SailPoint’s 40x Gap — Enterprise AI Agent Adoption Has Outrun Identity Security by a Factor of 40 SailPoint's Horizons 2026-2027 report found that 79% of organizations now run AI agents in production while only 2% have implemented purpose-built identity security for them, a 40x gap between adoption and protection, according to data presented at the SailPoint Navigate 2026 conference in Austin in October. SailPoint CTO Chandra Gnanasambandam said manual review of autonomous agents making 10,000 tool calls a second is "a fantasy," and an AvePoint State of AI 2026 survey cited in the report found 88.4% of organizations suffered at least one AI agent-related security breach in the past 12 months. The report also noted a $435M agent security funding wave between April and September 2026, including rounds for Horizon3, Zenity and Corma, and that 86.9% of companies have delayed AI deployments due to governance readiness. If you look at how fast companies are rolling out AI agents, it is clear that the traditional pace of IT deployment is a thing of the past. At the SailPoint Navigate 2026 https://www.sailpoint.com/horizons conference in Austin this October, the data confirmed just how aggressive this shift has become. According to the SailPoint Horizons 2026-2027 report https://www.sailpoint.com/horizons , 79% of organizations are now running AI agents in production. Yet, only 2% have implemented the purpose-built identity security required to manage them. That is a 40x gap between adoption and protection. As Matt Mills recently noted, Autonomous agents are no longer just experimental copilots; they are becoming the primary execution layer of modern enterprises. This shift is not merely a change in software architecture; it is a fundamental change in how work gets done. However, the infrastructure supporting this layer remains dangerously thin. The Reality of the Gap As SailPoint CTO Chandra Gnanasambandam noted during the event, the scale of the challenge is unprecedented: “The idea that a security admin is going to review and approve access for a group of autonomous agents making 10,000 tool calls a second isn’t just outdated-it’s a fantasy. The only way to govern autonomous machines is with autonomous machine defense.” The AvePoint State of AI 2026 survey https://www.avepoint.com/shifthappens/reports/artificial-intelligence-report-2026 found that 88.4% of organizations experienced at least one AI agent-related security breach in the past 12 months. Despite these numbers, there is a persistent awareness gap. While 80% of leaders underestimate their tooling gap, only 15% can actually provision non-human access in real time. This disconnect is stark when looking at maturity: 54% of organizations are currently at Horizon 1 for agent identity, while less than 1% have reached Horizon 5. For those who do invest, the results are tangible: 62% report measurable productivity gains, and 46% report safer, faster deployment. A Market in Motion The industry is scrambling to catch up. Between April and September 2026, a $435M agent security funding wave hit the market, including major rounds for Horizon3, Zenity, and Corma. It is important to see this capital for what it is: a market response to a glaring vulnerability, not a finished solution. As SailPoint CMO Wendy Wu put it, “Enterprises waiting for their agent programs to mature the way their human programs did are going to find out the hard way that they don’t have five years.” Enterprise Implications For deployers, this means the era of manual oversight is over. Organizations must shift from static, role-based access to dynamic, intent-based governance. This requires integrating identity security directly into the agent’s execution loop. Deployers can no longer treat agents as simple service accounts; they must be managed as autonomous entities with their own risk profiles. Failing to do so leaves the enterprise exposed to automated lateral movement and unauthorized data exfiltration, which is why 86.9% of companies have already been forced to delay AI deployments due to governance readiness. Regulatory and Operational Pressure The risks are moving beyond the IT department. We are seeing a convergence of operational fragility and regulatory exposure. Legislative proposals regarding “rogue AI”-which have been a focal point in recent Senate hearings https://forkast.news/senate-rogue-ai-hearing-ignites-bipartisan-push-for-agent-liability-and-enterprises-should-pay-attention/ -are moving from the periphery to the center of the policy debate. Whether it is implementing oversight mechanisms like those discussed in recent coverage of Classie Supervise https://forkast.news/classie-ships-supervise-the-first-platform-dedicated-to-real-time-enterprise-ai-agent-oversight/ , or adopting protocol-level security standards like ClawSecure MCP https://forkast.news/clawsecure-discloses-critical-mcp-protocol-vulnerabilities-affecting-linear-notion-dropbox-dash/ , the goal is the same: ensuring that the primary execution layer of the modern enterprise doesn’t become its greatest point of failure. What to Watch Funding-to-tools pipeline: Watch for how quickly the $435M in recent funding translates into usable, enterprise-grade security platforms rather than just point solutions. Legislative movement: Keep an eye on the Senate’s push for agent liability; the legal definition of “agent responsibility” will dictate future compliance costs. Cyber insurance: With 76% of organizations expecting governance to affect their insurance terms, expect underwriters to begin mandating specific identity security protocols as a prerequisite for coverage.