Artificial intelligence is rapidly reshaping enterprise operations, enabling organisations to automate workflows, improve productivity, and accelerate decision-making. However, as AI adoption increases, so does the complexity of managing and securing the identities that power these autonomous systems.
A recent IDC white paper, sponsored by Commvault, reveals that many organisations are expanding their use of AI faster than they are strengthening the identity security capabilities needed to support it. The research highlights growing concerns around AI agents, non-human identities, cyber resilience, and recovery planning—areas that are becoming critical as enterprises embrace autonomous technologies.
AI Is Expanding the Identity Attack Surface
One of the study's most significant findings is the growing challenge posed by AI agents and non-human identities.
Unlike traditional user accounts, AI agents can operate continuously, interact across multiple systems, and scale rapidly throughout enterprise environments. As organisations deploy more autonomous applications, the number of machine and AI identities is expected to grow substantially, creating new governance and security challenges.
According to the research:
- 90% of organisations believe they need stronger identity management capabilities to address risks associated with agentic AI.
- Nearly 59% say their existing identity management approach requires significant improvements or a complete overhaul.
- Only 26.7% have implemented dynamic role-based access controls designed to support AI workloads.
Identity Resilience Remains a Weak Spot
While many organisations continue investing in cybersecurity, the study suggests that identity resilience has not kept pace with AI adoption.
Only 24.7% of respondents reported having documented and tested recovery procedures for critical identity services such as Microsoft Entra ID and Active Directory. Since identity platforms serve as the foundation for authentication and access across enterprise environments, any disruption can significantly impact business continuity.
The findings reinforce the need to treat identity infrastructure as a critical business service rather than simply an IT function.
Cyber Resilience Requires Greater Collaboration
The research also highlights organisational challenges beyond technology.
Nearly 98% of respondents believe collaboration between IT and security teams needs improvement, with almost half stating that major improvements are required. In addition, more than half of organisations have yet to define their Minimum Viable Business (MVB)—the essential systems and processes required to continue operating during a cyber incident.
Without clear ownership, coordinated response processes, and tested recovery plans, organisations may struggle to recover effectively from increasingly sophisticated cyberattacks.
The Rise of Resilience Operations (ResOps)
IDC identifies Resilience Operations (ResOps) as an emerging operational discipline designed to strengthen organisational preparedness.
Rather than treating security, recovery, infrastructure, and business continuity as separate functions, ResOps brings these teams together to improve cyber readiness, accelerate recovery, and reduce operational disruption during incidents.
IDC predicts that ResOps will evolve into a mainstream enterprise capability over the next three to five years as organisations place greater emphasis on resilience alongside prevention.
Why Identity Security Matters in the AI Era
As AI adoption accelerates, identity is becoming the foundation of enterprise resilience.
Every AI agent, service account, API, and machine identity requires appropriate governance, authentication, authorisation, and lifecycle management. Without these controls, organisations face increased risks from excessive permissions, compromised identities, and unauthorised access.
Modern identity security strategies should include:
- Discovery and governance of AI and non-human identities
- Dynamic access controls based on risk and context
- Continuous monitoring of identity activity
- Identity recovery planning
- Zero Trust access models
- Regular testing of identity resilience capabilities
These controls not only reduce cyber risk but also enable organisations to adopt AI with greater confidence.
Trevonix Perspective
At Trevonix, we believe the IDC findings reinforce one of the most important trends shaping enterprise cybersecurity: AI adoption and identity security must evolve together.
As AI agents become embedded within enterprise operations, organisations can no longer focus solely on protecting workforce identities. Machine identities, service accounts, APIs, and autonomous AI agents are rapidly expanding the identity landscape and require the same level of governance, visibility, and lifecycle management.
Identity resilience should be viewed as a strategic business capability rather than a reactive security control. By combining identity governance, Zero Trust principles, privileged access management, continuous monitoring, and recovery planning, organisations can strengthen cyber resilience while enabling secure AI innovation.
The enterprises that invest in resilient identity foundations today will be better positioned to manage the operational and security challenges of tomorrow's AI-driven environments.
Key Takeaways
- IDC found that 90% of organisations need stronger identity management to support AI adoption.
- AI agents and non-human identities are creating new governance and security challenges.
- Less than one-third of organisations have implemented AI-ready dynamic access controls.
- Identity resilience and recovery planning remain significant gaps across many enterprises.
- Building resilient identity security will be critical for secure and scalable AI adoption.
Reference
ET CISO – IDC Study Highlights Identity Resilience Gaps as AI Adoption Accelerates


