TL;DR: Identity has moved from administrative plumbing to the enterprise control plane, with permissions metadata, authorization paths, and micro-certifications now defining where risk lives and how AI governance must scale, according to Veza. Incremental IAM, PAM, and IGA tuning is no longer enough; the governing assumption that access can be understood through directories and periodic reviews has collapsed.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “Looking ahead to 2026”.
Key questions
Q: How should IAM teams govern permissions instead of just user accounts?
A: IAM teams should govern effective permissions as the primary control object.
Q: Why do periodic access reviews struggle in AI-heavy environments?
A: Because risk changes faster than the review cycle.
Q: What breaks when identity is still treated as directory plumbing?
A: What breaks is the organisation’s ability to see authorization risk.
Practitioner guidance
- Map effective permissions, not just identities Build your governance inventory around what each subject can actually do across systems, including inherited and transitive access paths.
- Shift certification to permission-level decisions Replace broad access recertification with micro-certification workflows that validate specific entitlements in context and at the point of use.
- Model AI agent access chaining Trace how an AI agent acquires, combines, and uses delegated access so the control plane can evaluate runtime authorization paths.
Bottom line: The article argues that identity now governs enterprise risk through permissions metadata and authorization paths, not through directories and group membership alone.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity is now the enterprise control plane because authorization, not authentication, determines enterprise risk. The article is right to separate control from login events and directory records. In distributed systems, the real question is what access actually enables across applications, data, and workflow boundaries. That shifts identity from administration to governance infrastructure, and practitioners should manage the authorization plane as a primary control surface.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 52% of respondents see AI security decision-making power shifting toward platform and infrastructure teams rather than the executive suite, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.
👉 Read our full editorial: Identity as the enterprise control plane for AI governance