Paper | September 29, 2026
Identity security for the agentic enterprise
Governing human, machine and AI identities at scale
by Patrick Hartmann, DXC Identity Governance Technical Lead, Martin Reilly, DXC Digital Identity Products and Offerings Manager and Sugandha Sinha, DXC Intelligent Cyber Offerings
Identity is the control layer that determines who and what can access enterprise systems, data, applications, and critical business processes. As enterprises adopt cloud, automation, and AI, effective identity governance must extend beyond employees, partners, and customers to devices, workloads, service accounts, APIs, automated processes, and AI agents. This broader control plane enforces least privilege, automates access lifecycles, and creates auditable evidence of access decisions, enabling organizations to scale AI securely and meet regulatory obligations.
Agentic AI introduces identity principals that most programs were not designed to govern. Boards therefore need identity controls that make automated actions attributable, constrained and reversible.
Identity is the enterprise control layer for AI. As organizations embed generative and agentic AI into core operations, the identities able to access data, modify records and execute sensitive actions are growing faster than legacy governance frameworks can manage. Agentic AI—autonomous systems that reason, invoke tools and act with limited human intervention—introduces identity principals that most programs were not designed to govern. Boards therefore need identity controls that make automated actions attributable, constrained and reversible.
Industry evidence reinforces the urgency. Gartner identifies machine identity and access management as one of the least mature and fastest-growing areas of identity security and forecasts that, by 2028, approximately 25% of enterprise breaches will involve the misuse or compromise of AI agents. IDC forecasts that more than one billion AI agents will be deployed worldwide by 2029 — approximately 40 times the 2025 level. Together with DXC and SailPoint observations, these findings position identity as the control layer for AI, cloud and digital transformation across human, machine and autonomous identities.
For business and technology leaders, weak identity governance creates three material risks: unmanaged and overprivileged identities expand the attack surface; inadequate attribution and auditability weaken compliance with GDPR, NIS2, DORA and the EU AI Act; and insufficient governance delays AI approvals and deployment, allowing better-prepared competitors to move faster.
This paper sets out what AI-ready identity governance requires:
- A unified inventory and ownership model
- Spanning human, machine, workload and AI identities
- Least privilege and scoped delegated authority for agents
- Automated identity and credential lifecycles
- Automated actions that are auditable by design
It then sets out how that capability is delivered in practice through DXC's Digital Identity advisory and governance operating model, SailPoint's AI-driven identity security platform and DXC OASIS-enabled managed services that run identity operations at machine scale.
The outcomes are measurable, and they should be managed as such rather than asserted. Organizations that establish identity as the foundation of AI governance will be positioned to move faster on AI with a defensible control model behind it.