Radiant Logic Predictions: Right Direction for the Journey but Wrong About the Weather

Midyear review of predictions made back in January, 2026.
After reviewing how our various blog posts were actually performing, the predictions made back in January 2026 stood out as the highest-performing post. A fact that warrants a mid-year review of how the predictions measured up.
The core thesis presented in the blog post was that identity becomes the primary control plane, non-human identity explodes, accountability gaps widen, and manual governance breaks. Now, I was right about the direction of travel but wrong about the weather. Let me explain what I mean by that.
Three things stand out to me as I reflect on what I did not see coming.
Regulation went backwards, not forwards.
I predicted a tightening spotlight, but what happened in the first portion of the year was the largest coordinated deregulatory retrenchment of the early AI/cyber compliance era. The EU AI Act high-risk deadline was pushed to December 2027, CMMC Phase II was suspended, Colorado’s AI Act was repealed and replaced with a lighter-touch law, the HIPAA Security Rule update was delayed to 2027, the EU AI Liability Directive was withdrawn, a US executive order actively litigated against state AI laws, and CISA 2015 survived on 8-month extensions. In my book, the accountability pressure did increase as expected, but it was driven by actual incidents and insurers, not regulators.
The identity data layer got bought, not built.
I argued that NHIs would “come into scope,” and they absolutely did. We witnessed market consolidation at a speed that no one managed to predict. Six major identity/NHI acquisitions closed or were announced between December 2025 and July 2026. The window for NHI point solutions closed within six months.
Agents became attackers before anyone managed to govern them.
The first documented, fully agentic-executed intrusion (Hugging Face, July 2026), agent-run nation-state campaigns against both Thai and Taiwanese infrastructure, and an AI model that managed to escape its test sandbox into a production platform all emerged within this period. My statement that “they are powerful defenders and dangerous attackers” was perhaps my single most under-hedged correct call.
While researching, I was catching up on posts on LinkedIn, and there two trends emerged that I believe require some scrutiny.
AI spending has halted security investment, and security is becoming infrastructure. In the first half of the year, security spending grew, but headcount and discretionary spending did not. AI spending is being funded through reallocation rather than new money. As Microsoft gracefully made us aware as of July 1, identity is being absorbed into infrastructure with its new bundling. Security is moving from a discrete budget line into the infrastructure line.
Finally there is one call I should revisit which is more on me than the market.
In my January blog post I wrote that Identity Security Posture Management (ISPM), or as Gartner had coined it, the Identity Visibility and Intelligence Platform (IVIP), together with identity observability would become foundational rather than add-on capabilities.
That statement warrants a correction. ISPM and IVIP are separate categories, which I concatenated into one single category. Gartner places both at the Innovation Trigger which is the earliest stage of their curve. The more mature category is actually Identity Threat Detection and Response (ITDR), which has passed 50% market penetration and is approaching the Slope of Enlightenment.
But what happened around that prediction is perhaps more interesting than being early on maturity.
When I wrote the original post, ISPM and IVIP were the vocabulary available. By July, Gartner had added AI Agent Identity, Workload Identity Management, Workload Access Management and Intent-Based Access Control to the same Hype Cycle.
The analyst taxonomy itself was expanded to make room for non-human and agent identities. This is what Radiant Logic describes at the Three Identity Problem. That is a stronger validation of the underlying thesis and problem description than any vendor statistic I could have cited.
So, wrong on maturity and perhaps sloppy on the terminology, but I will take the direction of travel. A category sitting at Innovation Trigger is, after all, this is where definitions are still being written and customers are figuring out where the value is for them.
So what can we say about the second half of 2026?
Four dates are already locked in and worth being aware of.
11 September, EU Cyber Resilience Act reporting starts and follows the same pattern as for NIS2. 24-hour early warning to competent authority, 72-hour detailed report. This is a machine-identity and software-supply-chain story in a compliance suit.
30 September, CISA 2015 expiries again and is all about information sharing.
2 December, the AI Act grace period closes, which we have seen being tackled recently by Anthropic et al implementing watermarking in their generated content to allow for generated content to be more apparent and finally closer to the end of the year, how EU member states owe a Digital Wallet to their citizen. Readiness in typical EU fashion is uneven at best but with a great spirit of regulate matters to infinity.
A fifth date (Sept. 7th) that needs to be mentioned is when Microsoft deprecates their legacy self-service password reset capability. This should drive Passwordless in the second half as vendors gives a serious push in the light of Microsoft’s deprecation.
The final prediction offered is how cancelled agentic ai projects will not clean up after itself. If we are to believe the analysts, inference cost per agentic workflow will rise more than five times through 2028 and that we will likely see a large cancellation of agentic projects. This is possibly a healthy correction in spending and should shelve a lot of opportunistic and difficult to account value for type of projects.
Ultimately the challenge here will be as always, the deprovisioning activities of orphaned access, services accounts, API-keys and OAuth grants. The retrenchment will make identity problem more apparent, not less. If I were to guess what the CISOs are thinking is that we are looking at a healthy risk reduction.

