“Today, 54% of organizations sit at Horizon 1 for agent identity security,” the SailPoint “Horizons of Identity Security” report finds — a striking figure that captures the central tension facing businesses racing to adopt autonomous AI agents.
The AI velocity paradox and the architectural ceiling
SailPoint frames the problem as a “velocity paradox”: organizations are investing to operate at AI speed while relying on security controls designed for human pace. The report describes enterprise environments as “tethered to security architectures built for a different era,” creating a structural failure that legacy playbooks cannot resolve. In short, ambition to move faster has outrun the operational architecture meant to keep systems safe.
Two distinct timelines: human identity progress vs. agent identity stagnation
The report’s data draws a clear distinction between two maturing pathways. For human identity programs, progress is real: five years ago 45% of organizations were at the lowest maturity level (Horizon 1); today that share has fallen to 23%. By contrast, non-human and AI agent identity security is lagging sharply: 54% of organizations are at Horizon 1 for agent identity — a worse starting point than human security five years earlier. Overall, SailPoint finds the market’s center of gravity still clustered in foundational stages, with a combined 60% of organizations in Horizon 1 (“No Formal Program”) or Horizon 2 (“Manual, Tool-Assisted”). The report characterizes this as a coverage gap, not a competence gap: organizations that can manage human access well are struggling to extend the same standards to cloud workloads and agentic environments.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhy human-era playbooks fail: the Digitization Trap and the pivot to machine-speed trust
The report names two structural dynamics that break traditional approaches. First, the “Digitization Trap”: many organizations have digitized human-centric processes — onboarding, periodic access reviews — and then attempted to apply those scheduled cycles to machine identities. For identities that may exist for minutes or seconds, scheduled human reviews create operational drag and are functionally useless. Second, the path to higher maturity requires what the report calls a “Pivot to Machine-Speed Trust”: replacing standing privileges and manual, ticket-based access decisions with continuous, contextual, automated policy enforcement that operates at machine speed. According to SailPoint, this paradigm shift is a prerequisite for any program to reach the upper horizons of identity maturity.
The false compromise of “balance” and the market’s stall
Nearly half of organizations (49%) say they are trying to “balance both equally” — moving fast while staying secure. SailPoint’s data treats that posture as a false compromise. A stated intent to balance without the underlying automated, high-speed controls is not a strategy; it is a stall. The report argues many organizations are effectively trapped: they hold AI-speed ambitions yet remain on a human-speed foundation, waiting for an architectural shift that will resolve the paradox.
What this means for technologists and security teams, procurement leaders, and end users
- Technologists and security teams will need to shift away from periodic, human-driven controls toward continuous, policy-driven enforcement that can act at machine speed; the report signals that breaking standing privileges and automating context-aware decisions is necessary to climb into higher horizons.
- Procurement leaders and affected enterprises should demand solutions that extend proven governance disciplines to unmanaged non-human identities and that can unify human and agent identities into a single fabric, rather than products that merely digitize manual human processes.
- End users and the general public should expect continued acceleration of services driven by autonomous agents — but SailPoint’s analysis implies that broader, unified governance over non-human identities is the immediate priority if those services are to scale securely.
The report’s bottom line is direct: securing the autonomous enterprise does not require rebuilding from scratch. The immediate priority is to extend existing governance disciplines to cover unmanaged non-human identities operating across the digital estate, unifying them into a single fabric that can finally match the speed of AI. Until organizations make that architectural shift — moving from scheduled human controls to continuous machine-speed enforcement — the velocity paradox will remain an operational ceiling on both innovation and security.
Read the original SailPoint “Horizons of Identity Security” report coverage



