The Olam
Agent Identity: Why Israeli Cyber Leads the AI Governance Category
Crypto & Digital Assets

Agent Identity: Why Israeli Cyber Leads the AI Governance Category

May 26, 2026

Agent Identity addresses AI agents as a distinct identity class — separate from human users and traditional machine identities. The governance problem, the Israeli cohort positioning, and why the category is structurally one of the largest in enterprise identity.

Agent Identity is the category of identity-and-access management that addresses AI agents as a distinct identity class — separate from human users and from traditional machine identities. The category emerged through 2024-2026 as enterprise AI agent deployment scaled, identity-security teams encountered governance problems the existing identity infrastructure was not designed to handle, and Israeli identity-security companies began building specialized agent-identity capabilities.

The technical, governance, and commercial implications are substantial. Agent identity is now one of the most actively-developed segments inside the broader Israeli identity-security category.

What agent identity is

Traditional enterprise identity systems were built around two identity classes:

Human identities. Employees, contractors, partners. Authentication via passwords, multi-factor authentication, single sign-on. Authorization via role-based access control and identity governance.

Machine identities. Service accounts, API keys, certificates, secrets. Authentication via static credentials, sometimes rotated. Authorization frequently overly broad due to operational convenience.

AI agents do not fit cleanly into either class. An AI agent acts on behalf of a human (often without continuous human oversight), operates with elevated permissions (often broader than the human delegating to it), runs intermittently (rather than always-on like a service account), and may chain through multiple downstream systems in a single workflow. The existing identity infrastructure was not designed for an entity that behaves like a human in some respects, a machine in others, and a delegated proxy in still others.

The governance problem

Enterprises deploying AI agents at scale encounter four governance problems that traditional identity infrastructure does not solve:

Permissioning. An agent acting on behalf of a user needs permissions appropriate to that user's role — but ideally scoped narrower than the user's full entitlements, just-in-time. The existing identity systems generally cannot express that granularity.

Audit and accountability. When an agent takes an action, the audit log needs to capture both the agent's identity and the human principal on whose behalf it acted. Most existing audit systems were not designed to capture chained delegation cleanly.

Lifecycle management. Agents are created, deployed, updated, and decommissioned at a different cadence than service accounts. The identity governance lifecycle needs to accommodate that.

Trust and provenance. Verifying that an agent is operating with the expected code, on the expected infrastructure, with the expected permissions, in real time — a problem that does not exist for human identities and only partially exists for traditional machine identities.

The Israeli cohort

Israeli identity-security companies are positioned aggressively in the agent-identity category:

Oasis Security. The named Israeli cohort leader in non-human identity management with extension into AI agent identity. Founded by alumni of the Israeli identity-security ecosystem, Oasis has built substantial enterprise customer base around the non-human identity governance problem.

CyberArk (now Palo Alto Networks). The privileged access management category leader, with identity-security positioning that extends to agent identity under the broader Palo Alto Networks platform post-acquisition.

Astrix Security. Non-human identity management with agent-identity adjacency.

Apono. Just-in-time access management with applicability to agent permissioning and authorization.

Silverfort. Unified identity security with capabilities extending into the agent identity category.

The market sizing question

Agent identity as a commercial category was effectively zero in 2023. By 2026, multiple Israeli identity-security companies are reporting material revenue specifically attributed to agent-identity products and capabilities. The customer base is concentrated in financial services, healthcare, and broader regulated industries where agent governance is a board-level concern rather than a technical preference.

The structural sizing logic: non-human identities outnumber human identities by approximately 80 to one inside large enterprises. AI agents add a new identity class on top of that ratio. The category is sized to be materially larger than traditional privileged access management within a multi-year horizon — if the technical and commercial execution holds.

Why Israel leads the category

The Israeli concentration in agent identity follows from three structural advantages:

Cybersecurity engineering depth. Israel hosts the largest identity-security engineering bench outside the US. The post-Wiz, post-CyberArk cohort of identity-security founders is concentrated in Israel.

Unit 8200 and broader signals-intelligence experience. The IDF technical pipeline produces engineers with deep expertise in identity, authentication, and access management as they relate to security architecture.

Customer adjacency. The Israeli cyber ecosystem has long-running relationships with US Fortune 500 customers across cybersecurity. The agent-identity customer base is structurally similar to the existing identity-security customer base.

What the category means in 2026

Agent identity is no longer a speculative category. The Israeli companies operating in it have material revenue, growing customer bases, and product roadmaps that address governance problems enterprise customers are currently experiencing. The Palo Alto Networks acquisition of CyberArk was, in part, an explicit bet on the identity category extending to AI agents at scale.

For Israeli identity-security, the agent identity category is the most institutionally important growth vector through 2026-2028. The technical depth, the engineering pipeline, and the customer relationships position the Israeli cohort to capture a substantial share of what is structurally one of the largest categories of enterprise identity software in development.

Universities & Research

All coverage →

Olam Research

All coverage →