Research Hub > AI Identity Security and the Evolution of IAM | CDW
White Paper
12 min

AI Identity Security and the Evolution of IAM

Identity threats are advancing faster than most organizations can respond. To stay secure, leaders must rethink how they govern access across humans, machines and artificial intelligence.

IN THIS ARTICLE

As artificial intelligence agents and nonhuman identities (NHIs) proliferate, organizations can no longer rely on perimeter defenses or traditional identity solutions. The new security model is identity-first: determining who or what is requesting access in the moment, every time. 

Yet many organizations are struggling to make this shift and to adapt their IAM strategies to AI-enabled environments. Complexity and a lack of internal expertise make it difficult to establish proper governance and implement best practices consistently, while fragmentation and a lack of integration pose challenges to scale. Moreover, NHIs now dominate many IT environments, even as organizations have yet to resolve existing risks, such as dormant accounts, permission sprawl and multifactor authentication gaps.

In response, IAM is expanding to bring humans, machines and AI agents under a unified governance model, anchored by zero-trust principles, least-privilege access and continuous verification for every identity.

Build an identity and access management program designed to address AI-driven risks and emerging threats.

As artificial intelligence agents and nonhuman identities (NHIs) proliferate, organizations can no longer rely on perimeter defenses or traditional identity solutions. The new security model is identity-first: determining who or what is requesting access in the moment, every time. 

Yet many organizations are struggling to make this shift and to adapt their IAM strategies to AI-enabled environments. Complexity and a lack of internal expertise make it difficult to establish proper governance and implement best practices consistently, while fragmentation and a lack of integration pose challenges to scale. Moreover, NHIs now dominate many IT environments, even as organizations have yet to resolve existing risks, such as dormant accounts, permission sprawl and multifactor authentication gaps.

In response, IAM is expanding to bring humans, machines and AI agents under a unified governance model, anchored by zero-trust principles, least-privilege access and continuous verification for every identity.

Build an identity and access management program designed to address AI-driven risks and emerging threats.

People meeting

The Evolution of Cybersecurity and IAM

Amid the rapid expansion of artificial intelligence, organizations are rethinking identity and access management and recognizing that perimeter defenses and even advanced IAM are insufficient if they do not properly manage nonhuman identities. As AI agents and other NHIs proliferate, organizations are shifting from an “inside/outside” framework to an identity-first model that determines who or what is requesting access in the moment. IAM is also evolving from a toolset focus centered on capabilities, such as multifactor authentication (MFA), into a centralized control plane for cybersecurity.

For many organizations, making these shifts is easier said than done. Nearly 94% of IT and security leaders say that complexity in identity infrastructure poses a challenge to their organizations’ security posture. Fragmentation, lack of governance and insufficient skill sets make it difficult to scale and integrate IAM. Moreover, NHIs now dominate IT environments, exercising a profound effect on security and IAM. And, many organizations have yet to resolve existing identity-related risks, such as permission sprawl, MFA gaps and dormant accounts (by one estimate, comprising 38% of all accounts). 

To address these challenges, IAM is bringing humans, machines and AI agents under a unified model with consistent governance and security protections. In this environment, IAM best practices are essential, including least-privilege access, privileged access management (PAM) and identity lifecycle management. This shift underpins broader frameworks, such as zero-trust architecture and the continuous authentication of devices, users, behaviors and contextual cues before access is allowed. 

A strong IAM program is a core component of an overall security strategy. However, while leaders recognize the dangers of insufficient IAM, many organizations lack the expertise to address these challenges effectively. External guidance can be crucial to ensure that IAM solutions, policies and practices are firmly in place to manage existing and emerging risks in AI-enabled environments.

55%

The percentage of identity permissions that were “safe and compliant” in 2025, down from 70% in 2024

Source: Veza, “State of Identity & Access 2026,” December 2025

back-to-top

CDW can help modernize your IAM strategy.

The Evolution of Cybersecurity and IAM

Amid the rapid expansion of artificial intelligence, organizations are rethinking identity and access management and recognizing that perimeter defenses and even advanced IAM are insufficient if they do not properly manage nonhuman identities. As AI agents and other NHIs proliferate, organizations are shifting from an “inside/outside” framework to an identity-first model that determines who or what is requesting access in the moment. IAM is also evolving from a toolset focus centered on capabilities, such as multifactor authentication (MFA), into a centralized control plane for cybersecurity.

For many organizations, making these shifts is easier said than done. Nearly 94% of IT and security leaders say that complexity in identity infrastructure poses a challenge to their organizations’ security posture. Fragmentation, lack of governance and insufficient skill sets make it difficult to scale and integrate IAM. Moreover, NHIs now dominate IT environments, exercising a profound effect on security and IAM. And, many organizations have yet to resolve existing identity-related risks, such as permission sprawl, MFA gaps and dormant accounts (by one estimate, comprising 38% of all accounts). 

To address these challenges, IAM is bringing humans, machines and AI agents under a unified model with consistent governance and security protections. In this environment, IAM best practices are essential, including least-privilege access, privileged access management (PAM) and identity lifecycle management. This shift underpins broader frameworks, such as zero-trust architecture and the continuous authentication of devices, users, behaviors and contextual cues before access is allowed. 

A strong IAM program is a core component of an overall security strategy. However, while leaders recognize the dangers of insufficient IAM, many organizations lack the expertise to address these challenges effectively. External guidance can be crucial to ensure that IAM solutions, policies and practices are firmly in place to manage existing and emerging risks in AI-enabled environments.

CDW can help modernize your IAM strategy.

IAM Evolution By the Numbers

65%

The percentage of organizations that say managing NHIs or machine identities is among their top priorities

Source: Identity Defined Security Alliance, “2025 Trends in Identity Security,” September 2025

4.8

The average number of systems in which a single enterprise identity is stored

79%

The percentage of IT and security leaders exploring vendor consolidation as a way to simplify identity security and improve visibility

IAM Evolution By the Numbers

65%

The percentage of organizations that say managing NHIs or machine identities is among their top priorities

Source: Identity Defined Security Alliance, “2025 Trends in Identity Security,” September 2025

4.8

The average number of systems in which a single enterprise identity is stored

79%

The percentage of IT and security leaders exploring vendor consolidation as a way to simplify identity security and improve visibility

cdw

How AI Is Transforming Identity Security

AI affects IAM in several important ways, and organizations are struggling to ascertain the scope of the challenge. While AI-enabled IAM tools strengthen teams’ security capabilities, AI-powered attacks open new doors to bad actors. AI agents, NHIs and shadow AI expand the access-related risks that organizations must monitor and manage. 

A NEW LANDSCAPE: Machine identities include NHIs (such as AI agents), application programming interfaces (APIs), certificates and service accounts. These can outnumber humans a hundredfold. Many organizations do not know which identities are present in their environment or what permissions they have. Another important consideration, as organizations expand AI models and inferences, is the vast amount of data these systems access and can inadvertently expose if they are not properly protected. In addition, unlike human identities, NHIs may stay in the environment indefinitely if ownership and lifecycle management are lacking.

SECURING EVERY IDENTITY: As of 2025, 62% of organizations were experimenting with AI agents or had scaled across one or two functions. However, many are doing so without clear IAM frameworks, leaving AI agents with greater access and cross-system capabilities than necessary. Meanwhile, machine identities pose risks related to hardcoded secrets, orphaned credentials and API tokens.

Governance is the core tenet of identity management. As with human identities, NHIs require clear ownership and policies, ongoing oversight, and best practices such as temporary or rotating credentials. Rather than granting persistent access to AI agents, organizations should require them to reauthenticate every time, with stepped-up verification for additional privileges. Human ownership should be clearly documented and periodically reviewed for accountability, and agent activity must be monitored for anomalies.

AI ON THE OFFENSE: Bad actors use AI to gain unauthorized access in a variety of ways, such as stealing credentials through expedited password cracking or impersonating IT help desks with convincing deepfakes that allow access to high-level accounts. AI can also enable automated reconnaissance of identity systems to quickly identify points of entry, such as dormant accounts or overprivileged credentials that could provide access to high-value systems.

DEFENSIVE AI: On the flip side, AI helps IAM solutions become more adaptive, proactive and intelligence driven. Vendors continue to integrate AI capabilities into IAM and identity governance and administration (IGA) platforms, where it automates processes related to authentication, provisioning and reporting. For example, AI-enabled platforms apply behavioral analytics to detect abnormal login or access patterns and use contextual cues to make real-time, risk-based access decisions. Organizations are also incorporating identity-based verification into edge protection with solutions such as secure access service edge and cloud-based cybersecurity platforms.

EVOLUTION OF ZERO TRUST: While 71% of IT and security leaders see value in a zero-trust approach, only 23% apply it consistently, and nearly half reserve it for critical or high-risk identities — a cause for concern if NHIs are not included in this category. Zero-trust principles, including continuous verification (as opposed to login-only checks) and least-privilege access, are nonnegotiable for modern environments in which AI introduces new attack vectors and new avenues for malicious behavior. Today, zero trust must extend to APIs and other machine identities, as well as AI agents and workloads. For many organizations, this represents a significant shift in their IAM approach.

Click Below To Continue Reading

arrow

From Passwords to Passwordless

Passwordless and phishing-resistant authentication helps organizations achieve the elusive goal of strengthening security while removing friction from the user experience. Adoption won’t happen overnight. Although 61% of IT and security leaders want their organizations to adopt passwordless access, they expect legacy systems and other challenges to make that difficult. But organizations are clearly moving in that direction.

Passwordless authentication verifies users with passkeys stored on a device, biometric identification or hardware keys. The FIDO (Fast Identity Online) Alliance has established industrywide authentication standards for passkey credentials.

These methods help to reduce credential theft and unauthorized access arising from phishing tactics, such as tricking users into entering sign-on information on a malicious website.

While passkeys, biometrics and FIDO-based authentication are becoming standard, adoption is growing slowly: Only 19% of organizations had fully implemented FIDO2 tokens as of 2025.

Passwordless authentication is a notable advance in user experience, enhancing productivity and efficiency for users and IT help desks. It also adds a security layer by incorporating devices into the authentication process.

back-to-top-white
cdw

How AI Is Transforming Identity Security

AI affects IAM in several important ways, and organizations are struggling to ascertain the scope of the challenge. While AI-enabled IAM tools strengthen teams’ security capabilities, AI-powered attacks open new doors to bad actors. AI agents, NHIs and shadow AI expand the access-related risks that organizations must monitor and manage. 

A NEW LANDSCAPE: Machine identities include NHIs (such as AI agents), application programming interfaces (APIs), certificates and service accounts. These can outnumber humans a hundredfold. Many organizations do not know which identities are present in their environment or what permissions they have. Another important consideration, as organizations expand AI models and inferences, is the vast amount of data these systems access and can inadvertently expose if they are not properly protected. In addition, unlike human identities, NHIs may stay in the environment indefinitely if ownership and lifecycle management are lacking.

SECURING EVERY IDENTITY: As of 2025, 62% of organizations were experimenting with AI agents or had scaled across one or two functions. However, many are doing so without clear IAM frameworks, leaving AI agents with greater access and cross-system capabilities than necessary. Meanwhile, machine identities pose risks related to hardcoded secrets, orphaned credentials and API tokens.

Governance is the core tenet of identity management. As with human identities, NHIs require clear ownership and policies, ongoing oversight, and best practices such as temporary or rotating credentials. Rather than granting persistent access to AI agents, organizations should require them to reauthenticate every time, with stepped-up verification for additional privileges. Human ownership should be clearly documented and periodically reviewed for accountability, and agent activity must be monitored for anomalies.

AI ON THE OFFENSE: Bad actors use AI to gain unauthorized access in a variety of ways, such as stealing credentials through expedited password cracking or impersonating IT help desks with convincing deepfakes that allow access to high-level accounts. AI can also enable automated reconnaissance of identity systems to quickly identify points of entry, such as dormant accounts or overprivileged credentials that could provide access to high-value systems.

DEFENSIVE AI: On the flip side, AI helps IAM solutions become more adaptive, proactive and intelligence driven. Vendors continue to integrate AI capabilities into IAM and identity governance and administration (IGA) platforms, where it automates processes related to authentication, provisioning and reporting. For example, AI-enabled platforms apply behavioral analytics to detect abnormal login or access patterns and use contextual cues to make real-time, risk-based access decisions. Organizations are also incorporating identity-based verification into edge protection with solutions such as secure access service edge and cloud-based cybersecurity platforms.

EVOLUTION OF ZERO TRUST: While 71% of IT and security leaders see value in a zero-trust approach, only 23% apply it consistently, and nearly half reserve it for critical or high-risk identities — a cause for concern if NHIs are not included in this category. Zero-trust principles, including continuous verification (as opposed to login-only checks) and least-privilege access, are nonnegotiable for modern environments in which AI introduces new attack vectors and new avenues for malicious behavior. Today, zero trust must extend to APIs and other machine identities, as well as AI agents and workloads. For many organizations, this represents a significant shift in their IAM approach.

Click Below To Continue Reading

arrow

From Passwords to Passwordless

Passwordless and phishing-resistant authentication helps organizations achieve the elusive goal of strengthening security while removing friction from the user experience. Adoption won’t happen overnight. Although 61% of IT and security leaders want their organizations to adopt passwordless access, they expect legacy systems and other challenges to make that difficult. But organizations are clearly moving in that direction.

Passwordless authentication verifies users with passkeys stored on a device, biometric identification or hardware keys. The FIDO (Fast Identity Online) Alliance has established industrywide authentication standards for passkey credentials.

These methods help to reduce credential theft and unauthorized access arising from phishing tactics, such as tricking users into entering sign-on information on a malicious website.

While passkeys, biometrics and FIDO-based authentication are becoming standard, adoption is growing slowly: Only 19% of organizations had fully implemented FIDO2 tokens as of 2025.

Passwordless authentication is a notable advance in user experience, enhancing productivity and efficiency for users and IT help desks. It also adds a security layer by incorporating devices into the authentication process.

CDW can help your organization align its IAM program with strategic security objectives.

Cloudflare
Cyberark
Microsoft
Okta

CDW Experts

CDW Expert

From implementing IT solutions to researching emerging tech trends, our experts have years of experience working with the latest technologies.