Digital Security

Netwrix Forecasts Growing Dependence on Identity and Data Security as AI Expands Risk

Security outlook warns that misaligned identity governance and data protection will amplify exposure as AI-driven automation accelerates.

As artificial intelligence reshapes enterprise operations, identity and data security are becoming inseparable — and increasingly critical — according to a new cybersecurity outlook from the Netwrix Security Research Lab.

Netwrix forecasts that between 2026 and 2029, adversaries will scale identity-based attacks to compromise data as organizations rely more heavily on automation and AI-driven workflows. The report warns that misaligned identity governance and data protection will amplify exposure as agentic AI systems gain broader, autonomous access to sensitive information.

The outlook draws on Netwrix research into real-world identity attacks and data exposure paths and highlights the trends most likely to reshape cybersecurity over the next several years.

Identity and Data Security Converge in 2026

By 2026, Netwrix expects identity security to expand rapidly through automation across provisioning, token validation, and privilege management. These workflows increasingly determine who — and what — can access sensitive data, making failures in identity automation a direct data security risk.

Attackers are shifting away from targeting individual credentials and instead focusing on identity orchestration, federation trust relationships, and misconfigured automated workflows. As access to critical data begins with identity, organizations will need unified visibility across identity and data security to detect misconfigurations, reduce blind spots, and respond more quickly.

Agentic AI further accelerates this dependency. As AI systems perform tasks autonomously, they rely on identities to access, move, and act on data. Understanding which identities AI agents use, what data they can access, and under whose authority they operate becomes essential to preventing large-scale exposure.

Cyber insurance is also reinforcing this shift. As identity automation and AI-driven access increase risk, insurers are moving toward continuous validation of identity and data controls rather than periodic questionnaires. Organizations able to demonstrate consistent alignment between identity governance and data protection may benefit from improved coverage terms, while others face greater scrutiny.

What Is Unlikely to Change in 2026

Despite growing concern around AI-driven threats, Netwrix does not expect fully autonomous cyberattacks to dominate in 2026. While AI is accelerating reconnaissance, impersonation, and access abuse, most attack campaigns remain human-supervised due to operational complexity, unreliable feedback, and high costs.

Instead, defenders face the more immediate challenge of maintaining resilience against AI-accelerated attacks by denying the conditions automation depends on, including broad access and clean feedback loops. Strong identity controls and data visibility remain the most effective safeguards.

Looking Ahead to 2027 and Beyond

By 2027, Netwrix anticipates deeper convergence between identity systems and data sources as AI agents operate across previously siloed environments. Governance models will need to continuously validate identity context, access privileges, and policy alignment rather than rely on static controls.

Data itself is also expected to carry more built-in protection, including encryption, provenance, and access policies. While this can reduce breach impact, inconsistent implementation risks fragmentation and blind spots without strong identity context and standardized enforcement.

Emerging Risks in 2028 and 2029

Looking further ahead, Netwrix warns that declining trust in AI governance could undermine security if economic pressure reduces investment in oversight. Mapping identity relationships, data dependencies, and AI ownership early will be critical to maintaining resilience.

Vendor instability poses another growing risk. As organizations rely on emerging AI providers, uncertainty around data ownership, storage, and retrieval could create cascading compliance, security, and business continuity challenges if providers are acquired, restructured, or exit the market.

“The threat landscape isn’t only expanding because attackers suddenly have better tools,” said Dirk Schrader, vice president of Security Research at Netwrix. “It’s also expanding because identity security, data security, and automation are becoming inseparable. Organizations that succeed will be the ones that govern identity and data security together and treat automation as something to be continuously validated, not blindly trusted.”

For deeper insight into the vulnerabilities and attack paths informing the forecast, Netwrix recommends reviewing the latest analysis from its Security Research Lab.

Featured

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”