility
  • Identity architectures designed for humans are being stretched by machines, agents and models

This is the AI execution gap and in the context of Identity and Access Management (IAM), Identity Governance (IGA) and Identity Threat Detection and Response (ITDR), it is becoming one of the most material risks facing organisations today.

author-photo

Stacey Quintana, Head of Strategic Architecture

AI Powered Threats Concern

82%

of organisations worry about AI augmented cyber attacks

AI in Security Adoption

43%

of organisations are currently using AI in cyber security operations

Governance Gap for AI Agents

86%

of enterprises lack adequate controls to manage AI agents and non-human identities

AI adoption across enterprises is accelerating faster than the controls designed to govern it. Organisations are deploying copilots, assistants and autonomous agents at scale, yet many acknowledge that the guardrails around those systems remain immature. The result is a growing execution gap: AI is delivering productivity and innovation, but often without the visibility, accountability and assurance required to operate it safely.

At the centre of this gap sits identity. As attackers increasingly target credentials and privileged access, human and non‑human alike, identity systems have become the de facto frontline of cybersecurity. At the same time, AI introduces a new class of actors: agents, bots and service accounts that act continuously, across systems, and often with broad access. Many organisations are struggling to govern these identities coherently, with fragmented tools, limited integration and a shortage of AI‑specific security skills compounding the problem.

The market response is already taking shape. Large platform providers are embedding AI governance and agent controls directly into identity and access management suites, while a new generation of vendors is emerging around AI trust, risk and security management, including behavioural controls and so‑called “guardian” agents. The direction of travel is clear: away from siloed point solutions and towards unified, context‑driven platforms that can manage identity, risk and response together.

For organisations that close the execution gap, the upside is material. Strong identity governance combined with effective identity threat detection enables AI to be deployed faster, with greater confidence and fewer operational surprises. Where identity and access tools are consolidated and integrated into detection and response workflows, teams report improved efficiency and faster containment of incidents. Where the gap is ignored, the risk profile worsens and not because AI is inherently unsafe, but because it is insufficiently governed.

Over the next two to three years, AI governance will move firmly onto the board agenda. Operating models will evolve to span security, identity, architecture and the business, and success will increasingly be measured by outcomes rather than activity: how well identity controls support AI‑driven growth while limiting exposure. The organisations that lead in this phase will be those that treat identity and AI governance not as constraints on innovation, but as strategic enablers of it.

Stay Ahead of Identity, Security & AI Governance

Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.

Privacy Preference Center

Condatis
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.