# Enterprise AI Agents Create a New Identity Crisis: How Budget Dynamics Are Reshaping Security Spending
As artificial intelligence agents proliferate across enterprises, they're spawning an unexpected problem: a fundamental shift in how organizations budget for identity and access management (IAM). New research from Omdia reveals that nearly half of IT leaders are pulling AI agent identity projects out of traditional IT and security budgets, creating standalone funding streams that threaten to fragment identity governance just as the attack surface explodes.
The finding underscores a deeper challenge facing enterprise security teams: AI agents are not human users, and the identity infrastructure built for people doesn't automatically scale to autonomous systems operating at machine speed, accessing sensitive data, APIs, and workflows across hybrid cloud environments. As these agent populations grow toward production-grade autonomy, organizations face a critical juncture—either invest in unified IAM discipline for this new identity class, or risk creating shadow governance structures that no one is coordinating.
## The Threat: A New Attack Surface, Poorly Managed
Traditional identity and access management systems were designed around a simple model: people log in, people are granted permissions, people's access is periodically reviewed and revoked. AI agents upend this paradigm entirely.
Unlike human users, AI agents:
The Omdia research, which surveyed 350 IT leaders in the first half of 2025, makes clear that identity teams recognize this risk. The study found that identity leaders across the US and Canada are actively working to evolve existing IAM tooling to manage, govern, and secure AI agent identities alongside human and service account identities. But the funding model driving these projects reveals a deeper organizational fragmentation.
## Background and Context: How AI Agents Became an Identity Problem
The rise of AI agents in enterprise environments happened faster than most security programs anticipated. What started as experimentation with large language models and chatbots has accelerated into production deployments of autonomous agents that:
Each of these use cases requires the agent to authenticate to backend systems—and to hold permissions (often sensitive ones) to perform its function. Unlike a human user, whose access can be revoked in real time by resetting a password or disabling an account, revoking agent permissions often requires code changes, redeployment, or API token rotation that may span multiple systems.
The identity governance problem is compounded by organizational silos. In many enterprises, AI initiatives are owned by the business, a specific business unit, or a dedicated AI center of excellence—not the IT or security teams that traditionally manage identity. This creates a structural incentive to bypass traditional IAM processes and instead set up independent, parallel identity and permission systems for agents.
## Technical Details: What AI Agent Identity Actually Requires
Securing AI agent identities demands several technical and governance capabilities that traditional IAM systems often lack or require significant enhancement to provide:
Authentication & Credential Management
Fine-Grained Authorization
Governance & Lifecycle Management
Audit & Threat Detection
## The Budget Shift: A New Standalone AI Identity Bucket
Here's where Omdia's research reveals the most significant risk: traditional IAM projects—whether identity governance and security (IGA), access management (SSO, MFA), or privileged access management (PAM)—have historically been funded from either IT budgets (owned by the CIO) or security budgets (owned by the CISO). These are mature decision-making processes with established governance and vendor relationships.
AI agent identity projects are different. The Omdia survey found that 45% of IT leaders reported using a completely new standalone budget for AI agent projects, separate from traditional IAM and security spending. This is not a marginal shift—it reflects a fundamental organizational change in how AI initiatives are funded and governed.
The implications are troubling:
| Budget Source | Percentage | Risk |
|---|---|---|
| Standalone AI budget | 45% | Siloed from IAM teams, harder to coordinate governance |
| Existing IT/Security budget | 35% | Unclear which projects take priority |
| Unclear/mixed funding | 20% | Identity governance becomes fragmented |
This fragmentation means that identity teams—whose job is to manage and govern all identities in the enterprise—are now operating without visibility or control over nearly half of new identity deployments.
## Implications: A Sprawling, Ungoverned Identity Landscape
The practical consequence of this budget split is organizational fragmentation around identity security. AI initiatives funded from separate budgets are more likely to:
Over time, this creates a shadow identity infrastructure that no single team owns or can audit comprehensively. If a data breach or compliance incident occurs, the organization may not have visibility into what access an AI agent had, what it did, or whether that access was appropriate.
The risk is amplified by the rate of AI adoption. As more agents move into production—and as those agents gain access to more sensitive data and critical workflows—the identity governance gap becomes a material security and compliance risk.
## Recommendations: Reclaiming Identity Governance for AI
Organizations deploying AI agents at scale should:
1. Establish unified identity governance for AI agents: Require all AI initiatives—regardless of funding source—to register agent identities in a centralized IAM system. This system must be owned by the identity or security team, not by each business unit independently.
2. Enforce least-privilege access: Agents should only have access to the specific APIs, databases, and workflows they need. Use fine-grained authorization controls (ABAC, policy-based access) rather than broad role-based permissions.
3. Implement continuous credential rotation: Adopt tooling that automatically rotates agent credentials on a regular schedule (e.g., every 30 days) and detects/alerts on unusual credential usage patterns.
4. Require formal lifecycle management: Every agent should go through formal provisioning (registration, access approval) and deprovisioning (access revocation, credential cleanup) processes—just like human users.
5. Audit everything: Every action an agent takes must be logged. Logs should be searchable and integrated with your SIEM or security analytics platform.
6. Align budgets around shared governance: If AI and traditional IAM projects are funded from different buckets, establish shared KPIs and governance that force coordination between teams.
---
## HackWire Analysis
The real story here isn't about technology—it's about organizational structure. Enterprises are funding AI initiatives separately from security and IT precisely because AI has become a board-level strategic priority that bypasses traditional IT governance. Finance sees AI as a competitive imperative and funds it as a distinct business investment, not as an incremental IT capability.
This creates a predictable pattern: Each organization believes their AI agents are different, so they need different identity tooling. Within 18-24 months, they realize they've built multiple incompatible identity systems that nobody can govern at scale. Then they face a painful reconciliation—either rip-and-replace dozens of bespoke deployments, or accept that significant portions of their attack surface are operating in shadow.
The broader implication is that identity governance is about to become a major source of compliance failures and breach vectors. When organizations cannot answer "what access does this AI agent have?" or "what did that agent do on March 15th?", regulators and breach investigators will not accept "we funded it separately" as an excuse. Expect major incidents in the next 18-24 months tied to ungoverned AI agent identities, which will likely trigger new regulatory requirements around AI governance and identity management.
For security teams, the actionable insight is urgent: You need to establish AI agent identity governance NOW, before your organization has deployed dozens of agents across dozens of systems. Once the agents are in place, identity governance becomes an archaeological dig to figure out what's been granted and to whom. Do it upfront, and you prevent the mess. Wait six months, and you're managing a legacy problem.
— HackWire Editorial
---
## Related Coverage