Vikram Pande, Deputy General Manager at HCLTech.
Most enterprises did not design their identity architectures for a world in which software could act on behalf of people, yet that world is arriving quickly. AI copilots, intelligent agents, service identities, APIs and automated workflows can retrieve information, initiate transactions and interact with enterprise systems.
For technology leaders, this creates a strategic challenge. The next phase of zero trust cannot focus only on proving that an identity is legitimate. Organizations must also determine whether a human or machine identity should be allowed to perform a specific action against a specific resource under current conditions.
That is why I see identity increasingly becoming the enterprise control plane.
The real challenge is not logging in.
Many zero-trust programs begin with authentication. MFA, conditional access, passwordless authentication and device-compliance controls strengthen the front door, but successful authentication does not automatically mean appropriate access.
A legitimate user may still have excessive privileges. A compliant endpoint may provide access to information the employee no longer requires. An AI agent may authenticate correctly while receiving broader access than its task warrants.
The challenge, however, is not simply designing more granular identity controls. It is making those controls work consistently across a complex enterprise, where security requirements, business processes, legacy systems and employee experience all intersect.
One of the most important lessons I’ve learned from leading large-scale identity and workplace transformations is that security architecture alone does not determine whether a program succeeds. The operating model does.
In one identity and zero-trust transformation supporting more than 50,000 users, the objective was to strengthen identity security while reducing user friction and the operational burden associated with authentication and account recovery. The program included MFA, passwordless and biometric authentication, self-service password reset and stronger identity controls. Implementing those capabilities at scale required coordination across security, workplace technology, application, endpoint, service-management and business teams.
The leadership challenge here involved balancing security, continuity and the experience of the employees. We had to account for legacy applications and varying endpoint conditions while designing authentication policies, and strengthen recovery without creating excessive dependence on technical support.
By treating identity as an enterprise change in operating model rather than a security-only initiative, password reset requests were cut by about 90% while enhancing authentication capabilities.
The broader lesson was clear: technology provides the control, but governance, process integration and accountability determine whether that control works at scale.
Identity and device trust must work together.
Consider two access requests from the same employee. One comes from a managed, patched and compliant corporate endpoint, while the other uses the same credentials from an unmanaged device with an unknown security posture. The identity is the same, but the business risk is not.
Identity, endpoint and security strategies therefore cannot be managed independently. Organizations should combine identity, device, behavioral and resource-risk signals to make more precise access decisions.
Do not turn AI agents into the next generation of service accounts.
The emergence of AI agents should cause leaders to revisit lessons enterprises have already learned from machine identities.
One recurring challenge with machine identities that I’ve seen while managing enterprise identity environments is that ownership can become unclear over time, credentials may remain active longer than necessary and permissions can accumulate as systems and business processes evolve. What begins as a narrow technical requirement can become persistent access with limited visibility or accountability.
AI agents raise the stakes because they may interpret information, initiate workflows and take actions on behalf of people or business processes.
Organizations should avoid treating agents as more sophisticated service accounts. An enterprise AI agent should have a clearly accountable owner, documented business purpose, explicit delegation model, defined permission boundaries and a lifecycle covering approval, monitoring, review and revocation.
Executives must be able to answer simple questions like:
• Who is responsible for this agent?
• What business objective is it authorized to accomplish?
• What kind of data can it use?
• What actions can it take?
• Who has authority over it?
• How soon can such authority be stripped away?
Organizations often focus heavily on initial provisioning while underestimating the more difficult challenge of ongoing governance. Business processes evolve, people change roles and applications are replaced, while machine identities can persist through those changes.
For AI agents, governance should therefore extend from registration and authorization through observation, revalidation and revocation.
Measure security by outcomes, not deployment.
Technology leaders need to distinguish between implementation milestones and enterprise outcomes.
Deploying MFA to thousands of employees is important, but leadership should ultimately ask whether account-compromise exposure has decreased, recovery processes have become more resilient, endpoint compliance has improved and standing privileged access has been reduced.
These measures connect cybersecurity investment directly with enterprise value. What is more difficult, however, is embedding the security investment in an operations model that mitigates risks while enhancing productivity and flexibility.
Identity will become infrastructure.
AI will not replace zero trust. It will enable zero trust to evolve. The enterprise will govern people, contractors, devices, workloads, applications and AI agents using shared trust principles.
In this sense, identity can no longer be viewed simply as the mechanism people use to log in. It is becoming an enterprise infrastructure layer that determines who—or what—can interact with business systems, under what conditions, for what purpose and for how long.
For years, cybersecurity teams have focused on answering, “Who are you?” In an increasingly autonomous enterprise, the more consequential question will be: “What are you attempting to do, under whose authority and should you be allowed to do it right now?”
Organizations that can answer that question consistently will be better positioned to scale AI and automation without losing control of enterprise trust.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

