Skip to content
Governance

79% run AI agents. Can your clients prove they govern them?

SailPoint's fifth Horizons of Identity Security report (Oct 6, 2026) surveyed 340 senior identity, IT, cybersecurity and risk leaders. 79% run AI agents in production, yet 2% use identity security purpose-built for them. 57% are confident they can meet regulatory requirements, but only 43% feel prepared to produce verifiable evidence in an AI-related audit. For MSPs, that proof is the service: an agent evidence file per client, refreshed quarterly and exported at audit or cyber insurance renewal.

Consultiply resource guide cover titled 79% run AI agents. Can your clients prove they govern them?, with SailPoint Horizons of Identity Security survey callouts on agent adoption, purpose-built security, and confidence versus audit evidence, plus an MSP agent evidence file strip.

Published October 8, 2026 · ~7 min read

What SailPoint found

SailPoint released its fifth annual Horizons of Identity Security report on Oct 6, 2026, at its Navigate conference. Per SailPoint, the survey covers 340 senior identity, IT, cybersecurity and risk leaders worldwide, scored against a five-tier maturity model from Horizon 1 (No formal program) to Horizon 5 (Ecosystem integrated). SailPoint reports that 79% of organizations run AI agents in production, while 2% use identity security tools specifically designed to manage and govern them. SailPoint calls that a 40-to-1 gap. This is vendor research, from a company that sells the fix, and the sample is enterprise leaders, not small businesses.

More findings from SailPoint's release: AI agents now make up 22% of all non-human accounts, and 85% of organizations still rely on legacy identity tools not designed for agentic identities. On human identity, SailPoint says the share of organizations at Horizon 1 fell from 45% in 2022 to 23% today. For agent identity, 54% sit at Horizon 1. Roughly 60% of organizations remain in Horizons 1 and 2, and less than 1% have reached Horizon 5.

Figure 1: Consultiply chart recreated from SailPoint survey results (vendor research, 340 leaders). Source: SailPoint, Horizons of Identity Security 2026-2027.

Confidence is not proof

The finding that matters most for an MSP is the gap between what leaders believe and what they can show. Per SailPoint, 57% express confidence in meeting regulatory requirements, yet only 43% feel prepared to produce verifiable evidence in an AI-related audit. The same pattern repeats: 87% rate their human IAM capabilities as capable or better, while only 43% report mature processes for agentic access. And 80% believe the gap in their current tooling is moderate or smaller, while only 15% can provision non-human access in real time.

SailPoint CMO Wendy Wu put the speed problem this way: "You cannot bridge this gap by asking human-speed tools to work faster; security must be built for machine speed from the ground up, with discovery, ownership, and access decisions happening in real time rather than on a quarterly review cycle." On SailPoint's report page, Jérôme Robin, Director of Corporate Security at Criteo, adds: "The objective is not to slow down AI adoption. It is to make AI adoption safe enough to scale."

Figure 2: Belief vs. demonstrable capability, Consultiply chart recreated from SailPoint survey results (vendor research). Source: SailPoint, Horizons of Identity Security 2026-2027.

Why auditors and insurers make this an MSP line item

SailPoint also links governance to money. Per the release, 62% of organizations that invested in securing non-human identities report measurable productivity gains, 46% report safer, faster AI deployment, and 76% of leaders expect stronger identity governance to improve their eligibility for, or the terms of, cyber insurance. SailPoint says mature organizations are twice as likely to realize significant productivity gains and three times more successful at deploying AI safely. Those are self-reported survey answers, not measured outcomes.

For an MSP, that is the opening. Auditors, cyber insurers, client leadership, and incident leads all ask some version of the same question: which agents exist, who owns them, what can they touch, who approves risky actions, and when was that last checked? A client who feels confident but cannot answer with a dated record is exactly the 57% versus 43% gap. The MSP product is the record itself: an agent evidence file per client, kept current, that can be exported on request.

Channel Insider (Jordan Smith, Oct 7, 2026) reports more from the report: 65% of organizations have made AI agents available to more than a quarter of their workforce, only 4% use separate tools specifically for agent identities, 64% already govern machine and agent identities through centralized identity platforms, and 41% have a non-human identity strategy aligned with their enterprise AI roadmap. Channel Insider also outlines a three-stage roadmap from SailPoint: Discover (catalog service accounts, API tokens, scripts and agents, detect shadow AI, assign owners and business purposes, bring non-human accounts into access reviews and audit assessments), Govern (automate provisioning, privilege changes and decommissioning, enforce credential rotation, align with AI roadmaps), and Protect (just-in-time access, zero standing privilege, context-aware authorization, identity telemetry into security operations for automated containment).

Figure 3: SailPoint's three-stage roadmap as reported by Channel Insider, mapped to MSP deliverables (Consultiply framing). Source: Channel Insider.

Related reading: our Oct 7 guide on Atlassian's agent identity announcement covers building the agent inventory and access review. This guide is about the next step: turning that work into evidence a client can hand over.

What MSPs should do now

01

Build the evidence baseline once.

Register every agent and non-human account per client with its purpose, a named owner, its own identity (not a borrowed login), credentials in reach and when they were last rotated, scope, and which actions need a person to sign off. Record the gaps. This maps to the Discover stage.

02

Refresh it quarterly and sign it.

Diff against last quarter, attach the key and token rotation log, and get a dated, signed access review that includes agents. A record nobody re-checks is not evidence.

03

Package it for audit and renewal.

Export the file for the auditor, the cyber insurance questionnaire, or client leadership. The goal is that the answer to "can you show it?" is a document, not a meeting.

04

Label every number as SailPoint's.

All percentages here are SailPoint survey results, some relayed by Channel Insider. It is vendor research weighted to enterprises. Use it to frame the conversation, not as a benchmark for a 40-seat client.

Figure 4: Illustrative agent evidence record and three-part offer. Consultiply illustration, not client data and not SailPoint material.

Offer moves this month

01

Evidence baseline (one-time project).

Register every agent and non-human account, with owner, scope, and gaps.

02

Quarterly evidence refresh (recurring).

Diff against last quarter, key rotation log, signed review.

03

Audit and renewal pack (on demand).

Export for the auditor or the cyber insurance questionnaire.

04

Run the five-question check at the next QBR.

Ask whether the client could show an auditor today each item in the scorecard below. Every "no" or "partly" is a scoped ticket.

Figure 5: Five-question evidence check for a QBR. Consultiply illustration.

Numbers table

Figures below are SailPoint's survey results (Horizons of Identity Security 2026-2027, 340 leaders), from SailPoint's release unless marked Channel Insider. None were measured by Consultiply.

ClaimWhat was measuredStatus
Run AI agents in production (SailPoint)79% of organizations.Vendor claim
Purpose-built agent identity security (SailPoint)2%; SailPoint calls it a 40-to-1 gap.Vendor claim
AI agents as share of non-human accounts (SailPoint)22%.Vendor claim
Rely on legacy identity tools (SailPoint)85%, tools not designed for agentic identities.Vendor claim
Agent identity at Horizon 1 (SailPoint)54%. Human security at Horizon 1 fell from 45% (2022) to 23%.Vendor claim
Confident on regulatory requirements vs. ready with AI audit evidence (SailPoint)57% vs. 43%.Vendor claim
Human IAM capable or better vs. mature agentic access (SailPoint)87% vs. 43%.Vendor claim
Tooling gap moderate or smaller vs. real-time non-human provisioning (SailPoint)80% vs. 15%.Vendor claim
Cyber insurance expectation (SailPoint)76% expect stronger identity governance to improve eligibility or terms.Vendor claim
Business value of NHI investment (SailPoint)62% report measurable productivity gains; 46% report safer, faster AI deployment.Vendor claim
Agents available to over a quarter of workforce (SailPoint via Channel Insider)65%.Vendor claim
NHI strategy aligned with AI roadmap (SailPoint via Channel Insider)41%.Vendor claim
Callout

This guide is Consultiply's independent analysis of SailPoint's Horizons of Identity Security 2026-2027 findings and related coverage, translated for MSP operators. It is not affiliated with or endorsed by SailPoint. The survey is SailPoint's vendor research of enterprise leaders and does not represent small businesses. The evidence record and offer tiers are Consultiply illustrations.

SailPoint Report Finds 79% of Enterprises Run AI Agents in Production (GlobeNewswire via Yahoo Finance, Oct 6, 2026)

SailPoint Finds AI Agent Adoption Far Outpacing Identity Security (Channel Insider, Jordan Smith, Oct 7, 2026)

Where this came from

Reviewed, not run by us.

This guide is Consultiply's independent analysis of SailPoint's Horizons of Identity Security 2026-2027 findings and related coverage, translated for MSP operators. The survey is vendor research from a company that sells identity security, weighted to enterprises. It is not affiliated with or endorsed by SailPoint. SailPoint press release and Horizons of Identity Security 2026-2027 report page (Oct 6, 2026) →

Want this as a PDF you can share?

Free to download, no form to fill in.

Get the PDF (~551 KB)