Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By leaders from 1Password
By 2026, organizations will increasingly rely on agentic AI systems that act on behalf of employees. This shift will accelerate productivity, and it will also reveal gaps in today’s identity security tools.
As AI agents gain access to sensitive data and business systems, security and IT teams will face essential questions: Who authorized an action, which agent performed it, and was the access appropriate – or even intended? Traditional IAM, PAM, and SSO tools weren’t built to answer these questions, and that gap will reshape how organizations secure identity, credentials, and access in the years ahead.
Here’s how 1Password executives believe identity security will evolve as agentic AI becomes widespread.
AI Agents Will Redefine How We Govern Access
As agentic AI reshapes identity, it will directly influence how access is granted, monitored, and understood. Jacob DePriest, 1Password’s CISO/CIO, highlights how significantly this will change security operations.
“As humans grant AI agents increased access to data and systems, both in personal and corporate settings, security teams will need to track this activity across identity, endpoint, and data protection surfaces. They will need to handle agents operating with employee permissions, differentiate their actions from humans, and control the credentials granted to them. Those who gain visibility and control of agent access will set the standard for trusted AI ecosystems.”
This shift highlights a challenge: today’s identity structures weren’t built for entities that behave as both users and software.
AI Agents Will Break Identity Silos and Force a Security Revolution
Identity systems are often grouped by who, or what, they’re meant to protect: people at work, the apps they use, and the machines behind the scenes. Anand Srinivas, VP of Product and AI at 1Password, explains why this fragmented nature calls for a new architectural model.
“Up until now, identity, secrets and access management solutions have been siloed across different organizations responsible for application or workforce identity security. That worked when applications were deterministic, well-bounded entities all operating within centralized policy frameworks. However, agentic AI behaves as both traditional software and as a user that operates outside existing identity systems, thereby introducing new identity threat vectors. Securing this new paradigm will require breaking down the identity silos and creating a unified, policy-driven identity fabric that governs access deterministically, not probabilistically.”
As identity becomes unified, a related truth emerges: capability is no longer defined by model intelligence, but by what the model is allowed to access.
The Credential Will Be the New Compute
In the next era of AI, access becomes the true limiter of capability. Intelligence alone won’t determine what agents can do, but their access will.
Nancy Wang, SVP, Head of Engineering and AI at 1Password, underscores this point: “In the next phase, the constraint isn’t model capacity; it’s access. The most capable agents will be the ones that can act on behalf of users and systems, not just predict text. Every meaningful AI capability, from automation to decision-making, depends on credentials: API keys, OAuth tokens, service accounts.”
She continues, “That’s why the companies that master secure credential brokering: verifying who an agent is, what it can access, and how it uses that access, will define the next generation of AI infrastructure. The future of AI scale won’t be measured in FLOPs; it’ll be measured in permissions.”
As agents operate with increasing autonomy, the SaaS applications powering most business functions will become the next area undergoing rapid transformation.
AI Will Reshape SaaS Governance
As agents embed themselves into SaaS tools, and take action on behalf of users, visibility becomes increasingly complex. Traditional SaaS management tools weren’t designed to distinguish between human and autonomous activity – a gap that becomes more significant as AI use grows. Jason Meller, VP of Product at 1Password, warns that this will push SaaS governance to the forefront.
“This shift will push shadow SaaS from a mid-level concern into a top security and governance priority. Without visibility into AI-driven SaaS usage, organizations’ shadow IT challenge will be unlike ever before. The organizations that succeed in this next era of SaaS management will be those that extend governance and access visibility beyond humans to the machines now operating inside their SaaS environments.”
As AI agents embed themselves deeper into these tools, the protocols connecting them become the next critical point of security risk.
The Next AI Crisis Will Be Accountability
Even as organizations strengthen identity models, secure protocols, and governance, one question will define enterprise trust: Can they prove that every AI-driven action reflects human intent?
Abe Ankumah, Chief Product Officer at 1Password, believes accountability will become the central concern of enterprise trust. “While the discovery of AI agents will remain important, the greater challenge will be establishing trust. Each AI agent will need to be linked to a responsible human with clear delegated authority, creating a clear line of accountability for every autonomous action. This will become a defining business requirement and a new measure of enterprise trustworthiness.”
AI Will Force a Reinvention of Security Partner Models
As identity, access and accountability grow more complex in the agentic AI era, organizations won’t be able to manage these changes on their own. This shift will fundamentally change the role of security partners. Larissa Crandall, Global VP of Channel & Alliances at 1Password, explains:
“AI’s influence on the channel will accelerate in 2026, prompting partners to rethink how they operate, deliver services, and differentiate in a crowded market. Traditional resale motions will give way to advisory-led, automation-driven service models that create ongoing value and efficiency for customers. Partners that embrace AI, rather than fear or resist it, will unlock new revenue, outpacing competitors and becoming trusted, strategic partners for customers navigating rapidly evolving security demands.”
In an agentic AI world, identity security becomes continuous, access becomes dynamic, and trust becomes a business metric. As a result, organizations will increasingly depend on partners to guide this transformation end-to-end-not just implement tools, but help define policy, govern AI-driven access, and ensure accountability at scale. The enterprises that evolve alongside AI will be the ones that help customers turn autonomy into advantage.
##





