Enterprise investment in artificial intelligence is accelerating, but the governance layer required to control that investment is often lagging. As organisations deploy copilots, autonomous workflows and model-connected applications, identity governance and administration (IGA) becomes the mechanism for deciding who — and what — can access data, invoke tools and approve high-impact actions.
The central challenge is that AI expands the identity lifecycle. Traditional programmes were designed around employees, contractors and service accounts. AI introduces agent identities, workload identities, API credentials and rapidly changing permissions. These identities may act at machine speed and interact with sensitive systems long after an initial deployment has been approved.
IGA teams need visibility before they can enforce policy. Discovery should identify AI services, owners, connected data sources, delegated permissions and credential paths. That inventory needs to feed governance workflows: an owner must be accountable, access must have a business purpose and risky combinations must be detectable. Identity lifecycle management must cover creation, change, suspension and retirement.
Access decisions also need context. Risk-based policies can require stronger approval for production actions, restrict sensitive datasets and impose time limits on elevated privileges. Human approvals remain important, but they should be supported by clear entitlement and activity evidence.
The opportunity for IGA is to become the control plane for responsible AI adoption. Connecting identity data, entitlement governance and audit evidence lets organisations scale AI without creating an unmanaged parallel access model. Governance should be embedded in deployment pipelines instead of added after systems are live.