- What: Survey highlights identity governance challenges with AI agents
- Impact: IT and security professionals managing AI systems
Identity AI agents create identity governance challenges, impacting cyber resilience July 16, 2026 Share By SC Staff (Adobe Stock) Organizations are facing significant identity management challenges as they rapidly deploy agentic AI systems, according to a new survey. The systems designed to manage human identities are struggling to cope with the influx of machine identities, and many businesses have not yet defined their recovery strategies post-attack, based on information published by Channel Insider. A survey sponsored by Commvault and conducted by IDC reveals that 90% of IT and resilience decision-makers believe their identity management capabilities need improvement to address risks from agentic AI. Non-human AI agents, with their always-on access and ability to multiply, are outpacing human users, overwhelming traditional identity systems. Over half of surveyed North American organizations (58.7%) require substantial changes to their identity management approach, with only 26.7% having implemented dynamic role-based access controls for AI. Furthermore, 57.7% of organizations have not fully defined their minimum viable business operations for post-attack recovery. Gaps also exist in recovery orchestration, cleanroom deployments, and broader cyber resilience capabilities, with only 26% utilizing a unified backup platform and 35.4% automating the identification of clean recovery points. IDC recommends adopting resilience operations (ResOps) as a mainstream discipline to integrate business continuity, cybersecurity, and data protection for a unified recovery strategy, predicting its broader adoption in the next three to five years. Source: Channel Insider SC Staff Related Identity Europe built the world’s strongest privacy law. WhatsApp just found the gap it doesn’t cover. Umesh Kalanke July 15, 2026 WhatsApp usernames boost privacy but weaken identity verification, raising fraud risks. Identity ShinyHunters group exploits OAuth trust, prompting Microsoft security upgrades SC Staff July 14, 2026 The ShinyHunters group targeted Salesforce users by tricking them into authorizing a malicious Salesforce Data Loader application, which then requested OAuth permissions. Identity OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials Steve Zurier July 14, 2026 Attackers run multiple spoofing campaigns to confirm credentials. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds