TL;DR: Identity security has become one of the most important business challenges of the AI era. AI is rapidly increasing the number of machine and agentic identities, exposing decades of accumulated identity complexity while enabling attackers to move at machine speed. The organizations best positioned for the AI era will focus on three priorities: gaining visibility into all identities, containing threats at machine speed, and ensuring they can recover quickly when disruption occurs. At its core, identity is now a board-level business risk.
In conversations with the C-suite and board members over the past year, I keep hearing versions of the same uncomfortable reality. The legacy systems that got us this far in identity security and resilience are not the same systems that will help us disrupt and recover quickly from business disruptions.
In fact, AI has become one of the rare technology topics that has escaped the confines of IT and cybersecurity teams and entered into everyday conversation. Teenagers are talking and asking questions about AI and how it can be controlled. Grandparents are asking what AI means for privacy, scams, and information that they can trust online. That growing awareness mirrors what I’m hearing from executives: AI is creating enormous opportunities, but it’s also introducing new risks and questions about trust, security, and control.
What many don’t realize is how quickly the problem is growing. Palo Alto Networks found that identity weaknesses played a material role in nearly 90% of the incidents it investigated, yet more than 75% of organizations lack a tested identity recovery plan. Most leaders understand they have an identity security challenge, after accumulating years of users, applications, service accounts, cloud environments, privileged access, and disconnected systems. And they know complexity is building.
However, they don’t have visibility into its full scope and that’s becoming a challenge because AI is creating new categories of identities while exposing 25 years of technical debt. At the same time, attackers are moving faster than ever.
The result is that identity security is no longer just a CISO issue. It’s a business resilience issue, and increasingly a security management challenge. That’s why organizations are looking beyond traditional identity and security tools towards a more integrated, NIST-aligned approach, that exposes identity risk before it becomes compromise, stop attacks from spreading, and recover critical operations faster when disruption is unavoidable.
AI is rewriting the rules of identity security, but humans must remain in charge
For years, identity was primarily about people. Employees needed access to applications; partners needed access to systems; and administrators needed privileged permissions. That was complicated enough. Now organizations are creating machine identities, service accounts, APIs, automation workflows, AI agents, and autonomous systems at a pace that few anticipated.
At the center of most of these environments are Microsoft Active Directory and Entra ID, which remain the identity control plan for most enterprises. They govern access across human, non-human, and agentic identities, making them foundational to both business operations and cybersecurity resilience.
Every one of those identities needs access to something and can create risk if unmanaged. Security leaders increasingly recognize that preventing every compromise is unrealistic. As identity environments expand across human, non-human, and AI-driven entities, the challenge becomes identifying risk early, limiting the spread of attacks, and recovering quickly when compromise occurs. Yet most organizations have little visibility into their non-human identities. Industry estimates suggest that for every employee, there may be more than 100 non-human identities operating across your environment. That ratio is staggering.
Most organizations can’t confidently tell you how many they have or what these identities can access because identity environments were never designed to operate at this scale. AI is exposing the problem and forcing a reexamining of traditional security management approaches.
Here’s another sign of how fast this is moving. One recent survey highlighted in Okta’s Q2 earnings report, found that 81% of CISOs know AI agents are being deployed without adequate security controls. Security leaders can see the risk forming, but AI adoption is outrunning traditional governance. That’s how visibility gaps become business risks.
Policymakers are beginning to recognize the challenge. Quest supports the bipartisan Stop Rogue AI Act, which would direct NIST to develop standards, guidelines, and best practices for the secure deployment of AI agents. The proposal emphasizes visibility, oversight, and accountability for non-human and agentic identities operating across environments.
The battle for identity has begun
We’re witnessing a fundamental shift in how attackers operate. The old model of cybersecurity focused on malware and exploits. Today’s attackers focus on identity because valid credentials provide one of the fastest paths to sensitive systems, critical data, and privileged access. If attackers compromise an identity, they can often bypass many controls. That’s one reason identity has become the new perimeter.
The rise of Identity Threat Detection and Response (ITDR) reflects this reality. Organizations increasingly recognize that identity has become a primary attack surface. But identifying a threat is only part of the challenge. When attacks can unfold in seconds, organizations must also contain threats quickly and recover confidently when identities are compromised.
Recent events underscore the point. The breach involving Hugging Face and reports from OpenAI illustrate how attackers continue to focus on credentials, tokens, and trusted access paths, rather than attacking infrastructure directly. This lesson isn’t limited to AI companies. Every organization pursuing AI is creating more non-human identities that require privileged access. Identity increasingly becomes both the control plane for innovation and an attractive target for attackers. It also raises a broader security management challenge: most organizations lack a complete understanding of how these identities are connected, what they can access, and the business risk they create.
And it’s not just cybercriminals driving threats. Nation-state activity continues to rise across critical sectors, including financial services, healthcare, transportation, energy, manufacturing, and government. These are deliberate efforts targeting systems and services that organizations and societies depend upon every day.
This is why identity is no longer a conversation reserved for security teams. The implications have become too significant to ignore.
When agentic attacks are inevitable, resilience and recovery matters
The timeline of an attack has changed. Attackers increasingly use automation and AI to compress tasks that once required hours or days into minutes or seconds. In a recent incident, an AI-driven agent executed credential theft, privilege escalation, and lateral movement in approximately 30 seconds.
That’s not just a security statistic. It’s a business reality. The traditional approach of identifying a threat, handing it to another team, and deciding what to do next doesn’t work at machine speed. The response model must change.
Siloed security can’t keep up with pace of adversarial agentic forces
This is where many organizations find themselves at a disadvantage. Over the years, they purchased tools to solve specific problems: identifying risk; governing access; detecting threats; and performing recovery. Those point solutions may work well, but attackers don’t operate in categories. They move across identities, permissions, systems, and environments. At machine speed, the handoff between tools become vulnerabilities. What one tool finds, the next can’t act upon. By the time information moves between systems and teams, the opportunity to contain the threat may be gone. That’s why organizations are rethinking the role of security management, connecting risk identification, containment, and recovery in a way that keeps pace with modern attacks.
The organizations that will be most successful in the AI era won’t be the ones with the most security tools. They’ll be the ones that can move from visibility to action without friction. When attacks move in seconds, disconnected processes become a business risk.
The recovery conversation is long overdue
There’s another topic that doesn’t receive enough attention: recovery.
Most executives focus on prevention and detection. Far fewer discuss what happens after a critical identity system has been compromised. Yet many organizations still lack a tested recovery plan. If identity sits at the center of business operations, losing control affects more than security. Every leadership team must assume a compromise. What happens next is critical.
Recovery must go beyond an IT project and become a resilience strategy.
Identity security is now business resilience
This is why we believe identity has emerged as one of the most important leadership challenges of the AI era. Identity security isn’t new, but AI is amplifying weaknesses. It’s increasing the number of identities requiring governance while accelerating attacks. It’s exposing decades-old blind spots and raising the stakes for organizations that cannot quickly contain and recover from disruption.
Organizations that navigate this new era successfully will need to focus on three things:
- Establishing visibility into their identity environment, particularly the machine and agentic identities most organizations struggle to account for.
- Building the ability to contain threats at the speed they operate.
- Treating recovery and resilience as business requirements, not technical afterthoughts.
Identity security now determines how quickly an organization can detect risk, withstand disruption, and restore operations when something goes wrong, making it a core security management priority for the board and executive team. This is why identity is now a board-level issue and why resilience may be the most important identity outcome leaders should pursue today.
