Our State of Authorization: AI Edition is now available Get it now »

2026: A reflection on what’s ahead for Axiomatics, authorization, agentic AI, and more

A brief look at what lies ahead for Axiomatics, authorization, access management, AI, Zero Trust, and more

Access management is becoming increasingly complex as organizations navigate a mix of cloud applications, enterprise systems, and emerging technologies. The need to enforce policies consistently, maintain compliance, and adapt to new security paradigms is greater than ever. At the same time, innovations in AI are opening new possibilities for managing authorization more intelligently and collaboratively.

At Axiomatics, we are focused on helping organizations turn intent into action, providing tools and frameworks that bring clarity, control, and confidence to every stage of the authorization lifecycle.

Shaping a vision: The comprehensive authorization lifecycle

The past decade has seen the rise of externalized, runtime authorization. In 2013, The National Institute of Standards and Technology (NIST) published its attribute-based access control (ABAC) policy-enforcement point (PEP)/ policy-decision point (PDP) architecture. Yet despite this progress, authorization hasn’t reached the same level of adoption as authentication. At the 2023 Internet Identity Workshop, Eve Maler proposed to combine the P*P approach with OAuth’s AS/RS approach. This convergence has given rise to comprehensive authorization. An inclusive approach that spans home-grown systems, off-the-shelf, and software-as-a-service (SaaS) applications alike.

Building on this momentum, we have defined a vision for the comprehensive authorization lifecycle and began translating it into practical software components. Over the coming year, customers will see this vision take shape as a cohesive set of capabilities that support the full lifecycle of comprehensive authorization. Starting with the ability to:

  • Define authorization requirements in plain English, use AI as an aid, and track requirements.
  • Identify which attributes and attribute sources are needed, along with their governance and ownership.
  • Implement policies in Abbreviated Language for Authorization (ALFA) with a developer-friendly, policy-as-code approach as well as visualize policies in Axiomatics’ control plane.
  • Test policies using standard tools, trace policy evaluations, and visualize traces on top of policy structure.
  • Leverage Axiomatics’ control plane to deploy and control which policies are packaged as well as integrate with existing continuous integration and continuous deployment (CI/CD) pipelines.
  • Run user access reviews, send audit logs to your security information and event management (SIEM) system, and plug into existing identity and access management (IAM) governance solutions.

For the complete vision of the comprehensive authorization lifecycle, see the image below:

As a part of our lifecycle vision, AI extends beyond the defining stage and cano be integrated at any point of the lifecycle. For example, perhaps there are requirements that prohibit teams from interacting with certain countries, therefore blacklisting some customers. AI can format these requirements into a textual format which can then be inputted into a framework structure and policy-as-code. From there, it can be enhanced in a collaborative manner between the compliance team, the developers, and the application owners who are all working together to shape this policy before deploying it. By leveraging AI during the authorization lifecycle, it can help instill confidence in compliance teams, ensuring requirements are being met in a timely manner.

The future of identity and access management (IAM)

As organizations adopt more complex software ecosystems, managing access consistently across diverse platforms has become a major challenge. Many applications — from cloud-based SaaS to enterprise databases — prioritize functionality over security, leaving teams responsible for access and compliance to fill the gap.

As an authorization management platform (AMP), we’re able to help IAM teams enforce policies across both custom and third-party systems from a single control plane. For example, teams can manage fine-grained authorization across cloud-hosted enterprise tools,databases, and custom applications, which was not traditionally possible. This approach allows teams to implement, monitor, and refine authorization policies efficiently, even in environments with widely varying application designs as it’s not hard-coded individually.

By bridging the gap between functionality-first applications and comprehensive authorization, IAM teams can operate with confidence, ensuring security and compliance while adapting to the ever-expanding landscape of enterprise software. Axiomatics plays a key role in this evolution, providing the tools and frameworks that make scalable and flexible authorization a practical reality.

Zero Trust and beyond

Zero Trust has become a cornerstone in modern security strategies, emphasizing the principle of “never trust, always verify.” Authorization is a key enabler of this approach, ensuring that users gain access only when needed and that standing privileges are minimized. Just-in-time access and dynamic policies help enforce these principles, reducing potential exposure without slowing down day-to-day operations.

However, authorization management platforms serve a broader purpose than Zero Trust alone. Beyond enforcing strict access controls, they support compliance, streamline workflows, and enable complex access scenarios that organizations encounter across different systems. This combination of security, productivity, and adaptability allows teams to meet both regulatory requirements and operational needs in a single, unified framework.

In this way, Zero Trust is one piece of a larger vision. By integrating real-time access control with broader policy management, Axiomatics will continue providing the tools to not only strengthen security, but also address the evolving challenges of modern IT environments.

AI: A look ahead

The landscape of authorization is evolving rapidly, and one area of focus is making policy management more dynamic, responsive, and integrated with emerging technologies. Increasingly, tools are being designed to support end-to-end management of authorization — from capturing requirements to refining policies in real time — and to provide actionable insights that help teams understand and improve access controls.

Another exciting development lies at the intersection of AI and authorization. AI is being used not only to assist with policy creation and refinement, but also to help organizations define guardrails for autonomous agents and intelligent systems, ensuring that access and decision-making remain aligned with business and compliance objectives.

Overall, these directions reflect a broader push toward more agile, intelligent, and adaptive approaches to authorization — where insights, automation, and collaboration come together to help organizations manage access with greater confidence and efficiency.

Taming Agentic AI

As AI systems become increasingly autonomous, a new challenge is emerging around ensuring that these intelligent agents operate within safe and predictable boundaries. While organizations are aware that some form of oversight will be necessary, many are still observing from the sidelines, waiting for clearer frameworks and tools.

A key area of focus is developing ways to provide guardrails around agentic AI, helping teams define, enforce, and monitor policies that guide AI behavior in line with organizational goals and compliance requirements. Addressing this need involves thinking ahead, preparing for a future where AI plays a more active role, and creating mechanisms that allow organizations to act confidently when that moment arrives.

While this future is likely three years from now, exploring these gaps 18 to 24 months ahead allows the authorization space to position itself to meet the evolving demands of AI-driven environments, ensuring both innovation and control can coexist.

Built with customers in mind: Authorization at scale

At Axiomatics, we are continuing to refine and expand our solutions to address the growing importance of authorization across complex systems. Our approach is deeply customer-focused: we help customers solve real challenges, and their experiences directly shape the direction of our platform.

One customer success story that stands out highlights this collaboration in action. Today, this customer is using our solution for 600 applications currently. Some applications are integrated with our solution through the traditional PEP/PDP approach, however, for some applications the traditional integration approach didn’t work due to various complexities. As a solution, they bundled a few applications into one cloud instance and put Axiomatics behind the access to that cloud instance.

To illustrate how this works in practice, let’s walk through a simple use case. Say the marketing team uses five different applications so they are bundled in one cloud instance. What this means is that if you’re on the marketing team you can get access to all five of those applications at runtime because that is when your access to the cloud instance is provisioned. However, someone from the product team would not get access to those applications in the cloud instance as the attributes wouldn’t match the policies in place. If an employee were to get moved from the product team to the marketing team, they would now be able to get access to those five applications at runtime based on attributes and zero standing privileges.

Although this is not directly tied to fine-grained authorization in the strictest sense, it is a great use case to show how more applications can be integrated with authorization.

Looking ahead

For years, the focus has been on authentication. What was once difficult to achieve slowly became simpler as standards emerged to address complexity and drive consistency. After that long journey, authentication is now mainstream and well understood. Now, authorization is having its moment in the spotlight, which represents an important step forward. More organizations understand what authorization is, recognize its role in security architecture, and are actively looking for authorization vendors that address this growing need.

When evaluating authorization vendors, it’s important to look for software that is standards-based, something that has always been of importance to Axiomatics. This began with the eXtensible Access Control Markup Language (XACML) and continues today with ALFA and OpenID AuthZEN. Building and innovating on top of standards is part of our DNA and enables us to deliver the best possible customer experience.

It’s also important to look for vendors that are proven in the space and deeply understand the challenges of authorization. Axiomatics has been a leader in dynamic, fine-grained authorization for nearly two decades and has supported numerous enterprise customers around the world.

Lastly, there is a growing demand in the market for a centralized control plane for authorization, mirroring the evolution seen in other IAM verticals such as identity governance and administration (IGA) and privileged access management (PAM). By enabling organizations to manage authorization from a single platform, we provide clarity and oversight across diverse applications, ensuring policies are enforced consistently and compliance requirements are met efficiently.

Ready to dive in?

We look forward to continuing the journey with you into the new year as we continue exploring the evolving world of authorization and access management. In the meantime, check out:

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Deepak Gupta

As Chief Product Officer, Deepak focuses on delivering innovative, standards-based authorization solutions that make it easier to solve complex security and compliance challenges. He previously worked with Pathlock and SAP, and enjoys working closely with customers and the industry to solve complex real-world security challenges.