SailPoint Report Finds 79% of Enterprises Run AI Agents in Production, Yet Only 2% Have Deployed Purpose-built Security
Organizations at the lowest human identity security maturity level fell from 45% in 2022 to 23% in the study.
Sentiment and the balance of points
Rhea-AI Sentiment reads the wording of the document, how positive or negative its language is on a 1 to 5 scale. The balance of points shown with the takes weighs what the document actually discloses, so the two can disagree, for example when a trial that missed its main goal is described in upbeat language.
Rhea-AI Summary
SailPoint (Nasdaq: SAIL) released its fifth annual Horizons of Identity Security report, examining the gap between enterprise AI adoption and identity controls. The study found that 79% of organizations run AI agents in production, while 2% use identity security tools specifically designed to manage and govern them. Meanwhile, 85% rely on legacy identity tools not designed for agentic identities.
Only 15% can provision non-human access in real time. Among organizations that invested in securing non-human identities, 62% report measurable productivity gains and 46% report safer, faster AI deployment. These findings describe surveyed organizations, not SailPoint's financial performance.
Key Figures
- Organizations running AI agents in production
- 79%
- Report finding
- Using purpose-built identity security tools for AI agents
- 2%
- Report finding
- AI adoption-to-security readiness gap
- 40-to-1
- Report finding
- Relying on legacy identity tools
- 85%
- Tools not designed for agentic identities
- Agent identity at Horizon 1 maturity
- 54%
- Current report finding
- Able to provision non-human access in real time
- 15%
- Operational readiness finding
- Report measurable productivity gains
- 62%
- Organizations that invested in securing non-human identities
- Report safer, faster AI deployment
- 46%
- Organizations that invested in securing non-human identities
Previous AI Reports
-
Introduced unified security solution combining Agentic Fabric and Human Fabric for AI identities.
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Key Terms
iam technical
credential lifecycle management technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
Fifth annual Horizons of Identity Security report reveals a 40x gap between AI adoption and identity security readiness
AUSTIN, Texas, Oct. 06, 2026 (GLOBE NEWSWIRE) -- Today from its annual Navigate conference, SailPoint, Inc. (Nasdaq: SAIL), a leader in enterprise identity security, released its fifth annual Horizons of Identity Security report, revealing that enterprise AI adoption has dramatically outpaced the identity security controls needed to govern it. The study finds that while
This gap is driven by a stark divergence in security maturity between human and non-human identities. While organizations have made impressive strides with human security—nearly halving those at Horizon 1 maturity from
Wendy Wu, Chief Marketing Officer at SailPoint, said:
"Compressing a five-year maturity curve into a single year presents a massive operational challenge, starting with a fundamental awareness gap. Many organizations don't yet realize that they do not have the right tools purpose-built for the scale and velocity of agent and non-human identity security. You cannot bridge this gap by asking human-speed tools to work faster; security must be built for machine speed from the ground up, with discovery, ownership, and access decisions happening in real time rather than on a quarterly review cycle. Enterprises waiting for their agent programs to mature the way their human programs did are going to find out the hard way that they don't have five years."
Key findings:
- AI adoption has severely outpaced security controls: AI agents now represent
22% of all non-human accounts, yet85% of organizations continue to rely on legacy identity tools not designed for agentic identities. - Overall maturity remains anchored at foundational levels. Roughly sixty percent of organizations remain in Horizons 1 and 2, while less than
1% have achieved Horizon 5. This lag is overwhelmingly driven by non-human identity deficits:87% rate their human IAM capabilities as capable or better, while only43% report mature processes for agentic access. - A pronounced awareness gap masks operational vulnerability:
80% of leaders believe the gap in their current tooling is moderate or smaller, yet the operational reality is that only15% can provision non-human access in real time. Similarly,57% express confidence in meeting regulatory requirements, while only43% feel prepared to produce verifiable evidence in an AI-related audit. - Foundations remain the primary operational roadblock. Before enterprises can realize dynamic, intent-based security, they must first master baseline hygiene and visibility. Credential lifecycle management, shadow AI discovery, and real-time monitoring are rated as severe operational hurdles across the market.
- The business value of non-human identity security is immediate and measurable: Mature identity programs deliver significant business velocity.
62% of organizations that have invested in securing non-human identities report measurable productivity gains, and46% report safer, faster AI deployment. Looking ahead,76% of leaders expect stronger identity governance to improve their eligibility for — or the terms of — cyber insurance.
The report concludes that the mandate for security leaders is to move from a fragmented, human-centric approach to a unified identity fabric that governs all identity types—human, machine, and AI agent—with continuous, context-aware automation. By advancing from foundational tiers (Horizons 1-2)—where organizations struggle with manual controls and lack basic visibility—to advanced maturity (Horizons 4-5), enterprises gain the real-time visibility and automated policy enforcement needed to secure autonomous agents. This transition pays off well beyond basic compliance; mature organizations are twice as likely to realize significant productivity gains and three times more successful at deploying AI safely, effectively transforming compliance from a reactive audit scramble into a state of automated, continuous assurance. This is the only path to closing the security gap while enabling the full velocity of the autonomous enterprise.
About the report
The 2026 Horizons of Identity Security report is based on a global survey of 340 senior identity, IT, cybersecurity, and risk leaders conducted by SailPoint, evaluating organizations across strategy, operating models, talent, technical confidence, and technical capabilities against a five-tier maturity model ranging from Horizon 1 (No formal program) to Horizon 5 (Ecosystem integrated).
To read the full 2026-2027 “Horizons of Identity Security” report, please visit here.
Check out the livestream of SailPoint CMO Wendy Wu revealing the findings of this year’s Horizons report from SailPoint Navigate.
About SailPoint
SailPoint (Nasdaq: SAIL) is defining the new era of adaptive identity security. In a world where non-human identities now significantly outnumber humans, our AI-powered platform unifies identity, security, and data intelligence to protect today’s enterprise from advanced identity-based threats. We deliver the identity solution that spans both the breadth of identities and the depth of context needed to drive real-time access with confidence. Built on principles like zero-standing privilege and contextualized risk, our SailPoint platform transforms identity from a point of vulnerability into a powerful security advantage. Trusted by many of the world's leading organizations, SailPoint secures the enterprise with intelligent, autonomous identity security.
Media relations for SailPoint
Shannon Paulk
Sr. Manager, Corporate Communications
303-748-2275
shannon.paulk@sailpoint.com