Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane

BLOG

TL;DR –

 A new IDC whitepaper, commissioned by GuidePoint Security, explores why identity is the foundational control plane for securing agentic AI and what organizations should prioritize as adoption accelerates.

  • Non-human identities (NHIs) outpace human identities in many environments, with ratios cited as high as 75 to 1. Identity is the control plane that allows data controls and runtime controls to work. Without it, the other two scope to the wrong subject, enforce against the wrong agent or log the wrong actor.
  • Every respondent in the IDC study agreed: each agent needs a named human sponsor and a managed life cycle.

 

Service accounts. Application identities. API keys. Machine workloads. These are just a few examples of non-human identities (NHIs) that already outnumber human identities in many environments. The rapidly increasing use of AI agents expands the imbalance. Respondents in a new IDC study said their NHIs are outpacing existing identity and access management (IAM) programs, with ratios of NHI to human identities cited as high as 75 to 1. 

A new IDC whitepaper, Managing Agentic AI Through the Identity Control Plan: What Organizations Should Look For, examines challenges artificial intelligence (AI) has introduced to security and identity leaders and what they need from vendors today to close the security gap. The study draws on responses from a qualitative panel of senior security and identity leaders spanning across industries, corroborated with quantitative results from three IDC surveys covering more than 2,500 respondents.

Agentic Identity is Now a Board-Level Issue

“IAM became a board-level priority for me when my discovery report revealed that we have over 500 AI agents operating within our network and systems, far more than the handful I initially estimated.”

– Security Architect, Enterprise IT

AI is further shifting the security perimeter away from the network and identity is emerging as a new security perimeter and primary control plane. With that evolution,identity has solidified its position as a board-level and buying-center issue for mitigating enterprise risk.

Today, agentic AI runs through three control planes, the IDC study finds: identity, data and runtime. All three matter, but they are not peers. Data controls and runtime controls each depend on knowing, with confidence, which agent is acting. Therefore, identity is the foundational control plane that allows the other two to work.

The Data Behind the Urgency

IDC research shows that abused NHIs were the initial entry point in 19% of the most recent identity incidents among the 651 organizations who reported a confirmed incident, effectively tied with phished or stolen credentials at 19.5%. 

NHI and AI agent security is now a top two IAM program priority for 43.7% of organizations over the next 12 to 24 months, alongside identity governance modernization (50.7%) and privileged access management (PAM) modernization (50.6%).

Interestingly, a substantial 77.3% of organizations report high or very high confidence that they can see all human identities and NHIs across on-premises, cloud and SaaS. Yet the same survey shows that only 18.5% run continuous identity discovery and inventory or ownership gaps rank among the most cited non-human identity challenges (42.0%). Additionally, bots, RPA and AI agents are the least covered non-human identity type in current management programs, secured by only 41.5% of organizations. High confidence built on quarterly snapshots of the categories that exclude agents is exactly the false assurance the study panel’s discovery stories puncture.

Consistent Pain Points Across Organizations

Governing AI agents is not the same as governing humans and that difference is producing a consistent set of pain points across organizations interviewed in the study:

“I cannot see or count my agents.” Most organizations cannot state an exact agent count. Every respondent flagged the inability to account for the total number of agents operating in their environment.

“Privilege is sprawling at machine speed.” Only 18% of organizations enforce least privilege through just-in-time (JIT) access with automated remediation; 34.4% use automated entitlement right-sizing and nearly half still rely on policy-driven or manual access reviews.

“I can no longer trust the human signal.” The threat model has shifted to synthetic trust. AI-generated impersonation means human signals such as a voice on the phone or a face on a video call can be fabricated. Identity-proofing that assumes a real person on the other end no longer holds.

“There is risk I do not control: shadow AI and vendor-embedded AI.” Third-party vendors are embedding AI agents into SaaS applications, creating exposure that existing identity programs do not reach.

The paper dives into more paint points and solutions to address them.

The One Thing Senior Security Leaders Already Agree On

Among the security and identity leaders who participated in the research, there was strong consensus on the answer: every agent needs a named human sponsor and a managed lifecycle. Where organizations differ most is in how far they have matured in their approach to agent identity, not in the destination they are maturing toward: a purpose-built, distinctly governed identity class for every agent. The variation across organizations is a maturity gap, not a standing disagreement.

In Part 2 of this series, we will walk through IDC’s maturity model for agent identity management and the operating model organizations can adopt today.

Download the full IDC whitepaper →

 

IDC White Paper, sponsored by GuidePoint Security, Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look for, #US54897326-WP, September 2026

 

Integrated Marketing Campaigns Manager
GuidePoint Security

Laura Babbili is a cybersecurity marketer with a background leading integrated marketing campaigns that engage technical audiences and drive business impact. She has held roles at global companies including TikTok, Cisco and IBM, where she developed and executed strategies around small business, cloud security and IT infrastructure, respectively. She holds a bachelor’s degree in Journalism from the University of Northampton in the United Kingdom and is now based in Austin, Texas, where she lives with her husband, daughter and dog.