Join our Newsletter — 33% off our NHI Course

Customer identity is under pressure, and AI agents add to it

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: A survey of 416 CIAM decision makers found 82% reporting negative business impact from customer identity issues, while 87% still use password-based authentication and 88% are using or planning to use AI agents, according to Descope. The pattern shows CIAM shifting from a login problem to a governance problem that now spans customers, developers and agentic access.

Editorial analysis by NHI Mgmt Group, based on content published by Descope: “Descope Survey Shows 82% of Organizations Experience Negative Business Impact Due to Customer Identity Issues”.

By the numbers:

  • 82% of survey respondents cited at least some negative business impact from customer identity issues.
  • 87% of organisations use password-based authentication for their customer-facing applications.
  • 51% of organisations use their existing workforce IAM to implement customer auth, while only 8% would choose to do the same if they were to start from scratch.

Key questions

Q: What breaks when organisations use workforce IAM for customer identity journeys?

A: The usual failure mode is rigidity.

Q: Why do passwords still create business risk in CIAM programmes?

A: Passwords create risk because they increase recovery volume, drive user frustration and leave identity teams managing exceptions at scale.

Q: How should teams govern AI agents that act inside customer accounts?

A: Treat them as delegated non-human identities, not as ordinary customer sessions.

Practitioner guidance

  • Separate customer and workforce identity architecture Stop treating workforce IAM as the default control plane for customers.
  • Reduce password dependence in customer journeys Prioritise passkeys, stronger phishing-resistant authentication and recovery paths that lower helpdesk load without forcing customers through brittle fallback steps.
  • Define an identity model for AI agents Classify agents explicitly as separate identities or delegated actors, then assign access scope, logging and approval rules before they enter production journeys.

Bottom line: Customer identity issues are now producing measurable business drag, which means CIAM has to be managed as a governance programme rather than a front-end login layer.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21403
 

Customer identity has crossed from authentication design into lifecycle governance. The survey’s central message is that CIAM is now being shaped by operational consequences, not only login mechanics. Once support cost, launch delays and onboarding loss become the measurable outcomes, the control problem is broader than password choice. Practitioners should read this as a governance shift, not a UI debate.

A few things that frame the scale:

  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap, according to the State of Secrets in AppSec.
  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How can teams tell whether CIAM is becoming a governance problem?

A: CIAM is becoming a governance problem when identity choices start showing up as support cost, launch delay, user dropoff and repeated exception handling. Those signals mean the control model is no longer aligned to the business journey, and patchwork fixes are masking the underlying architecture issue.

👉 Read our full editorial: Customer identity is straining under passwords, patchwork and AI agents


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.