AI Agents Are Moving Fast, but Security Controls Are Still Built for Humans
A new report from SailPoint, titled "Horizons of Identity Security", describes a "velocity paradox". Businesses are investing in AI-speed operations, including autonomous AI agents, while still relying on security controls designed for human-speed work. The report argues this is a structural problem that older approaches cannot fix.
The maturity numbers show how stuck the market is. A combined 60% of organisations remain in Horizon 1 ("No Formal Program") or Horizon 2 ("Manual, Tool-Assisted"). The report says the cause is not a lack of effort but an architectural ceiling: processes built to govern employees may not scale to agents that carry out thousands of transactions per minute. Even organisations that manage human access well are struggling to apply the same standards to cloud workloads and agentic environments. The report calls this a coverage gap, not a competence gap.
The core issue is that processes designed for people do not work for machines. When asked about the tension between moving fast and staying secure, 49% of organisations say they "balance both equally". The report's data suggests this is a false compromise. This article covers only the opening of the report, so further findings are not summarised here.