
The 2025 Gartner Identity & Access Management Summit focused on a few big ideas: AI in and around IAM, the rise of machine identities, better use of identity data, and emerging deepfake and ITDR concerns, and the push toward passwordless authentication and zero standing privilege. It’s clear that the IAM community now treats identity as the control plane for both cloud and AI, providing advanced governance capabilities on top of the core “IAM plumbing” to provision accounts.
AI appeared across three related themes: using AI to improve IAM, governing identities for AI agents, and defending against AI-driven attacks. Veza, for example, announced “AI Agent Security,” describing it as a way to extend identity security posture management (ISPM) and access governance to agentic AI, combining identity, configuration, and access intelligence in a unified platform. Sessions highlighted agentic AI innovations and AI security posture management as key topics, alongside IAM mainstays like PAM and IGA, signaling that identity teams are now expected to own guardrails for AI agents as well as human users.
Sessions discussed the pros and cons of current AI capabilities, and some of the best use cases for AI include using it as an analytical engine for IAM itself: using AI-driven analytics to detect abnormal sessions, classify risky behavior, and power AI-native authorization and real-time threat detection. This aligns with the identity-first security narrative, where AI augments IAM teams rather than replacing core governance practices.
A second strong thread is the shift from users to workloads and non-human identities, where the current thinking is that the legacy service-account model (long-lived, highly privileged static credentials) is no longer viable at scale, especially in cloud-native environments. Aembit notes that “dynamic service identities + just-in-time (JIT) access + zero-standing privilege drastically reduce the chance of credential misuse,” capturing the new baseline many vendors are aiming for. The emphasis is on tying identity to the workload itself so that credentials are ephemeral, policy-driven, and evaluated at the point of access against real-time posture. This machine-first framing focuses on the identities of services, APIs, and automations rather than only human users, where Aembit is able to:
Identity Hygiene was another prevalent theme, highlighting that better outcomes depend on clean, well-governed identity data, not just on new tools. Governance functions, such as access reviews and entitlement management, help keep identity data accurate and decision-ready across OnPrem and Cloud. The implicit message from Gartner and conference speakers is that AI, ITDR, and machine IAM will only be as effective as the identity data feeding them. Organizations would do well to invest in data quality and unified context before chasing advanced automation, as low data quality leads to incorrect results and, without context, can execute the wrong path/enforce the wrong rules, leading to suboptimal results.
Sphere promotes Identity Hygiene to address both these issues, “ensuring identities and access are only permitted where they should be”. Idenhaus agrees that identity hygiene is the missing security layer for Zero Trust success. There is a simple (but demanding) takeaway: before chasing more controls, get your identity house in order—discover everything, assign accountable owners, clean up over-privileged access, and keep it that way with automation.
Deepfake detection and identity-layer threats are key concerns, where synthetic voice and video are being used to compromise hiring, payments, and remote workflows. As a point of reference, this month’s GetReal Security Deepfake Readiness Benchmark Report notes that enterprises are facing a growing volume of AI-powered deepfakes and identity manipulations in everyday business, with CEO Matt Moynahan warning that such attacks have “crossed the chasm and are becoming mainstream.”
In response, security platforms are emphasizing identity threat detection and response (ITDR) features such as real-time session monitoring, behavioral analytics, and automated defense actions as critical capabilities. The ultimate goal is real-time threat detection and termination of high-risk sessions. IAM is on the front lines against AI-powered social engineering and deepfake abuse and is no longer just a back-end directory service.
New passwordless innovations move beyond shared secrets, aligning with the push for phishing-resistant methods that are more tightly bound to users and their devices. Zero Standing Privileges means removing always-on administrative rights and replacing them with tightly scoped, time-bound elevations tied to specific commands or applications. Zero Standing Privilege, continuous privilege governance, and passkeys were identified as top priorities, and were key themes in this year’s Gartner IAM Conference. It was noted that cyber insurers are beginning to expect just-in-time privileged access as a condition of coverage, further elevating ZSP from good practice to a de facto requirement.
The 2025 Gartner IAM Summit is about convergence, where AI agents, machine identities, and deepfakes are forcing organizations to rethink identity as a dynamic, data-driven control plane that must span humans, workloads, and AI itself. At the same time, traditional challenges such as poor identity data quality, overprivileged accounts, and fragmented governance persist. These challenges are being addressed through frameworks such as Zero Standing Privilege, identity security posture management, and AI-enhanced ITDR. Establishing identity data as strategic infrastructure, extending IAM to machine and AI identities, modernizing authentication with passwordless and phishing-resistant methods, and adopting ZSP are becoming table stakes rather than stretch goals. That combination, more than any single tool or trend, appears to define the 2025 Gartner IAM playbook.