<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lilian SAULOUP, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/lilian-sauloup/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/lilian-sauloup/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 04 Jun 2026 13:15:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Lilian SAULOUP, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/lilian-sauloup/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AI for IAM: A pragmatic trajectory rather than a revolution</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/#respond</comments>
		
		<dc:creator><![CDATA[Lilian SAULOUP]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 13:13:39 +0000</pubDate>
				<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[access management]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Transformation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30015</guid>

					<description><![CDATA[<p>1.    AI is no longer a fantasy, it&#8217;s a reality that IAM must not miss Two years ago, we asked whether artificial intelligence (AI) could represent a revolution for IAM in our article “Artificial intelligence: a revolution in IAM? &#8211;...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/">AI for IAM: A pragmatic trajectory rather than a revolution</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 style="text-align: justify;">1.    AI is no longer a fantasy, it&#8217;s a reality that IAM must not miss</h2>
<p style="text-align: justify;">Two years ago, we asked whether artificial intelligence (AI) could represent a revolution for IAM in our article “<a href="https://www.riskinsight-wavestone.com/en/2024/03/artificial-intelligence-a-revolution-in-iam/">Artificial intelligence: a revolution in IAM? &#8211; RiskInsight</a>”. We already emphasized the need for a <strong>nuanced approach</strong>, based on <strong>concrete use cases</strong>, <strong>test-and-learn</strong> logic, and a requirement for <strong>trust compatible with the specific challenges</strong> of identity and access.</p>
<p style="text-align: justify;">Today, the assessment has become more precise: AI has not caused the disruption that some predicted, but it is beginning to find a <strong>real</strong>, more <strong>targeted</strong>, and above all more <strong>pragmatic</strong> role within IAM.</p>
<p style="text-align: justify;">What we also observe is that AI leads to an expansion of the scope of IAM: IAM must now also address issues related to AI and AI agents. To delve deeper into this point, we invite you to explore our article “<a href="https://www.riskinsight-wavestone.com/en/2026/04/securing-ai-agents-why-iam-becomes-central/">Securing AI Agents: Why IAM Becomes Central &#8211; RiskInsight</a>”.</p>
<p style="text-align: justify;">As a reminder, AI is <strong>progressively establishing itself</strong> as a lever for transforming information systems, and <strong>IAM is no exception to this trend</strong>. Faced with the multiplication of identities driven by transformations of different natures, whether it be infrastructure evolutions with the cloud, business vision changes with the rise of CIAM, or the arrival of new technologies like AI agents, organisations must deal with increasingly rich and difficult-to-maintain authorisation models.</p>
<p style="text-align: justify;">In this context, <strong>AI promises to make IAM services more efficient and accessible</strong>, whether through intelligent recommendations, conversational assistants, better data utilisation, or processing volumes that are difficult to manage with traditional approaches.</p>
<p style="text-align: justify;">However, these contributions call for caution. IAM directly concerns access security: at this stage, <strong>AI must remain an assistance tool</strong>, under human supervision, as <strong>responsibility</strong> cannot be delegated to it. In practice, it still primarily manifests as <strong>peripheral components (copilots, chatbots, agents)</strong> that enhance existing systems without disrupting critical functions. The challenge is therefore no longer so much about whether AI has a place in IAM, but rather about identifying <strong>where and how to apply it in a truly relevant way.</strong></p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-30044" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation.png" alt="AI-IAM relation" width="602" height="304" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation.png 602w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation-378x191.png 378w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation-600x304.png 600w" sizes="(max-width: 602px) 100vw, 602px" /></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">2.    What AI use cases truly make sense in IAM?</h2>
<p style="text-align: justify;">The contributions of AI in IAM are unevenly distributed:</p>
<ul style="text-align: justify;">
<li><strong>Identity Governance &amp; Administration (IGA) </strong>concentrates the bulk of initiatives thanks to its data volumes and frequent decisions (reviews, validations, recommendations).</li>
<li><strong>Access Management (AM)</strong> is also heavily featured, with projects primarily aimed at accelerating and streamlining the user authentication process.</li>
<li><strong>Privileged Access Management (PAM)</strong> is seeing the emergence of more targeted uses, particularly around the detection and monitoring of privileged behaviours.</li>
<li>The potential of AI in <strong>Customer Identity and Access Management (CIAM)</strong> remains relatively underexploited, even as it is becoming strategic. This is particularly evident in the emergence of AI agents capable of interacting or acting on behalf of users, especially through chatbots.</li>
<li>AI currently offers limited value for <strong>Trust Services</strong>, where processes are already largely automatable without AI, and is positioned more as peripheral support.</li>
</ul>
<p style="text-align: justify;">To organise these initiatives without ending up with a long list, two main categories of use cases can be identified:</p>
<ol>
<li>Those that aim to <strong>resolve current challenges</strong> in existing processes.</li>
<li>Those that make it possible to address new issues <strong>that traditional approaches cannot cover</strong><strong>.</strong></li>
</ol>
<h3 style="text-align: justify;">The value of AI first emerges from current IAM pain points…</h3>
<p style="text-align: justify;">This first family of use cases generally constitutes <strong>the most natural entry point</strong>, as it relies on existing IAM processes.</p>
<p style="text-align: justify;">AI then plays an <strong>accelerating role</strong>, by <strong>reducing costs and operational</strong> burden, while <strong>improving the experience</strong>, <strong>quality of service</strong>, and <strong>speed of execution</strong>, without calling into question the control model.</p>
<p><img decoding="async" class="aligncenter wp-image-30046 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case.png" alt="AI use case" width="602" height="339" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case.png 602w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case-339x191.png 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case-600x339.png 600w" sizes="(max-width: 602px) 100vw, 602px" /></p>
<p style="text-align: justify;">…to become a lever for overcoming the limitations of traditional approaches</p>
<p style="text-align: justify;">The second category of use cases falls into a different category: here, AI is no longer merely aimed at saving time but <strong>unlocks analytical capabilities that are beyond the reach of traditional approaches</strong>, by cross-referencing multiple data points (identity, organisation, permissions, usage, events) across large volumes of data. In particular, it <strong>enables the large-scale detection of atypical access</strong>, such as rare combinations of rights, authorisations inconsistent with a role, or accumulations linked to successive exceptions.</p>
<p style="text-align: justify;">AI also enables the analysis of career trajectories, identifying how certain profiles evolve over the course of job changes, projects or emergencies, to target remedial actions. It also enables intelligent prioritisation of these remedial actions by combining application criticality, data sensitivity and usage signals, whilst in the field of PAM, emerging uses aim to identify behaviours involving unusual privileges to trigger enhanced controls.</p>
<p style="text-align: justify;">Finally, this also paves the way for delegating lower value-added tasks, such as handling Level 1 tickets, for which automation was technically feasible but economically difficult to justify. Today, some <strong>AI-powered</strong> IAM solutions make this substitution realistic and accessible.</p>
<p style="text-align: justify;">The multiplication of pain points and automation avenues should not lead to the indiscriminate deployment of AI. Some needs can be effectively addressed using simple rules or algorithms, and whenever access is involved, every potential error carries a security risk. It is therefore essential, once use cases have been identified, to select and prioritise them, rather than accumulating initiatives.</p>
<h2 style="text-align: justify;">3.    Prioritise AI in IAM before it becomes a pile of initiatives</h2>
<p style="text-align: justify;">Once relevant use cases have been identified, it is necessary to determine which ones to focus efforts on, as not all justify the same level of investment. Prioritisation can thus be based on two key axes: <strong>added value</strong> and <strong>implementation complexity</strong>.</p>
<p style="text-align: justify;"><strong>The challenge here lies in the ability to analyse these two aspects rigorously for each use case.</strong></p>
<p style="text-align: justify;">The first axis, relating to <strong>value</strong>, can thus be understood through several sub-criteria:</p>
<ul style="text-align: justify;">
<li><strong>Operational cost reduction</strong>: <em>measuring how the use case helps avoid certain recurring costs.</em></li>
<li><strong>Efficiency gains and reallocation of efforts</strong>: <em>the ability to free up time and redirect teams towards higher value-added tasks.</em></li>
<li><strong>Reducing cyber risk</strong>: <em>the impact of the use case on reducing identified cybersecurity, IT, or control risk.</em></li>
<li><strong>Contribution to regulatory and strategic issues</strong>: <em>to what extent does the use case meet a priority regulatory or strategic expectation (e.g., DORA, ECB, audits).</em></li>
<li><strong>Impact on the affected populations</strong>: <em>assess who the use case serves and with what frequency of use, as modest but daily use by a large number of users can create more value than a more ambitious use case limited to a restricted scope. The main populations to consider are generally IAM administrators, IAM integrators, end-users, and approving managers.</em></li>
</ul>
<p style="text-align: justify;"><em> <img decoding="async" class="aligncenter size-full wp-image-30048" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value.png" alt="Persona impact on a use case value" width="602" height="338" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value.png 602w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value-600x338.png 600w" sizes="(max-width: 602px) 100vw, 602px" /></em></p>
<p style="text-align: justify;">The second axis, <strong>complexity</strong> can be assessed according to four complementary dimensions, consisting of:</p>
<ul style="text-align: justify;">
<li><strong>Technical complexity</strong>: the technological effort required to deploy the use case, whether in terms of integrations, architecture, AI models used, or dependencies on the existing information system.</li>
<li><strong>Organisational complexity</strong>: the level of coordination required between teams, scopes, and processes to effectively support the use case.</li>
<li><strong>Associated risks</strong>: cyber, regulatory, or operational risks that may be introduced or reinforced by the implementation of the use case.</li>
</ul>
<p style="text-align: justify;">As a reminder, this approach aims primarily <strong>to guide thinking and structure decision-</strong>making; it is only a proposal that must therefore be adapted <strong>to each context</strong>.</p>
<p style="text-align: justify;">High-impact but quick-to-deploy use cases should be prioritised. Conversely, those requiring significant effort (unavailable data, complex integrations, high security requirements) for limited benefit should be discarded or deferred. To make the trade-off concrete, a &#8220;matrix&#8221; logic works well:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-30050 size-medium" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop-340x191.png" alt="How to prioritise use cases to develop?" width="340" height="191" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop-600x338.png 600w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop.png 602w" sizes="auto, (max-width: 340px) 100vw, 340px" /></p>
<p style="text-align: justify;">However, this approach also requires being clear on one point: <strong>AI depends heavily on data</strong> (quality, completeness, traceability, repositories) and the ability to exploit it securely. Without <strong>solid foundations</strong>, even a promising use case will remain at the demonstration stage. To generate value in real-world conditions, it must be able to rely on <strong>sufficiently robust IAM foundations</strong>: data quality, structured repositories, process stability, clarity of the authorisation model, etc. Thus, prioritisation must be confronted with the reality of available solutions and their maturity.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">4.    A booming market, with usage still largely unequal</h2>
<p style="text-align: justify;">The IAM market is strongly energised by AI, with expanding roadmaps and the emergence of so-called &#8220;AI-native&#8221; products, designed from the outset to integrate assistance, analysis, and automation mechanisms. These approaches generally address either a <strong>targeted need</strong> or <strong>a differentiation strategy in a rapidly evolving market</strong>.</p>
<p style="text-align: justify;">In parallel, traditional IAM solutions are progressively enhancing their offerings with AI functionalities and generally benefit from greater resources than AI-native players to support this transformation, primarily in cloud environments, which are more conducive to their deployment than on-premises architectures.</p>
<p style="text-align: justify;">However, there remains <strong>a notable gap between promise and reality in production</strong>: most of the functionalities available today are still peripheral assistance (search, summarisation, copilots) rather than AI truly embedded in critical functions.</p>
<p style="text-align: justify;">Adoption also remains gradual, particularly in large organisation, <strong>where the priority remains optimising existing systems</strong>, <strong>stabilising</strong><strong> repositories, reducing technical debt, and ensuring compliance</strong>. AI-native approaches, still relatively new, must be integrated into a realistic roadmap and a clear operating model. <strong>AI should not be seen as a miracle product, but rather as a lever to be incorporated into a global IAM transformation.</strong></p>
<p style="text-align: justify;"><strong> </strong></p>
<h2 style="text-align: justify;">5.    Conclusion – From the announcement effect to a controlled trajectory</h2>
<p style="text-align: justify;">AI applied to IAM seems to be reaching a turning point. The real challenge is not to accumulate use cases: it is to <strong>build a coherent, selective, and sustainable approach</strong>. Because it intervenes in access decisions, AI in IAM requires a higher level of caution than in other areas. The promise of automation <strong>must never mask the responsibility of humans and organisations</strong>. Any recommendation must be understandable, contestable, and justifiable, especially in an audit context. It is necessary to clearly define who validates and who arbitrates, ensure the acceptance of business teams without which AI will be bypassed, ensure regulatory compliance, and rigorously frame the data exposed to assistants to prevent any exfiltration of sensitive information.</p>
<p style="text-align: justify;">To maintain this trajectory, <strong>it is not enough to evaluate use cases in isolation</strong>: the <strong>foundations must be evolved</strong> (quality of identity data, repositories, role model, controls), <strong>an operational model capable of supervising AI</strong> on a daily basis <strong>must be defined</strong>, and emerging uses, particularly around AI agents, must be secured. AI for IAM should therefore <strong>not be thought of as an immediate revolution</strong>, but as <strong>a gradual progression</strong>, from assistance modules to advanced analysis capabilities, ultimately leading to better-controlled automation.</p>
<p style="text-align: justify;">Ultimately, approaching AI in IAM well means moving forward pragmatically, targeting uses that offer <strong>the best balance between value and complexity</strong>, maintaining control over sensitive decisions, and staying attentive to the real market maturity.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">6.    Five priorities to move from AI ambition to IAM results</h2>
<p style="text-align: justify;">In summary, here are the key points to bear in mind to adapt to this transformation:</p>
<ol>
<li style="text-align: justify;"><strong>Identify AI use cases that truly make sense for IAM</strong>, whether they involve improving existing processes or unlocking new capabilities for analysis and automation.</li>
<li style="text-align: justify;"><strong>Objectively define the value and complexity of each use case</strong> to prioritise them for implementation.</li>
<li style="text-align: justify;"><strong>Build a progressive, controlled, and governed trajectory</strong>, rather than accumulating initiatives without an overall vision.</li>
<li style="text-align: justify;"><strong>The market is structuring itself rapidly</strong>: talk to your vendors to understand what they are really offering.</li>
<li style="text-align: justify;"><strong>Also inquire about emerging new solutions</strong>, particularly AI-native ones, and do not hesitate to contact us if you wish to discuss your initial field feedback or broaden your market vision.</li>
</ol>




<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/">AI for IAM: A pragmatic trajectory rather than a revolution</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
