Checking IDs for AI Agents

Sep 4, 2026

The rise of agentic AI is increasing demand for tools capable of identifying and governing non-human access, which could more than double the market for identity security.

Author
Meta Marshall, Head of Cybersecurity and Networking Research

Key Takeaways

  • The identity security market could more than double to $60 billion as agentic identification adds demand.
  • Authentication is becoming more complex, with security systems needing to determine not only who or what is seeking access, but why access is needed, for how long and what actions an agent can take.
  • As AI agents can operate continuously and faster than humans, identity security solutions need to make decisions at runtime and at greater scale.
  • The need to secure AI agents’ identification across fragmented systems could encourage more unified platforms and potentially spur consolidation in the sector.

Artificial intelligence has the potential to deliver substantial gains in efficiency and productivity while lowering costs. But as AI becomes more capable, it can also become a more powerful tool for cybercrime.

 

That risk is particularly important as enterprises begin adopting AI agents. Unlike traditional software, agents can operate continuously and at speeds far beyond human capabilities. They are increasingly dynamic and autonomous, able to connect information and take actions across a broad range of tools, systems and data sources.

 

Recent reports of AI agents bypassing safeguards to compromise networks have brought these risks into sharper focus. They have also accelerated efforts to develop new security architectures capable of protecting enterprises in an increasingly agentic world.

 

One area where the impact is likely to be especially significant is identity security, as securing agentic identities creates an additional source of demand. The enterprise market could more than double over the next two years, from approximately $24 billion today to $60 billion.

 

For incumbent security vendors, the urgent need to address agentic identity security represents a significant opportunity. Adoption of AI agents should not only increase demand for core identity capabilities; it should also create demand for new tools that allow AI agents to be discovered, registered, governed and monitored much like their human counterparts.

 

Securing AI Agents Requires a New Approach

Historically, identity security has focused primarily on employees, third parties, customers and, to a more limited extent, service accounts and machine identities. The fundamental challenge has been relatively straightforward: establish who is attempting to access a network and determine what permissions or privileges that person or machine should have.

 

AI agents make that equation considerably more complex.

Adoption of AI agents should not only increase demand for core identity capabilities; it should also create demand for new tools that allow AI agents to be discovered, registered, governed and monitored much like their human counterparts.

 

 

As adoption accelerates, enterprises will need stronger safeguards for non-human access. A modern identity stack will have to go beyond determining who an AI agent is and what it is trying to access. Security systems increasingly will need to understand why an agent needs that access and for how long.

 

 

 

That means enterprises will need authentication and governance systems capable of answering a broader set of questions: who owns the agent, what permissions it has, which credentials it uses, what systems it can access, what actions it can take and whether that access is excessive.

 

These questions are not entirely new to cybersecurity. What changes with AI agents is the scale, speed and level of autonomy with which they need to be answered.

 

Identity solutions will increasingly need to make these decisions at runtime, potentially across enormous populations of agents and interactions. Architectures designed primarily around human users and relatively static machine identities may not be sufficient for that environment.

 

AI Could Accelerate Identity Security Consolidation

The implications extend beyond security architecture to the structure of the identity-security market itself.

 

Today, the market is characterized by numerous separate solutions addressing authentication, identity governance, privileged access, threat detection and other functions. That model has allowed organizations to select specialized products for distinct use cases, but it has also produced highly fragmented identity architectures.

 

AI introduces another layer of complexity. As enterprises seek to secure a rapidly growing population of autonomous agents, coordinating identity controls across that fragmented stack becomes more difficult—and a unified approach becomes more valuable.

 

As a result, that dynamic could become an incremental catalyst for consolidation across the identity market.

 

Enterprises indicate that they want to handle identity security in one place instead of piece by piece. Agents are complicated, and companies suddenly have a lot of them to keep track of. That is front of mind for enterprises right now, and it is a real opportunity for identity vendors—both public and private—to pull a market that has always been split up into something more unified.

 

Companies that can bring together identity discovery, authentication, governance, privileged access and monitoring into more integrated platforms could be particularly well positioned as customers rethink how they secure both human and non-human identities.

 

For the cybersecurity industry, agentic identity is likely to become more than simply another emerging use case, but potentially an important driver of the next phase of growth.