TL;DR: A survey of 416 CIAM decision makers found 82% reporting negative business impact from customer identity issues, while 87% still use password-based authentication and 88% are using or planning to use AI agents, according to Descope. The pattern shows CIAM shifting from a login problem to a governance problem that now spans customers, developers and agentic access.
At a glance
What this is: Descope’s survey says customer identity is creating business drag because password reliance, patchwork CIAM and rising AI agent use are outpacing current governance models.
Why it matters: IAM and security teams need to treat CIAM as a governance problem across human and non-human access paths, not just a login experience problem.
By the numbers:
- 82% of survey respondents cited at least some negative business impact from customer identity issues.
- 87% of organisations use password-based authentication for their customer-facing applications.
- 51% of organisations use their existing workforce IAM to implement customer auth, while only 8% would choose to do the same if they were to start from scratch.
- 88% of respondents are using or planning to use AI agents, but only 37% have progressed beyond pilot programs.
Context
Customer identity is the set of controls that determines how external users authenticate, recover access and move through digital journeys. In this survey, the pressure comes from three directions at once: password dependence, patchwork CIAM implementations and the growing need to govern AI agents alongside people.
Descope’s findings matter because CIAM is no longer only about reducing login friction. When customer identity is bolted onto workforce IAM or spread across ad hoc tools, the result is higher support cost, slower launches and weaker governance over both human and non-human access paths.
The article’s core claim is not that organisations lack identity tooling. It is that many are trying to operate customer identity with control models designed for a different population, while AI agents make that mismatch more visible.
Key questions
Q: What breaks when organisations use workforce IAM for customer identity journeys?
A: The usual failure mode is rigidity. Workforce IAM tends to assume stable populations, administrative provisioning, and slower policy change, while customer journeys require rapid experience updates, flexible authentication, and lower-friction recovery. The result is often poor user experience, more engineering dependency, and a governance model that cannot keep pace with business needs.
Q: Why do passwords still create business risk in CIAM programmes?
A: Passwords create risk because they increase recovery volume, drive user frustration and leave identity teams managing exceptions at scale. The business cost is not just weaker assurance. It is higher support demand, slower onboarding and more abandonment when users cannot move through the journey smoothly.
Q: How should teams govern AI agents that act inside customer accounts?
A: Treat them as delegated non-human identities, not as ordinary customer sessions. Governance should require explicit consent, narrow authorization scope, token binding, and a complete audit record tying each action back to the human principal that approved it.
Q: How can teams tell whether CIAM is becoming a governance problem?
A: CIAM is becoming a governance problem when identity choices start showing up as support cost, launch delay, user dropoff and repeated exception handling. Those signals mean the control model is no longer aligned to the business journey, and patchwork fixes are masking the underlying architecture issue.
Technical breakdown
Why password-centric CIAM keeps breaking down
Passwords remain common because they are familiar, but they create recurring operational load for support, recovery and onboarding. In CIAM, the problem is not only weak assurance. It is that password-based journeys create a large recovery surface, encourage workaround behaviours and make user experience depend on how much friction teams are willing to tolerate. When most customers still authenticate this way, identity teams spend more time managing exceptions than shaping coherent access policy. That is why password dependence persists even when teams recognise it is suboptimal.
Practical implication: Treat password reduction as a governance programme, not just an authentication feature choice.
Why workforce IAM is a poor substitute for customer identity
Workforce IAM and CIAM solve different identity problems. Workforce IAM is optimised for employees, contractors and internal lifecycle assumptions, while customer identity has different scale, support, consent and recovery patterns. Using internal IAM for external users often produces brittle onboarding, poor self-service and limited visibility into customer authentication decisions. The survey’s split between what organisations do today and what they would choose from scratch shows that the substitute model is often accepted for speed, not because it fits the operating reality.
Practical implication: Separate customer identity architecture decisions from workforce IAM assumptions before technical debt hardens into policy.
How AI agents change the CIAM boundary
AI agents introduce a new identity subject that is neither a human customer nor a conventional backend service. They may initiate actions, access data and operate within customer journeys, which means CIAM has to govern agent identity, not just customer sessions. That changes authorisation, auditability and trust boundaries. The challenge is especially sharp where organisations have not yet defined whether an agent is acting on behalf of a customer, as a system component or as a distinct identity with its own access scope. Without that distinction, governance becomes ambiguous.
Practical implication: Define whether agents are customers, services or separate identities before allowing them into production journeys.
NHI Mgmt Group analysis
Customer identity has crossed from authentication design into lifecycle governance. The survey’s central message is that CIAM is now being shaped by operational consequences, not only login mechanics. Once support cost, launch delays and onboarding loss become the measurable outcomes, the control problem is broader than password choice. Practitioners should read this as a governance shift, not a UI debate.
Identity boundary collapse: Workforce IAM is designed for internal users with internal lifecycle assumptions, and that premise fails when the same stack is repurposed for customers. The survey shows that organisations know this intuitively, which is why only 8% would choose that path again from scratch. The implication is that customer identity architecture must be treated as a distinct discipline, not an inheritance layer.
AI agents turn CIAM into a multi-actor trust problem. Once agents enter customer journeys, the programme has to govern actions, access and accountability across human users and software actors at the same time. That raises the value of explicit identity classification, scoped authorisation and auditable delegation. Practitioners should expect CIAM to converge with NHI governance rather than remain a purely customer-facing function.
Patchwork implementations are now a resilience issue, not just a technical debt issue. The article links fragmented identity design to launch delays, support burden and conversion loss, which means the business impact lands directly in operating performance. That makes CIAM rationalisation a board-level identity architecture question, not a narrow authentication upgrade. Practitioners should prioritise control coherence over point fixes.
Named concept: customer identity governance gap. The gap is the distance between what customer-facing identity journeys now require and what legacy authentication and inherited IAM models can reliably govern. AI agents widen that gap because they add a new identity subject without simplifying the underlying control model. Practitioners should use this gap as the organising concept for CIAM modernisation.
From our research library:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap, according to the State of Secrets in AppSec.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: AI Agent Identity Security Buyer's Guide
What this signals
Customer identity governance gap: External identity journeys now demand controls that sit between consumer simplicity and enterprise-grade assurance, and inherited workforce models rarely land there cleanly. That gap widens further when AI agents enter the journey as separate actors, because the identity subject is no longer just a person.
CIAM programmes should be measured against business outcomes as much as against authentication strength. When support tickets, onboarding abandonment and release delays rise together, the programme has shifted from an identity feature set to an operating constraint that needs architectural correction.
For practitioners
- Separate customer and workforce identity architecture Stop treating workforce IAM as the default control plane for customers. Map the identity lifecycle, recovery, consent and support requirements that are unique to external users before changing platforms.
- Reduce password dependence in customer journeys Prioritise passkeys, stronger phishing-resistant authentication and recovery paths that lower helpdesk load without forcing customers through brittle fallback steps.
- Define an identity model for AI agents Classify agents explicitly as separate identities or delegated actors, then assign access scope, logging and approval rules before they enter production journeys.
- Measure business impact from identity friction Track support tickets, onboarding dropoff and identity-related launch delays together so CIAM decisions are tied to operational outcomes, not only security metrics.
Key takeaways
- Customer identity issues are now producing measurable business drag, which means CIAM has to be managed as a governance programme rather than a front-end login layer.
- Password dependence and workforce IAM reuse both point to a control model that no longer fits external identity journeys or the arrival of AI agents.
- The practical response is to separate customer identity architecture, reduce password reliance and define how non-human actors are authorised before they reach production.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | AI agents in customer journeys create identity and privilege boundaries that need explicit control. |
| Recommendation — Define agent identity boundaries and scope privileges before allowing agent-driven customer actions. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centers on weak authentication patterns and customer-facing identity journeys. |
| Recommendation — Replace weak customer authentication flows with stronger, phishing-resistant options and governed recovery. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The survey points to poor alignment between access control and customer identity use cases. |
| Recommendation — Review customer access permissions so entitlements match external user journeys and risk. | ||
| CIS Controls v8 | CIS-5 — Account Management | Customer identity lifecycle and access governance are central to the article’s CIAM findings. |
| Recommendation — Standardise account management for customer identities to reduce exception handling and access drift. | ||
Key terms
- Customer Identity And Access Management: Customer Identity and Access Management is the discipline of governing how external users sign in, recover access, and move through digital services. It combines authentication, profile management, and lifecycle control so organisations can deliver secure, low-friction experiences at scale.
- Password Authentication: Password authentication is a login method that relies on a shared secret a user types to prove identity. In exposed infrastructure, it creates predictable risk because passwords can be guessed, reused, phished, or brute-forced. Replacing it with cryptographic keys and multifactor authentication materially raises the cost of unauthorized access.
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org