90% of IT Leaders Say Identity Management Critical for Secure Agentic AI Deployment

2 Sources

Share

A Commvault-IDC study reveals that 90% of IT and resilience decision-makers believe identity management capabilities must improve to address risks from agentic AI systems. With non-human identities set to outnumber humans, nearly two-thirds say significant overhauls are required, while only 26.7% have implemented dynamic role-based identity access controls designed for AI.

Identity Management Emerges as Bottleneck for Agentic AI

Identity management has emerged as the critical challenge facing organizations deploying agentic AI systems, according to new research from Commvault and IDC. The Commvault-IDC study surveyed 539 IT and resilience decision-makers across North America and found that 90% believe they need to improve identity management capabilities to address risks introduced by agentic AI

1

2

. Approximately 85% of survey participants have already experienced a cyber incident, underscoring the urgency of this challenge.

Source: DT

Source: DT

The research highlights a fundamental mismatch between systems designed to govern people and the requirements for governing AI agents, machine identities, and autonomous workflows. Nearly two-thirds of respondents—58.7%—indicate that significant improvements or a complete overhaul of their identity management approach is required to support secure agentic AI deployment

2

. As organizations deploy agents in volume, non-human identities with always-on access capabilities that can multiply on demand may rapidly outnumber human identities.

Critical Gaps in AI-Ready Infrastructure

The study reveals alarming gaps in infrastructure readiness for governing AI agents. Only 26.7% of organizations have implemented dynamic role-based identity access controls designed to support AI and analytics

2

. Even more concerning, just 24.7% have documented and tested their ability to protect, detect compromise of, and recover Active Directory and Entra ID environments—critical identity infrastructure that serves as a Tier 0 application

2

.

"AI is fundamentally changing how organizations operate, make decisions, and manage risk," said Vidya Shankaran, Field CTO at Commvault. "But many organizations are discovering that the systems designed to govern people are not prepared to govern a growing population of AI agents, machine identities, and autonomous workflows. Identity is a critical Tier 0 application and has a pivotal role to play in an organization's confidence in a clean recovery"

1

.

Resilience Operations Gains Momentum

To address these challenges, the research points to the growing need for Resilience Operations (ResOps), an emerging operational discipline that brings together business, security, infrastructure, data protection, and disruption recovery teams around maintaining business continuity during incidents

1

. More than half of respondents—57.7%—have not fully defined their minimum viable business, the critical systems and processes required to continue serving customers during a disruption

2

.

Frank Dickson, Group Vice President for IDC's Security & Trust research practice, predicts that Resilience Operations (ResOps) will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years. "Organizations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment," Dickson stated

1

.

Collaboration Gaps and Assessment Tools

The research also uncovered significant collaboration challenges, with nearly all respondents—98.4%—believing that collaboration between IT and security teams needs improvement. Half of those surveyed, 49.7%, say major improvements are needed

2

. To help organizations evaluate their preparedness, IDC has launched a Cyber Readiness Assessment, sponsored by Commvault, enabling businesses to assess their cyber resilience maturity and identify areas where identity, protection, detection, response, and recovery capabilities require improvement

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved