Join our Newsletter — 33% off our NHI Course

The NHI & Agentic AI Summit – Where Traditional IAM Breaks – IDV 2026

Session 2: Where Traditional IAM Breaks — Rethinking Trust for Autonomous Identities | Non-Human & Agentic AI Identity Summit @ Identiverse 2026

Speakers: Elisa Abedrapo, Identity Services SM, Epsilon | Homayun Yaqub, Advisory Services, Digital Hands | Itamar Apelblat, Co-Founder & CEO, Token Security | Alexis Moyse, Co-Founder & CEO, Clarity Security

In this session from the Non-Human & Agentic AI Identity Summit at Identiverse 2026, four identity and cybersecurity practitioners tackle one of the most uncomfortable questions in the space right now: is traditional IAM failing because of AI agents, or were we already failing long before they arrived?

The panel opens with a frank admission that sets the tone for everything that follows. Traditional IAM was never really working. 85% of breaches are still identity-based. Organisations have been finding unmanaged credentials for years. AI agents haven’t created a new failure — they’ve just made an existing one impossible to ignore any longer.

From there, the panel gets into what actually makes AI agents a distinct and harder problem. Unlike traditional NHIs — which are fast and diverse but at least deterministic — AI agents are probabilistic, goal-driven, and unpredictable in ways that break the assumptions IAM has always relied on. They can spawn sub-agents, operate at machine speed, and pursue objectives without the common sense constraints that make human identity behaviour at least somewhat predictable. That combination, as Homayun Yaqub puts it, isn’t just an inflection point. It’s a fundamentally new identity class.

The conversation around access governance is where the panel gets most specific. Elisa Abedrapo raises the core tension: when we provision humans we ask for justification and review it every three months — but an AI agent might exist for fifteen seconds. Alexis Moyse argues that intent-driven access is the answer, and that it should apply to humans and non-humans alike — not just agents. The access review as a periodic checkbox exercise, he argues, shouldn’t exist at all. The goal is to grant access in the least risky way possible to get a job done and revoke it the moment that job is done.

Itamar Apelblat pushes the philosophical implication further. Least privilege, just-in-time access, zero standing privilege — these principles are still sound, but they need to become dynamic rather than static. His practical advice to identity teams: start deploying agents in your own day-to-day work, because that is the fastest way to understand where the fundamentals break down in practice, and then work out how to support them at scale.

Homayun takes the trust question head-on. When asked what becomes the new unit of trust in a world where authorization decisions must be made continuously without human checkpoints, his answer is context — continuously evolving context that informs dynamic guardrails, not static controls. The shift, he argues, is from thinking about security in terms of behaviour — which is retrospective — to thinking about it in terms of posture and exposure. Where along an agent’s path does exposure become too high? Where are the choke points where dynamic controls can be applied before the agent’s usefulness tips into risk?

Alexis closes the IAM failure question plainly: it isn’t a new failure, it’s an existing one we’re finally being forced to deal with. The shift from protecting what AI says to protecting what AI does is the defining challenge for identity teams right now — and increasingly, those identity teams are the ones being looked to for how AI agents get governed and adopted securely across the organisation.

The session ends on a note of cautious optimism. The panel’s consensus: don’t try to solve for a fully autonomous multi-agent future today. Start by understanding which agents are deployed now, build governance that supports those use cases at scale, and expand from there.