惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
T
The Blog of Author Tim Ferriss
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
Engineering at Meta
Engineering at Meta
量子位
I
InfoQ
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
G
Google Developers Blog
J
Java Code Geeks
Recent Announcements
Recent Announcements
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
V
V2EX
腾讯CDC
P
Proofpoint News Feed
A
About on SuperTechFans
爱范儿
爱范儿
U
Unit 42
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI

Featured Blogs - Forrester

Customer Zero Proves AI Works When Humans Change Customer Zero Programs Prove That AI Works When Humans Change Prime Day, June 2026: How Retailers Competed With Amazon Inclusive Design Is Automotive’s Overlooked Growth Opportunity B2B Social Media Influencers Have More Influence Than Ever Comcast Split Puts NBCUniversal In Play What Technology Leaders Should Not Miss At Technology & Innovation Forum Central Why Your AI Strategy Needs A DEXM Solution: Lessons From Nexthink Masters Of Experience The Dawn Of The Accidental Developer The Next Era Of B2B Events: 8 Data-Backed Shifts Defining 2026 The Next Era Of B2B Events: Eight Data-Backed Shifts Defining 2026 Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And…AI Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI Use EO 14409 As A Canary For Enterprise PQC Migration And Procurement Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement EO 14409 Makes PQC Migration A Multi-Year Operational Program For Federal Security Leaders New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum Answer Engines Will Select Your Content. Your Digital Experience Has To Do More. Meta Gambles With Its Trust In Prediction Markets The EU’s Digital Markets Act Meets The Mobile OS, Round 2 Don’t Just Hear About The IT Singularity — Work Through It At Our Austin Tech Forum Don’t Just Hear About The IT Singularity — Work Through It At Our NYC Tech Forum The Cost Of AI Productivity Is Less Creativity Dollars And Sense At FinOps X 2026: Is AI Value Management Bigger Than FinOps? Quantum Security Is No Longer Optional: A Practical Blueprint For Successful Implementation The AI Orchestration Layer In Banking Is The New Battleground The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing AI Forces A Redesign Of How Marketing And Agencies Work The IT Singularity Is Here: Announcing Forrester’s 2026 Technology Events
Identiverse 2026 Recap: Identity Security for Agentic AI ...
Andras Cser · 2026-06-26 · via Featured Blogs - Forrester

Last week’s Identiverse conference in Las Vegas left no doubt that the scope and importance of identity security is now magnified. Identiverse 2026 underscored the current transition in identity security as organizations grapple with an expanding universe of identities beyond humans. As Ping Identity CEO Andre Durand framed it in his opening keynote, the industry is shifting toward “actions, not access” – a move from static access control to continuous, real-time identity decisions that govern what entities can do.

Conversations across the event highlighted the growing importance of governing non-human identities (NHIs), AI agents, and machine-driven interactions as first-class security concerns. NHI and AI security was also the predominant theme across the 200+ booths in the expo hall.  Amidst the crush of AI-infused presentations and vendor messaging, the conference also stood out as a testament to the range of identity’s reach, featuring breakout sessions spanning mobile driver’s licenses (mDLs), data and privacy, fraud, FIDO passkeys, cybersecurity architecture, software development practices, industry standards, threat detection and response, and operational resiliency.

AI agents’ adoption is unstoppable, during the conference we heard presenter estimates that 75-85% of organizations have already started adopting AI agents. Security, and in particular Identity and Access Management, continue to play an oversized role in securing AI agents.

AI agents represent an autonomous, non-deterministic, and numerous non-human identity type but also present a new channel for user interaction (e.g.: human users can spawn their own enterprise data collection, and consumer purchase agents). Here are our main takeaways from Identiverse 2026:

  • New discovery and governance methods are required. AI agents do not fit into the existing mold of static and human time horizon Identity Management and Governance (IMG/IGA) tooling and processes. AI agent governance is more real time, context aware, and build-time intent aware. Delegation to a uniquely identified agent, and not impersonation is the recommended design pattern. AI governance should also look at agent provenance and reputation using repositories, agent suppliers (e.g.: Amazon shopping agents).
  • AI Agents Require new access policy decision frameworks. AI agents’ authentication to MCP servers is the easier, more mature part: they use OAuth 2.1 OIDC tokens to authenticate to MCP servers and other resources. AI Agent authorization is where we are seeing the greatest paradigm shift from simple static, ABAC/RBAC authorization policies to much more contextual, intent-verified, boundary constrained (“this agent can only spend up to $300 on buying kitchenware from an eCommerce site”). Authorization is just-in-time, context (network, jurisdiction, resource) and must happen in real time. The conference reinforced the growing momentum behind more dynamic, fine-grained authorization.
  • Risk definition and measurement is still unclear. AI agents’ actions represent financial and reputational risk to organizations. For example, in a B2C use case, a purchasing AI agent may 1) scrape a website and hoard a cart, 2) make fraudulent purchases, and 3) perform actions that cause dissatisfaction for the agent’s human owner. Defining, keeping track of and abating these risks does not yet have a mature product solution.  End user organizations are currently using in-house built telemetry and solutions for this purpose.
  • IAM for AI agents must fit into an organization’s IAM mesh. AI agent identities must be tied and correlated to human identities’ access management in enterprise IAM. IAM for human and deterministic machine identities remains an organizational challenge – adding IAM requirements for AI agents further complicates the landscape. Trying to cobble together a non-standards based IAM solution to manage AI Agents can quickly create technical debt. Okta, Microsoft and Ping Identity have just introduced frameworks for IAM for AI agents– their ready to deploy blueprints with examples are overdue and solid starting points for managing AI Agent identities.
  • Identity standards is ongoing but not unified. Auth.md, ID-JAG, SPIFFE, AUIC-1, IETF’s RFCs and other standards are either not final, work in progress or are less than 12 months old. Commercial and in-product support is still scarce but rapidly improving. Anecdotally, we found that organizations are still waiting for AI agent security standards to solidify, mature, and become commercially supported before fully implementing them.

Overall, Identiverse 2026 underscored that the next phase of identity security will be defined by how effectively organizations extend governance to autonomous systems, unify identity data across silos, and operationalize identity intelligence in real time.

Forrester clients who want to dive deeper into this topic and discuss how they should implement IAM for agents should schedule an inquiry or guidance session with us.

Categories

Blog

Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI

Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]

Blog

Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement

On June 22, 2026, the White House issued a new executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks. While it has direct implications for federal agencies, there are parts that are worth paying attention to for enterprise security and risk leaders. Here’s what’s worth your attention, whether or not you hold a federal […]