
About this episode
This story was originally published on HackerNoon at: https://hackernoon.com/ai-wont-fix-your-broken-iam-data.
AI is transforming identity and access management, but fragmented identity data can undermine automation and amplify security risks across enterprise systems.
Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity.
You can also check exclusive content about #identity-and-access-management, #iam-data-fragmentation, #truth-source-cybersecurity, #identity-governance, #breach-attack-vector, #iam-security-operations, #incident-response-security, #good-company, and more.
This story was written by: @jonstojanjournalist. Learn more about this writer by checking @jonstojanjournalist's about page,
and for more stories, please visit hackernoon.com.
Enterprises are rushing to add AI to identity and access management, but fragmented identity data remains a critical weakness. Without a reliable, continuously updated source of identity truth, AI-driven automation can accelerate bad decisions rather than improve security. Experts argue organizations must first normalize identity data, clarify entitlements, and establish context before layering AI and automation on top.
Interactive timestamps
Jump to segmentGet every episode summarized
Each time The Good Tech Companies publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
65 searchable segments. Every word is indexed and playable.
Full transcript
The Good Tech Companies — AI Won’t Fix Your Broken IAM Data. Machine-transcribed; use the interactive transcript above to jump the player to any line.
0:00This audio is presented by Hacker Nune, where anyone can learn anything about any technology. AI won't fix your broken IAM data by John Stoy and Journalist. Artificial intelligence is rapidly becoming the default answer to almost every security challenge. Boards are asking about it, CISOs are budgeting for it, vendors are rebranding around it, but in identity and access management, IAM, AI is only as good as the data you feed it, and in most enterprises, that data is far from complete. IBM's cost of a data breach report found that compromised credentials remain one of the most common initial attack vectors in breaches, and that organizations are increasingly adopting AI and automated detection, response workflows to reduce breach costs and well time. The report also underscores identity-related vulnerabilities as core contributors to risk and highlights strengthening identity security as a key area for remediation. And yet, many organizations are racing to, I-enable, IAM without first establishing a reliable, continuously updated source of identity truth.
1:02I'm notuntie AI, says UC bearishiv, who is currently leading an IAM security startup. I'm anti-nonsense. If you don't know what's true and reliable in your environment, AI won't fix that. It will just make mistakes happen faster. Why this is urgent now? AI in 2026 is no longer just summarizing dashboards. It is taking action, it approves requests, revokes access, triggers workflows, and enforces policy changes across systems. That shift changes the risk equation. When humans made identity decisions manually, data fragmentation created delay and friction. When AI systems make or heavily influence those decisions, data fragmentation creates amplified consequences. AI accelerates decisions. If the underlying data is incomplete, outdated, or missing context, the system doesn't just move faster. It moves faster in the wrong direction. The fragmented reality behind access. In most enterprises, there is no single system of record for identities in access.
2:04Authentication data lives across multiple platforms. Life cycle management and Anna-other, privileged credentials somewhere else. HR records in a separate system. Access requests in tickets. Entitlements are often embedded inside the applications themselves, especially in legacy and homegrown ones. Each system holds a fragment of reality. None holds enough information to be truly actionable. Teams are manually stitching reality together. Barishev says, by the time your reconcile HR records, directory data, privileged access, and the application data itself, the answer often is already outdated. The result is an identity picture that is always incomplete, often out of date, and is always resource intensive. The litmus test, there is one simple question that reveals whether identity truth exists. Can you answer right now which identities have access to what? And why? Not after exporting and correlating data from 10 different systems. Not after running a month-long user access review campaign. Right now, this question doesn't only matter during audits when regulators expect
3:07precise evidence. It also matters during incident response when an identity's blast radius determines the containment strategy. It matters in joiner mover lever workflows where policies rely on a deep understanding of entitlement grants. It matters during M and A's when two identity universes collide, and it matters in the day-to-day operations when teams perform hygiene activities, handle access requests, and chip away at the daily grind of IAM work. If the answer requires manual reconciliation of multiple disparate systems, your foundation is weak. You don't need another dashboard. Many organizations point to dashboards as proof of visibility, but more often than not, its visibility features. Dashboards are garbage and garbage out systems. As long as your identity data lacks context, explainability, and clarity into the relationships between identities, applications, and controls, achieving objectivity is hard. Without investing in a solid data foundation for IAM operations, teams will hesitate to act. Or worse, act without understanding the impact and
4:10implications, what a ready identity actually requires, AI ready and automation ready identity begins with continuous truth, not quarterly snapshots. It requires normalized entitlements, whose meaning travels with the macross systems. It requires a defensible, why, for access that goes beyond checkbox theater. And it requires safe actionability, understanding impact before making changes. Only when identity data is current, contextualized, and explainable can it irreliably prioritize risk or automate remediation. Start with truth, then automate. This does not require a grand transformation program. It requires focus, pick a single pain point, application onboarding, access reviews, offboarding, identity hygiene, or incident response. Define a simple metric, mean time to understand how long it takes the practitioner to have all the data they need for execution to become arbitrary. Prioritize critical systems first, especially legacy or high-risk platforms where blind spots are greatest. Then, and only then, layer automation and AI on top as
5:15the last mile, automating workflows, prioritizing anomalies, highlighting risky combinations, or streamlining approvals. AI will matter in IAM. It can reduce noise, speed decisions, and augment overworked teams. But if the underlying access picture is partial, AI increases speed, not certainty. Get identity truth first, then let AI help you move faster. This story was distributed as a release by John Stoyan under Hackernoon Business Blogging Program. Thank you for listening to this Hackernoon story, read by artificial intelligence. Visit Hackernoon.com to read, write, learn, and publish.
More episodes
More from The Good Tech Companies

Vanta vs Scytale (2026): A Head-to-Head Compliance Platform Comparison
The Good Tech Companies

10 of the Best Local SEO Tools for Multi-Location Agencies in 2026
The Good Tech Companies

Lightsage Raises $4M Led by Nexus to Build the Growth Stack for AI Agents
The Good Tech Companies

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conven...
The Good Tech Companies