On 9 October 2026, The Hacker News published a partner piece on SailPoint's "Horizons of Identity Security" report. It describes a "velocity paradox": companies deploy autonomous AI agents while relying on controls designed for humans1. According to the report, 60% of organisations sit in the two lowest maturity levels. The share at the lowest level for employee identity security fell from 45% to 23% over five years, while for AI agents and other non-human identities it stands at 54%1. The authors call scheduled access reviews useless for machine accounts that exist for minutes or seconds. They say advanced organisations have replaced standing privileges with continuous automated policy enforcement1. The report's main recommendation is to extend proven governance practices to unmanaged non-human identities1. These are a solution vendor's data and conclusions, presented in a partner publication1; the editors have not independently verified them. Editorial takeaway: organisations should find out which service accounts and agents they run and who controls their permissions.

  1. [1] The AI Velocity Paradox: Why Security Is Decades Behind AI AmbitionThe Hacker News