IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
GuidePoint adds AI identity services as gaps widen

GuidePoint adds AI identity services as gaps widen

Mon, 21st Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

GuidePoint Security has added three identity and access management services focused on agentic AI, identity verification, and non-human identity. The expansion comes as organisations report gaps in oversight of AI agents and other machine identities.

The services target areas where security teams are struggling to apply identity controls beyond human users. They cover the identity lifecycle from onboarding and authentication to privileged access and machine identity governance.

An IDC study sponsored by GuidePoint Security found a wide gap between confidence and practice in identity oversight. While 77.3% of organisations reported high or very high confidence in their visibility across human and non-human identities, only 18.5% said they run continuous identity discovery.

Coverage was weaker for newer forms of non-human identity. Only 41.5% of organisations include bots and AI agents in their identity management programmes, the study found.

Three services

The Agentic AI service is designed to help organisations discover and inventory AI agent identities, define trust boundaries, and set governance across their lifecycle. The Identity Verification offering focuses on fraud risks in onboarding, authentication, and account recovery, using maturity and gap analysis against frameworks including CMMI and NIST SP 800-63.

The Non-Human Identity service is intended to improve oversight of machine identities by identifying them, assessing ownership, and reviewing privileges and credential security. Together, the three additions broaden GuidePoint's existing work in identity governance and administration, access management, privileged access management, customer identity and access management, and Microsoft identity tools including Active Directory and Entra.

The move reflects a wider concern in cybersecurity that automation and AI are extending access rights to software entities that can act with limited human intervention. This raises questions about how organisations verify those identities, restrict their permissions, and track changes over time.

GuidePoint has already deployed the services for customers in sectors including retail, airlines, and manufacturing. These engagements have used independent assessments to identify gaps, rank risks, and shape identity programmes around changing threat patterns.

Kevin Converse, Vice President of Identity and Access Management at GuidePoint Security, linked the launch to what he described as a mismatch between perception and readiness.

"The gap between perceived visibility and actual readiness is exactly where risk lives. Organisations often assume their identity and access management programs are stronger than they actually are, and that gap tends to surface at the worst possible time," said Kevin Converse, Vice President of Identity and Access Management at GuidePoint Security.

He said the aim is to give identity and security teams evidence to support spending and remediation decisions.

"Our comprehensive IAM services give security and identity leaders the evidence to prioritize investment and close gaps before they become findings, without adding friction for legitimate users," Converse said.

Identity pressure

Identity and access management has become a larger part of cybersecurity budgets as companies deal with cloud systems, remote work, contractor access, and automated workloads. The spread of AI agents adds another layer because these systems may interact with internal tools, applications, and data stores in ways that resemble a user account, but at a different scale and speed.

Many organisations have built identity programmes around employees, customers, and privileged administrators. Machine accounts, service accounts, bots, and AI agents have often been added piecemeal, leaving ownership unclear and lifecycle controls weak.

That can create several operational problems. Security teams may not know how many non-human identities exist, what privileges they hold, whether their credentials are rotated, or whether they remain active after the underlying service changes or is retired.

Against that backdrop, suppliers and advisers are trying to frame identity governance as a broader discipline that covers every entity seeking access to systems and data. GuidePoint said its engagements can also include technology evaluations to help organisations compare identity products against their existing architecture and risk profile.

Its IAM practice now spans workforce, customer, privileged, machine, and AI identities, reflecting what it sees as a shift in how access risks are emerging across organisations.