Session 6: The Buyer’s Dilemma — Evaluating the NHI & Agentic AI Security Market | Non-Human & Agentic AI Identity Summit @ Identiverse 2026
Speakers: Amit Masand, Founder & CEO, IDM Express | Murad Dikeidek, Head of Cybersecurity, UI Health | Steven Rennick, Senior IT Architect, Ciena
In this session from the Non-Human & Agentic AI Identity Summit at Identiverse 2026, security practitioners from healthcare and enterprise infrastructure get into the part of the NHI and agentic AI conversation that vendor marketing tends to obscure: how do you actually evaluate, select, and implement a solution in a market where every vendor claims to solve everything?
The session opens with a reality check from Steven Rennick. Walk the vendor hall, he says, and every booth will tell you the same thing — full NHI coverage, full agentic AI support, all your problems solved. The question isn’t what vendors claim. It’s whether organisations even understand their own environment well enough to evaluate those claims. His position: if you don’t know what NHIs you have, how they’re being created, and where the actual problems sit, don’t talk to a vendor yet. You’ll end up buying a solution that’s looking for a problem.
Murad Dikeidek, who manages cybersecurity for a 460-bed academic hospital with 26 clinics across the Chicago area, frames the buyer’s journey as a structured process of progressive narrowing. Start with a requirements list — must-haves and nice-to-haves — before ever engaging with vendor messaging. Use trusted analyst resources like Gartner and Forrester to get to a shortlist. Talk to peers in your industry who have already been through the process, because shared challenges mean their experience is directly relevant. Narrow to fewer than ten vendors before doing demos, then conduct a proof of concept in your own environment. Every product claims to solve your problems — the only way to verify that is to test it against your actual use cases. And more than the product itself, evaluate the vendor: not a vendor you buy from, but a partner who will grow with your organisation.
One practical point Dikeidek raises that tends to get skipped: reporting and dashboards. A product has to be able to show how it reduces risk in terms that leadership can understand. If you can’t answer the question of whether you’re getting ROI, the product is failing you regardless of its technical capabilities. The tool needs to sell itself, not require you to build a manual case for it every budget cycle.
Rennick pushes on the implementation reality. NHI and agentic AI security isn’t a side gig for the team that runs your Okta or manages PAM. It requires people with the right capabilities and a genuinely modern lens — treating the problem the same way you’ve always treated workforce identity problems will not work. He also challenges organisations to look inward before writing a large check: most identity platforms are already starting to address discovery and NHI governance. The starting point should be what you already own, what gaps exist, and whether your existing vendors are even talking about the right things — intent, transaction tokens, shared signals framework, identity fabric. If they’re not, that’s a signal.
Dikeidek raises one of the most underappreciated failure modes in enterprise security buying: buying the right product and deploying it into the wrong environment. He describes the pattern as buying the Cadillac and implementing the Chevy — overpaying for capabilities that the organisation isn’t ready to use because the prerequisites — clean permissions, defined ownership, baseline governance hygiene — aren’t in place. He now asks vendors directly: what does our environment need to look like before your product works properly? That question alone saves significant time and money.
On what makes the agentic AI buying decision different from traditional IAM procurement, the panel’s consensus is that the problem has fundamentally changed in scale and unpredictability. Traditional access was defined and predictable. Agentic AI creates identities that can spawn further identities, with access patterns that cannot be anticipated in advance. That means the requirements-definition phase is harder, the proof of concept is more complex, and the governance structures around the solution — data committees, access committees, monitoring and accountability frameworks — matter as much as the product capabilities themselves.
Rennick closes on the organisational reality: NHI is a programme, not a project. It will not be solved and then wrapped up. It will be ongoing, it will grow in complexity, and it requires executive sponsorship from the top rather than a grassroots effort from identity teams who have competing priorities. Without that sponsorship, even the right product in the right environment will fail — because the cross-functional cooperation required to make it work simply won’t materialise without it.