Enterprises are racing to deploy autonomous AI agents, but a new report from SailPoint warns that security architectures have not kept pace. The "Horizons of Identity Security" report describes a "velocity paradox": businesses operate at AI speed while relying on human-speed security controls. The data shows that identity security maturity has stalled overall, with 60% of organizations still in the lowest two maturity tiers—no formal program or manual, tool-assisted processes.

The divide is starkest between human and non-human identities. For human workforces, the share of organizations at the lowest maturity level dropped from 45% five years ago to 23% today. But for AI agents and other non-human identities, 54% of organizations remain at the lowest tier—a worse starting point than human security had five years ago. The report calls this a coverage gap, not a competence gap, since even firms with strong human identity programs struggle to extend those standards to agentic environments.

The core problem is that processes designed for people do not work for machines. Scheduled access reviews, for example, are functionally useless for ephemeral machine identities that may exist for only minutes. The report also notes that 49% of organizations claim to "balance" speed and security equally, but without the operational capability to enforce that balance, it is a false compromise. The recommended path forward is to extend proven governance disciplines to non-human identities and unify them into a single fabric that can operate at machine speed. (Note: This article is based on a partner-contributed piece from SailPoint.)