Back to Feed
AI SecurityOct 9, 2026

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

Report finds AI deployment outpaces security, creating a 'velocity paradox'.

Summary

A new report from SailPoint highlights a 'velocity paradox' where organizations are deploying AI agents at machine speed but relying on human-speed security controls. This mismatch stems from legacy identity and access management (IAM) architectures designed for human employees, which are inadequate for ephemeral, rapidly multiplying AI agents. Consequently, many businesses are stuck in foundational security maturity levels, unable to effectively manage non-human identities.

Full text

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition The Hacker NewsOct 09, 2026Identity Security / Artificial Intelligence As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a structural failure that legacy approaches cannot solve. The data shows that while businesses have spent years maturing their identity programs for human employees, those same playbooks are fundamentally broken when applied to the ephemeral, autonomous, and rapidly multiplying world of non-human AI agents. A Market Stalled at the Starting Line Despite years of investment in identity and access management, the market's overall security maturity has hit a wall. According to the report, the center of gravity remains firmly planted in the foundational stages, with a combined 60% of organizations still in Horizon 1 ("No Formal Program") or Horizon 2 ("Manual, Tool-Assisted"). The multi-year persistence of this trend reveals a critical insight: the problem isn't a lack of effort, but an architectural ceiling. The operational playbooks built to govern human employees may not scale effectively to govern autonomous agents executing thousands of transactions per minute. A Tale of Two Maturities: The Human vs. Non-Human Divide The paradox becomes clearer when looking at the stark division between the maturity of human and non-human identity security. The report’s data reveals two entirely different timelines. Human Identity is Maturing: For human workforces, security programs are progressing. Five years ago, 45% of organizations were at the lowest maturity level (Horizon 1). Today, that number has been cut nearly in half to 23%. Agent Identity is Lagging Dramatically: The opposite is true for non-human and AI agent identities. Today, 54% of organizations sit at Horizon 1 for agent identity security—a worse starting point than for human security five years ago. This disconnect shows that even organizations with strong capabilities for managing human access are struggling to extend those same standards to cloud workloads and agentic environments. It is a coverage gap, not a competence gap. Why Old Security Playbooks Fail in the Agentic Era The core of the velocity paradox is that processes designed for people do not work for machines. The report identifies key structural dynamics that cause this failure: The "Digitization Trap": Organizations in the middle-maturity tiers have successfully digitized human-centric processes like employee onboarding and periodic access reviews. However, applying these same scheduled review cycles to ephemeral machine identities—which may exist for only minutes or seconds—creates severe operational drag and is functionally useless. The Pivot to Machine-Speed Trust: Breaking into the upper horizons of maturity requires a fundamental paradigm shift. Advanced organizations have moved away from manual, ticket-based access decisions. They have replaced standing privileges with continuous, contextual, and automated policy enforcement that operates at machine speed. The False Compromise: "Balance" Is Not a Strategy When faced with the conflict between moving fast and staying secure, nearly half of the market (49%) claims to "balance both equally." However, the report’s data suggests this is a false compromise. A stated posture of "balance" without the underlying operational capability to enforce it is not a strategy; it is a stall. Organizations are caught in the paradox: They have an AI-speed ambition but a human-speed foundation, leaving them unable to move decisively. This is where most of the market currently sits, waiting for an architectural shift that can resolve the paradox. The ultimate conclusion is clear: Securing the autonomous enterprise does not require rebuilding from scratch. The immediate priority is for organizations to extend their proven governance disciplines to cover the unmanaged non-human identities operating across their digital estate, unifying them into a single fabric that can finally match the speed of AI. For additional perspective on how identity maturity is evolving in the age of AI, SailPoint’s “Horizons of Identity Security” report explores the trends, gaps, and capabilities shaping the path forward. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Access Management, artificial intelligence, Cloud security, Identity Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills

Entities

Horizons of Identity Security (product)SailPoint (vendor)Artificial Intelligence (technology)Identity and Access Management (technology)