Identity security maturity in the AI era
Discover how CISOs and security leaders can govern autonomous AI agents and non-human identities across the enterprise. Explore the 5 pillars of identity maturity and prioritize your IAM roadmap using the BRiCE framework.

Key Takeaways
- Identity is the new perimeter: Identity has replaced traditional networks as the primary security control plane, with compromised credentials driving 80% of enterprise breaches.
- Non-human identity surge: Non-human identities outnumber human employees by 80 to 1, creating unmanaged attack surfaces and delegation risks across APIs, workloads, and autonomous AI agents.
- Legacy IAM is failing AI: Traditional, static RBAC and quarterly access reviews cannot keep up with the dynamic, non-deterministic behaviors and broad access inherited by AI agents.
- Strategic ROI via the BRiCE framework: CISOs can systematically prioritize identity investments across 12 capability domains by evaluating Business Value, Risk Impact, Cost, and Effectiveness.
This summary was created with AI and reviewed by an editor.
Ask AI to write a summary
Featured event: A CISO’s take
Join Jim Alkove and Ramy Houssaini to learn how forward-thinking security teams are addressing Enterprise AI Copilot risks.
Chief Information Security Officers face a fundamental paradigm shift: Identity is no longer an administrative IT function. It has become the primary control plane and operational perimeter of the modern digital enterprise.
Designed for CISOs, CIOs, security leaders, architects, and technology providers, the Identity Security Maturity in the Era report offers a strategic framework to understand current trends, assess organizational maturity, and navigate the next generation of identity-centric security.
As organizations accelerate the adoption of autonomous AI agents, copilots, and machine-to-machine workflows, traditional identity boundaries are dissolving. According to research published by the Data Security Council of India (DSCI) and Oleria, compromised credentials and access misuse remain involved in 80% of enterprise breaches. Meanwhile, Non-Human Identities (NHIs) now outnumber human employees by an average of 80 to 1.
To enable digital transformation without creating unmanageable blast radiuses, security leadership must transition from static access controls to a mature, intelligence-driven identity program.
Why traditional IAM fails autonomous AI
Traditional Identity and Access Management (IAM) and Identity Governance and Administration (IGA) solutions were engineered around human workforce assumptions: predictable working hours, role-based access control (RBAC), and periodic quarterly access reviews.
When applied to autonomous AI agents and machine identities, these assumptions collapse:
- Unbounded access delegation: AI agents operate using delegated authority from users, developers, or other services. They frequently inherit broad, long-lived privileges across cloud environments, SaaS platforms, and core databases.
- Dynamic, non-deterministic behavior: Unlike legacy service accounts executing fixed scripts, agentic AI evaluates context, chains actions across multi-app ecosystems, and makes independent decisions in real time.
- Attribution and accountability gaps: Tracing whether an operational action was triggered by a human prompt, an automated sub-routine, or a prompt injection attack creates severe forensic challenges.
Without continuous oversight, AI agents and unmanaged NHIs create hidden execution pathways that attackers exploit to move laterally and escalate privileges.
The 5 capability pillars of identity security
To move beyond fragmented tool deployments, security leadership must structure identity strategy across five core capability areas:
The identity security maturity model grid
Organizations benchmark their security posture across five evolutionary stages:

Stage 1: Initial (Ad-Hoc)
Fragmented identity stores with manual, inconsistent JML processes. Zero visibility into non-human identities or shadow AI tools, and reliance on single-factor or weak OTP authentication.
Stage 2: Developing (Foundational visibility)
Centralized inventory of core workforce identities tied to HR systems. Basic MFA enabled for critical systems, with partial cataloging of service accounts and API credentials.
Stage 3: Defined (Repeatable processes)
Automated lifecycle provisioning and offboarding for employees and vendors. Documented RBAC models, periodic access certification campaigns, and credential rotation policies for critical service accounts.
Stage 4: Managed (Automation & ITDR)
Automated discovery of cloud, SaaS, and non-human identities. Implementation of Just-In-Time (JIT) access, context-aware risk-based authentication, and automated identity threat detection (ITDR).
Stage 5: Optimized (Autonomous guardrails & human-on-the-loop)
Continuous, real-time identity discovery and classification across all human, machine, and AI agent identities. Policy-driven autonomous lifecycle management under a full Zero Trust architecture, balancing machine execution velocity with human-on-the-loop oversight.
Prioritizing IAM capital expenditures: The BRiCE framework
CISOs cannot fund all 12 identity domains simultaneously. To maximize security return on investment, security leaders can apply the BRiCE Framework to calculate a composite prioritization score:
BRiCE Score = [(Business Value × Risk Impact) / Cost] × Effectiveness
- Business value: Alignment with business operational velocity, user experience, and digital transformation initiatives.
- Risk impact: Direct reduction in identity-based attack vectors, credential abuse, and blast radius.
- Cost: Total financial expenditure, implementation timeline, and operational friction.
- Effectiveness: The projected capability jump within the Identity Security Maturity Model.
Initiatives with higher BRiCE scores, such as automated non-human identity discovery or enforcing JIT access on privileged service accounts, deliver maximum risk reduction relative to capital investment.
Strategic action plan for CISO leadership
- Conduct an automated identity asset audit: Deploy discovery tools to inventory every workforce account, vendor identity, service account, API token, and AI integration across multi-cloud and SaaS environments.
- Eliminate standing privileges: Transition high-risk administrator access and autonomous service accounts to ephemeral, Just-In-Time (JIT) access models.
- Establish human-on-the-loop AI guardrails: Enforce strict policy guardrails where AI agents execute routine tasks autonomously, but privilege escalation or high-sensitivity data actions require explicit human authorization.
Read the full POV: Identity Security Maturity in the AI Era
This POV was co-authored with the DSCI team. Explore the full report to access the complete 12-domain maturity model grid, benchmarking tools, and strategic roadmaps designed to help your enterprise securely navigate the age of agentic AI.


.png)