Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Lou Fiorello, VP & GM, Security Products, ServiceNow
AI agents are now embedded across enterprise environments, acting with growing autonomy on behalf of customers, employees, and critical business services. They hold credentials, initiate workflows, make decisions, and influence outcomes at scale. Yet many organizations still treat these systems as extensions of automation, rather than as identities with privileges, behavioral patterns, and lifecycle considerations.
As a result, enterprises are entering 2026 with structural gaps that must be addressed before AI can scale safely, responsibly, and at scale. Security architectures designed around human users and static automation are no longer sufficient for a world where AI operates continuously, adapts in real-time, and interacts across ecosystems.
The year ahead will force organizations to rethink identity, visibility, and governance from the ground up. The following predictions outline what will matter most as AI becomes a core engine of enterprise work.
AI Identity Becomes a Baseline Requirement
Enterprises are rapidly deploying AI agents that can authenticate into systems, retrieve data, trigger workflows, and complete tasks previously assigned to humans. Yet the identity discipline for these agents has not kept pace. Many are often created without consistent roles, monitored sporadically, and rarely offboarded when no longer needed. This introduces avoidable, and already observable, vulnerabilities in production systems.
In 2026, enterprises will pivot to identity models that unify humans, machines, and AI agents under one governance framework. This shift requires:
- Breaking down silos across security, IT, and data teams
- Standardizing provisioning and deprovisioning workflows
- Embedding lifecycle and policy governance directly into the platform
This unified identity fabric becomes essential – not only to protect the enterprise, but to unlock the full operational impact of AI.
Oversight of Autonomous Agents Moves to Real Time
AI agents are no longer executing fixed scripts. They are learning, adapting, and making decisions that carry real business consequences. The question is no longer whether can agents act independently. It is whether enterprises can see what they are doing, understand why, and ensure alignment with policies and risk thresholds.
Oversight must shift from reactive monitoring into real-time, identity-aware governance orchestrated through an AI control tower that spans every agent in production. Traditional tooling cannot contextualize AI-driven decisions or detect deviations from expected behavior.
In 2026, organizations must adopt oversight that is continuous, contextual, platform-orchestrated, and scalable to thousands of agents. Without this, enterprises will automate faster than they can understand or control – introducing risk that’s AI’s pace, not the business’s.
AI Introduces a New Form of Third-Party Exposure
As AI agents begin interacting directly with external systems, the nature of third-party risk fundamentally changes. What matters is no longer just access; it is the influence, autonomy, and decision-making power agents exercise on the organization’s behalf. Cross-enterprise, agent-to-agent interactions accelerate collaboration, but also create new pathways for data exposure, increased opacity in delegated decisions, and governance blind spots across shared work. These interactions create a visibility challenge that extends beyond traditional vendor management approaches.
In 2026, enterprises will demand transparency into both internal and external agent behavior, enforcing consistent policy and control access across organizational boundaries. A new operating model emerges-one that governs AI-driven workflows with the same rigor applied to any critical enterprise system, rather than treating them as passive integrations.
Platform-Level Trust and Governance Become Prerequisites for Scaling AI
Trust in AI is not built through documentation or policy statements. It is earned through demonstrable control and transparency embedded directly into the platform. Enterprises will need to show how models are governed, how decisions are generated, and how risk is contained at every stage of the AI lifecycle.
In 2026, governance will become an enabler rather than an obstacle. Organizations recognize that they cannot scale AI responsibly-or quickly-without clear visibility into actions and auditability for outcomes. Governance must be treated as part of the core architecture, not a layer added after deployment. This means building guardrails into the platform, designing systems that explain their reasoning, and ensuring accountability across every agent and workflow. These capabilities form the basis of enterprise trust and become essential to accelerating AI adoption.
2026 is the Year to Build an AI-First Operating Model
Next year, the pace of AI innovation will accelerate, not stabilize. Waiting is the wrong strategy. Leading organizations are already working backward from an AI-first future. They are implementing control frameworks that begin with a comprehensive inventory, extend into identity governance, and cover compliance and lifecycle management for every agent. They are designing flexible systems that anticipate rapid changes in behavior, embedding risk thinking into product development, and integrating guardrails into the platform itself rather than constructing controls around it.
This preparation ensures that as AI becomes more capable and pervasive, enterprises can move quickly while protecting their customers, assets, and operations.





