CIO Influence
CIO Influence News Machine Learning Security

New IDC Research Sponsored by GuidePoint Security Finds AI Agents Are Outpacing Security Teams

New IDC Research Sponsored by GuidePoint Security Finds AI Agents Are Outpacing Security Teams

GuidePoint Security Logo

Findings point to identity as the foundational control plane and provide a four-stage maturity model for managing AI agents

GuidePoint Security, the cybersecurity advisor and services partner organizations rely on to protect what matters most, announced the publication of a new IDC White Paper, “Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look For.”

Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight

Identity is the foundational control plane for agentic AI, because data permissions, runtime controls, and audit records all depend on knowing which agent is acting.

Sponsored by GuidePoint Security, the research draws on in-depth interviews with senior security and identity leaders, along with data from multiple IDC surveys spanning nearly 3,600 respondents. Its central finding: identity is the foundational control plane for agentic AI, because data permissions, runtime controls, and audit records all depend on knowing which agent is acting.

“Organizations are deploying AI agents faster than their security programs can account for them, and most don’t have a clear picture of what’s already running,” said Kevin Converse, Vice President, Identity and Access Management, at GuidePoint Security. “This research confirms what we’re seeing with our customers: visibility, ownership and scoped access need to be built into agentic AI from the start.”

Additional key findings include:

  • Non-human identity security is outpacing IAM programs. All participants said non-human identities are outpacing their identity and access management programs, with ratios of non-human to human identities cited as high as 75 to 1.
  • Continuous identity discovery remains limited. 77.3% of organizations report high or very high confidence they can see all identities across their environment — yet only 18.5% of organizations run identity discovery continuously or in near real time.
  • Non-human identity compromise rivals credential theft. Abused non-human identities were the leading initial entry point in 19% of the most recent confirmed identity incidents, effectively tied with phished or stolen credentials at 19.5%.

The research identifies four critical capability areas organizations should prioritize: governance, risk and policy frameworks for agentic AI; AI-driven threat detection and identity threat response; agent and non-human identity life cycle and ownership; and privilege right-sizing with just-in-time access. It also provides a four-stage maturity model to help security leaders assess where they are today and determine the right next step.

“The architecture will continue to evolve, but organizations don’t need to wait for it to settle,” Converse added. “Treat AI agents as another form of identity to be managed. A named owner, an accurate inventory and a clean revocation path are all necessary security fundamentals for managing this new class of identity that operates at machine speed.”

Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?

[To share your insights with us, please write to psen@itechseries.com ]

Related posts

PlaxidityX Releases Insightful Report on the State of DevSecOps Adoption within the Automotive Developers Community

PR Newswire

Visteon Launches Edge-to-Cloud AI Platform for Intelligent Vehicles Powered by NVIDIA Technologies

PR Newswire

Instaclustr Announces General Availability of Fully Managed Apache Cassandra 4.0

CIO Influence News Desk