TL;DR: Super apps, agentic AI, and tighter EU regulation are converging in 2026, and KOBIL argues that security by design, verified digital identities, and centralised lifecycle control are now required to keep identity, access, and data governance coherent across platforms. The practical issue is not just feature sprawl but the loss of control that follows when human and AI-driven access are managed separately.
NHIMG editorial — based on content published by KOBIL: artificial intelligence, super apps, platform security, and digital sovereignty in 2026
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
Questions worth separating out
Q: How should organizations approach the governance of AI agents?
A: Organizations should adopt a governance framework that incorporates continuous visibility, adaptive IAM practices, and stringent policy-based controls.
Q: Why do superapps increase identity governance pressure for IAM teams?
A: Because they concentrate many business processes under one authenticated environment, so access scope, proofing quality, and lifecycle decisions have wider blast radius.
Q: What breaks when identity lifecycle processes stay fragmented across teams?
A: Fragmentation creates inconsistent provisioning, slow offboarding, duplicate reviews, and unclear accountability.
Practitioner guidance
- Map the shared trust boundary Document every identity, session, and delegation path inside the super app or consolidated platform, including human users, service providers, and AI agents.
- Define AI agent privilege scopes Assign each AI agent a named identity, least-privilege scope, and explicit revocation trigger before it is allowed to execute customer, citizen, or internal workflows.
- Unify lifecycle controls across actors Bring employees, partners, and service accounts into one access lifecycle so provisioning, periodic review, and offboarding follow the same governance evidence model.
What's in the full article
KOBIL's full article covers the operational detail this post intentionally leaves for the source:
- How KOBIL maps super app security to verified digital identities for people and AI agents across mobile workflows.
- How its platform consolidation model handles employee, partner, and service-provider access across the full lifecycle.
- Why the company links digital sovereignty to data control, identity control, and European jurisdictional governance.
- Where its mobile security and app protection components fit into the broader compliance and audit narrative.
👉 Read KOBIL's analysis of super apps, agentic AI, and digital sovereignty →
Super apps and agentic AI: what identity teams need to secure now?
Explore further
Security by design is no longer a product feature, it is the governing model for shared digital platforms. Super apps compress identity, transactions, and data into a single experience, which means security failures now propagate faster across business functions. That is why the governance question is not whether a platform has encryption or MFA in isolation, but whether its identity architecture can preserve trust across every delegated action. Practitioners should evaluate control coherence before they evaluate feature breadth.
A few things that frame the scale:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
A question worth separating out:
Q: Who should own digital sovereignty decisions for identity and access?
A: Identity, security, and legal teams should own the control model together, because sovereignty depends on where identity data, logs, and policy enforcement operate. Procurement can choose providers, but it cannot validate operational control alone. The practical test is whether the organisation can still govern identities and recover services if a provider or jurisdiction is disrupted.
👉 Read our full editorial: Super apps and agentic AI need security by design in 2026