Agentic AI Identity Security: Why IAM Must Evolve Now

The News

SecureAuth CEO Geoffrey Mattson joined the AppDevANGLE podcast to discuss the rapidly evolving intersection of identity security, agentic AI, and zero trust architecture. Mattson outlined how the rise of AI agents has created an entirely new class of security threat, one that traditional identity and access management platforms were never designed to handle. The company, which has served large financial institutions and healthcare providers for roughly two decades, is now positioning its behavioral analytics and adaptive authentication capabilities as the control plane for agentic AI deployments.

Analyst Take

The IAM Problem Is No Longer About Humans

The conventional IAM model operates on a simple premise: authenticate a human once, authorize a set of actions, and let detection tools catch anything that goes wrong afterward. That model is structurally incompatible with agentic AI. Agents are non-deterministic. They operate continuously, act across dozens of integrated systems simultaneously, and can alter behavior mid-session based on context. Mattson’s framing is important: the identity question for an agent isn’t “who are you?” but “what are you doing right now, and does it match what you should be doing?”

This is a substantive architectural shift for enterprise security teams. The perimeter model collapsed once with cloud adoption; it’s collapsing again with agents. The attack surface for an LLM-based agent isn’t a set of known API endpoints or SQL inputs; it’s the full breadth of natural language the model understands. That’s not a gap you close with a firewall rule or a static policy. It requires continuous behavioral profiling layered on top of authorization policies, which is exactly the capability SecureAuth is describing.

The Friction Tradeoff Has New Stakes

Security teams have always lived with the friction-versus-security tradeoff, but the agentic context makes it acute in a new way. Requiring human approval for every agent action is theoretically the safest approach and operationally impossible. Agents executing thousands of transactions per second simply cannot be gated on human consent loops. Mattson’s point about SMS-based step-up authentication is a useful illustration of the broader problem: controls that feel robust on paper carry real costs in money, latency, and user experience, and they still fail against modern attack vectors like SIM swapping.

The same economic logic applies at enterprise scale. When agents are involved in revenue-generating workflows, such as financial transactions, customer onboarding, or supply chain decisions, excessive friction doesn’t just slow things down. It creates pressure to loosen controls, cache credentials, or route around security tooling entirely. SecureAuth’s adaptive analytics approach, making real-time decisions about whether to challenge an actor based on behavioral signals rather than static schedules, is the more defensible architecture for this environment.

What the Data Says About Where Organizations Actually Are

The timing of this conversation matters. ECI Research’s 2026 Application Development: Day 0 survey found that 53.5% of respondents selected “AI-enabled development tools” as a top investment priority for the next 12 months, making it the single most cited priority in the survey. Agentic AI isn’t a future consideration; it’s being deployed now, often faster than security controls are being updated to match. That deployment velocity is exactly the threat surface Mattson is describing.

The supply chain security picture compounds the concern. According to ECI Research’s 2026 Application Development: DevSecOps & AppSec survey, 29.1% of respondents identified “AI-generated package risk” as their biggest open-source security concern in 2026. When you pair that with the finding from the same survey that 45.3% of respondents said AI-assisted development has “increased risk moderately,” a picture emerges of an industry that is adopting AI tools rapidly while still working out the security implications. SecureAuth’s agentic security positioning lands squarely in that gap.

The zero trust framing Mattson uses is well-suited to this moment. Identity-centric zero trust, where every action by every actor (human or agent) is evaluated in real time against authorization policy and behavioral profile, is the architectural model that actually fits a distributed, agentic environment. The challenge for enterprises is that most existing IAM infrastructure was built for periodic, human-initiated authentication events. Retrofitting continuous, intent-based evaluation onto that stack is non-trivial, and it’s where purpose-built vendors like SecureAuth have a credible opening.

Looking Ahead

The agentic AI security market is early but moving fast, and the vendors who establish behavioral profiling and continuous authorization as the standard model will have significant durability. SecureAuth’s two-decade history with large financial and healthcare customers gives it a meaningful reference base in exactly the sectors where agent-driven workflows and regulatory exposure intersect most sharply. The public agent risk registry Mattson mentioned is a smart positioning move: it creates a low-friction entry point for security teams evaluating agent deployments and builds brand association with the problem before competitors define the category.

The broader market implication is that identity security vendors who cannot extend their platforms to non-human identities will face increasing displacement. The convergence Mattson describes, where detection and response capabilities must be embedded into the IAM control plane rather than operating as a separate layer, is a structural consolidation signal. Watch for acquisition activity in this space as larger security platform vendors attempt to close the agentic identity gap, and watch for SecureAuth to push harder on enterprise integrations with the major agentic frameworks where token-passing credential risks are most acute.