AI Identity Security Lags, Exposing Enterprises to Growing Risk
Event summary
- A Cloud Security Alliance (CSA) survey, commissioned by Oasis Security, found that 79% of IT professionals feel ill-equipped to prevent attacks via non-human identities (NHIs).
- The survey revealed that 78% of organizations lack documented policies for AI identity creation and removal, and 92% lack confidence in their legacy IAM solutions to manage AI-related risks.
- Manual processes dominate identity lifecycle management, with only 14% fully automating creation and removal, leading to slow remediation times (24% taking over 24 hours to rotate credentials).
- The survey, conducted in August/September 2025, included responses from 383 IT and security professionals across various organizations.
The big picture
The rapid proliferation of AI agents and automated workflows is creating a massive explosion in identity creation and access, far outpacing the ability of traditional identity management systems to keep pace. This gap represents a significant and growing attack surface for enterprises, and the lack of governance and automation is creating a bottleneck for AI adoption. The findings underscore a systemic vulnerability as organizations increasingly rely on AI for core business functions.
What we're watching
- Governance Dynamics
- The lack of formalized AI identity governance will likely force a rapid shift towards policy-as-code and automated enforcement, potentially creating a market for specialized governance tooling.
- Legacy Systems
- The widespread inadequacy of legacy IAM systems to handle AI identities will accelerate the migration to cloud-native identity platforms, putting pressure on vendors to offer AI-specific capabilities.
- Operational Strain
- The slow remediation times highlighted in the report suggest a significant operational burden, which will likely drive demand for automated credential lifecycle management solutions and increased investment in security operations.
