Digital Identity Moves to the CxO Agenda: What’s New in the Gartner® Hype Cycle™ for Digital Identity, 2026

Summertime typically means the days are longer and brighter, but it also the release of a new hype cycle from Gartner on Digital Identity innovation. The latest edition released in July 2026 delivers a clear message: identity is no longer a practitioner level concern and most identity programs are struggling to keep a pace.
We’re proud to share that Radiant Logic is named a Sample Vendor in three categories in this year’s report: Identity Visibility and Intelligence Platforms, AI for Access Administration, and SCIM. In fact, the same recognition was made last year. More on that below, but first, let’s look at what changed.
From the IAM Team to the Boardroom
The most telling change in this year’s edition is not on the curve itself, it’s the framing. Last year, identity stood out as a cornerstone of cybersecurity with a flirt to practitioners. This year Gartner publishes the report under its CxO Leadership initiative alongside guidance for building a resilient and agile cybersecurity program. This is in line with new regulatory frameworks worldwide with a focus on resilience.
That repositioning matters.
When an analyst firm moves identity research from a practitioner track to an executive track, it reflects the field observation that identity has become the control plane for enterprise security, and decisions about identity architecture are now business decisions and most importantly spotlighted funding from the top.
With the new audience comes a new thesis. Where the 2025 edition positioned identity as a cornerstone, the 2026 edition opens by stating that the digital identity landscape is being transformed by three forces: AI agents, identity visibility, and identity threats.
Three Forces Reshaping Digital Identity
- AI agents. Gartner cites its 2025 Machine Identity survey, in which 94% of organizations reported dealing with increased machine identities, largely driven by AI and AI agent deployments. Agents that act on behalf of humans — or entirely autonomously — break assumptions that human-centric IAM was built on.
- Identity visibility. Gartner notes that visibility and proactive defense of identity infrastructure are behind the growing traction of open standards, the rising interest in identity visibility and intelligence platforms (IVIP), and the emergence of identity security posture management as a discipline. You cannot secure, govern, or automate what you cannot see.
- Identity threats. Attackers continue to target identity infrastructure itself — credentials, configurations, and IAM controls — keeping technologies for threat detection, posture management, and enhanced authentication moving steadily through the cycle.
Six New Entrants — and Almost All of Them Are About AI
The 2026 Hype Cycle features six new innovation profiles, and the pattern is unmistakable:
- Workload access management — runtime, least-privilege access enforcement for services, containers, and AI agents, are replacing static credentials with dynamic, context-aware controls.
- Intent-based access control — an authorization framework for agentic AI evaluates an agent’s intended actions against the captured intent of the user, instead of broad standing permissions.
- CIAM for AI agents — customer identity access management for a world where customers send their own AI agents to interact with your business.
- AI agent identity — giving AI agents a unique, governable digital representation within the organization.
- Authorization management platforms — shared services for authoring, orchestrating, and enforcing authorization policy across infrastructure, APIs, applications, and data.
- Identity security posture management (ISPM) — the discipline of continuously assessing and managing IAM policies and configurations, which Gartner describes as complementary to IVIP and identity threat detection and response (ITDR).
Five of the six speak directly to the machine and AI agent identity explosion. The sixth, ISPM, speaks to visibility and posture. In other words, the new arrivals map almost perfectly onto Gartner’s three transforming forces.
What Fell Off the Cycle?
Just as interesting is what’s gone. Device-bound passkeys, passive behavioral biometrics, and third-party biometrics were removed because they are now fully mature. OpenID Connect has graduated as a mainstream standard. Machine IAM was decomposed into its constituent elements (workload identity management, workload access management, and IoT authentication) and RISC and CAEP are now tracked under the Shared Signals Framework. We are looking at a specializing in the market.
Movements Worth Watching
- Verifiable credentials are the standout: rated transformational, on the Slope of Enlightenment, with mainstream adoption expected in less than two years — the nearest-term transformational technology on the entire cycle.
- SPIFFE and AI for Access Administration sit at the Peak of Inflated Expectations, reflecting intense market interest in workload identity standards and AI-assisted governance.
- Identity visibility and intelligence platforms continue climbing toward the peak, rated as high benefit as they promise the “single pane of glass” that years of IGA, access management, and PAM investment have not delivered on their own.
Radiant Logic recognized as Sample Vendor in Three Categories
Radiant Logic is named a Sample Vendor in three innovation profiles in the 2026 report — and we believe the thread connecting them is exactly the thread connecting Gartner’s three transforming forces: identity data.
- Identity Visibility and Intelligence Platforms. Gartner describes IVIPs as delivering a single view of IAM data, activity, relationships, configuration, and posture — with analytics that improve every other integrated IAM control. Gartner’s visibility, intelligence, action (VIA) model makes the dependency explicit: the quality of every action depends on the quality of intelligence, which depends on the degree of visibility. That is precisely what RadiantOne was built for — unifying fragmented identity data across hybrid environments into one authoritative, graph-based view.
- AI for Access Administration. Gartner offers a caution we’ve echoed for years: machine intelligence is no better than human intelligence at dealing with data that doesn’t exist. AI’s value in access governance is capped by the quality of the identity, entitlement, and access data feeding it. RadiantOne provides that data foundation, and AIDA, our AI data assistant, applies it — surfacing risky access and turning certification campaigns from checkbox exercises into informed decisions.
- SCIM. Now in early mainstream adoption, SCIM keeps proving that open standards win. As both a SCIM client and server, RadiantOne uses the standard to synchronize and provision identity data across decentralized environments, no custom connectors required.
Visibility feeds intelligence; intelligence powers AI; standards move the data. Three categories, one platform story.
What Identity Leaders Should Do Now
The most practical message from the 2026 Hype Cycle: the AI agent wave is arriving on top of identity programs that, in most organizations, still lack full visibility into the identities and access they already have. Before you can govern an explosion of agent identities or trust AI to administer access, you need a unified, high-quality identity data foundation. That’s the capability Gartner’s new report elevates, and it’s the one we’d encourage every CISO to assess first.
Want to see where your identity data stands today? Get in touch with us for a demo of RadiantOne, or explore how AIDA brings AI to access governance all grounded in data you can trust.
Source and Disclaimer
Gartner (2026) Hype Cycle for Digital Identity, 2026. Zachary Smith and Nayara Sangiorgio, 6 July.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.
Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

