Identity Management Day, held on 14 April 2026, is a global awareness day observed on the second Tuesday of April each year since 2021. The 2026 theme was announced as “Finding Identity: The Search for You, Me, and the Machines”. This theme places machine identities and agent-based digital entities alongside human identities within the security agenda. The official event announcement clearly states that the 21-hour global broadcast stream will address the management of human, machine, and agent identities, and that MFA (multi-factor authentication) does not, on its own, cover the full picture.
At the core of this agenda lies the corporate access structure. Within the same access arrangement in organisational systems, the following elements operate together:
- Employee accounts,
- Service accounts,
- Application identities,
- Integrations,
- Automations,
- Device identities,
- AI agents.
Assessments published by SMB Tech and Cyber Daily show that the 2026 identity agenda is shaped around non-human identities, AI agents, identity risk and identity resilience. Identity governance and access management assessments shared by Omada, together with Melissa’s analyses in the fields of digital identity verification and data verification, further strengthen the focus on machine identities and agent-based digital identities. Lifecycle, scope of authority and governance burden are among the core components of this subject. For this reason, the type of identity used for access, the scope of the authority granted, the assurance level of the verification method, the visibility of non-human identities and the traceability of agent-based access have become direct management matters.
Threat-related data makes this picture concrete. According to findings from WatchGuard’s latest Internet Security Report, a 1548% increase in new and unique malware was recorded in the final quarter of 2025. Approximately 23% of threats bypassed signature-based detection. 96% of blocked malware was transmitted through channels encrypted with TLS, meaning Transport Layer Security. This data set shows that visibility is narrowing and that the identity using the access is, in itself, a security issue.
The set of questions facing organisations is clear:
- Which identity is accessing which resource?
- Under which approval is this access granted?
- How long does each privilege remain active?
- Within which inventory are non-human identities tracked?
- Under which permissions do AI agents operate?
- For which risk level is the verification method selected?
- How are logging, review and audit carried out?
These questions should not be regarded as technical items appearing on an information technology operations list. These issues are core elements of corporate trust, management discipline and a sustainable control structure. Decisions relating to identities do not remain limited to access. Data security, operational continuity, authority management, record order and the corporate accountability structure are also part of these decisions. For this reason, the subject establishes a direct link with the relevant management systems.
- ISO/IEC 27001 – Information Security Management System requires access control, authentication, authorisation and audit trails to be defined and auditable.
- ISO/IEC 27701 – Privacy Data Management System makes visible the authority limits, responsibilities and processing areas of digital identities accessing personal data.
- ISO 22301 – Business Continuity Management System requires the controlled management of critical accounts, administrative privileges, service dependencies and continuity of access.
- ISO/IEC 42001 – Artificial Intelligence Management System brings the traceability of agent-based access, data usage permissions and non-human identities onto the agenda.
Within this structure, ISO/IEC 29115:2013 provides an important reference. The standard defines four levels of assurance for identity verification. It explains the criteria for achieving these levels. It provides guidance for aligning different assurance structures. It directs attention to controls that reduce identity verification threats. It clearly sets out that verification assurance should be associated with risk for critical systems, sensitive data, high-privilege accounts and agent-based access.
Identity Management Day 2026 delivers a clear message to organisations. Invisible identities must be made visible. Privileges must be managed according to purpose, role and duration. Service accounts and agent access must be tracked within the inventory. Verification assurance must be defined through risk logic. Logging, review and audit must be operated as a corporate discipline.
CFE CERT provides training and certification services in the fields of information security, personal data, business continuity, digital identity and related management systems. For detailed information, you may contact us via info@cfecert.co.uk