Our State of Authorization: AI Edition is now available Get it now »

Lessons learned at KuppingerCole EIC 2026

Get an in-depth look on the conversations at EIC around authorization and AI ecosystems with Axiomatics' CTO, David Brossard.

To explore the key themes emerging from KupperingCole’s European Identity and Cloud Conference (EIC), I sat down with our CTO, David Brossard. From the rise of agentic AI and the growing importance of authorization to the convergence of identity and cybersecurity, our discussion uncovered the trends shaping the future of identity, access management, and AI governance.

What were the most important trends or themes you noticed?

Right off the bat, I would say AI, Agentic AI, Authorization, and all the flavors of authorization that Agentic AI requires — from consent and delegation to intent and more.

Of course, I may be a bit biased given my focus on authorization, so I decided to cheat a little bit and asked my trusted intern, ChatGPT, if it could confirm the trends I saw on-site by analyzing the agenda. And sure enough, it confirmed my impressions: the strongest signal is that the conference is about how identity becomes the trust and control layer for AI-driven, decentralized, and increasingly autonomous systems.

Because we are no longer just dealing with human actors, but also non-human actors such as agents, processes, and workloads, the question becomes: how do you establish trust and control when software can act independently?

For authorization vendors like Axiomatics, this is good news. Our architecture and policy-driven approach works equally well on human identities and non-human identities. If anything, the need for attribute-based access control (ABAC) or policy-based access control (PBAC) is even greater now that organizations must support finer-grained scenarios and access delegation.

Another trend that stood out was governance moving closer to runtime. Historically, governance activities were periodic and focused on:

  • Access reviews
  • Role engineering
  • Certification campaigns

Many talks at the conference revolved around:

  • Continuous governance
  • Behavioral monitoring
  • Real-time trust evaluation
  • AI accountability
  • Identity Threat Detection and Response (ITDR)

These approaches combine governance with operational security, blending aspects of runtime access control with identity management. It’s a notable evolution that further reinforces the need for policy-driven architectures.

Lastly, another strong theme was the convergence of IAM and cybersecurity. Topics traditionally viewed through a cybersecurity lens, including:

  • Zero Trust,
  • ITDR,
  • Cyber resilience,
  • Fraud prevention,
  • Cloud security,
  • Privileged Access Management (PAM),
  • Workload identities, and
  • Machine identities and non-human identities

were all discussed as a part of the broader identity conversation.

In fact, the entire conference was framed around the convergence of identity and cybersecurity disciplines.

Which session or speaker resonated with you the most, and why?

Elizabeth Garber of the OpenID Foundation delivered a powerful keynote on privacy-preserving technologies and their impact on everyday life. The keynote goes beyond technology and looks at very pragmatic, if not chilling, uses of identity and privacy.

Closer to home, Dr. Phillip Messerschmidt delivered a fantastic masterclass on authorization titled Authorization Put to the Test: How Modern Authorization Models Actually Help. For anyone new to the space, it offered an excellent overview of ABAC, PBAC, ReBAC, and other authorization models.

I was unfortunately unable to attend the session called Zero Trust – A Decade In, but with Allan Foster, Sebastian Rohr, and John Tolbert on the panel, it was bound to be a fantastic session. I plan to revisit that session as we design our very own approach to Zero Trust in the world of Agentic AI.

Looking back at your sessions, how would you summarize the key points you wanted attendees to take away, and what was the audience’s feedback?

I was fortunate to participate in three sessions:

  • OpenID Workshop, including an AuthZEN update
  • Beyond OAuth and OIDC: New Standards for Agentic AI
  • OpenID Foundation Blueprint for the Future

While many speakers discussed AI governance conceptually, I propose a blueprint for the authorization infrastructure required to make that governance a reality.

Ultimately, we need to acknowledge authorization is the missing control plane for AI and distributed systems. Together with peers across the standards community — including OpenID Foundation and IDPro — we are actively working to design this missing layer. That vision is also the foundation of Axiomatics and our recently launched Authorization Hub.

The icing on the cake was going up on the main stage to receive an award from Dr. Phillip Messerschmidt in recognition of the work being done within the OpenID Foundation’s AuthZEN Working Group alongside industry peers. We progressed from an initial concept in summer of 2023 to a 1.0 standard in January 2026. AuthZEN enables interoperability across policy decision points (PDP) and applications, helping organizations implement authorization more consistently across their environments.

David Brossard accepting the authzen award at EIC

What innovations, technologies, or topics seemed to be getting the most attention?

Authorization is quietly becoming more important than authentication.

Of course, no one stated this bluntly, but when you look at the conference agenda, authorization appeared repeatedly across topics such as:

  • Identity fabrics
  • AI governance
  • Delegated decision-making
  • Consent discussions
  • Workload identity

Even discussions around business wallets and digital credentials touched on authorization.

The emerging question is no longer: “Who are you?”

But: “What are you allowed to do, under what conditions, on whose behalf, and can we prove it afterward?”

I want to pause for a moment here: the latter part of the question, can we prove it afterward? is so fundamental.

Yes, we need better access controls. Yes, we need to make sure only the right actors get access to the right resources. But even more fundamentally, we need to prove it. We need an audit trail of what did or did not happen.

Technology such as Axiomatics provides an important foundation. However, integration with SIEM platforms, analytics tools, and AI-driven insights solutions will become increasingly critical for organizations to a successful deployment.

If someone couldn’t attend, what would you say is the single most important thing they missed?

Martin Kuppinger’s opening and closing keynotes are always highlights of the event and are packed with both strategic visions and actionable insights.

This year, he built a compelling narrative arc across the conference around the transition from human-centric IAM to AI-, machine-, and ecosystem-centric identity governance. Identity governance can no longer be designed around employees as the primary subject. Instead, it must encompass everything that can act, decide, transact, or influence outcomes.

Identity is rapidly becoming the governance layer for an economy increasingly populated by non-human actors.

Another observation that stood out was that authorization appeared everywhere, often without being explicitly named. Many sessions were framed around AI governance, trust, delegation, digital wallets, or identity fabrics. Underneath those discussions, however, were fundamentally authorization challenges.

That may be one of the most important meta-trends emerging from the conference and one of the clearest signals that organizations should begin preparing now.

Thank you to those who visited us at EIC!

EIC 2026 reinforced a message we’ve been hearing across industries: as AI systems become more autonomous, identity alone is no longer enough. Organizations need dynamic, policy-driven authorization that can govern decisions in real time, support delegation, provide accountability, and scale across both human and non-human actors.

Axiomatics team at EIC 2026

Thank you to everyone who stopped by the Axiomatics booth. It was a pleasure connecting with customers, partners, and fellow identity professionals. The conversations we had in Berlin left us optimistic about the future and excited about the role authorization will play in building trustworthy AI systems.

Want to learn more about the topics discussed at EIC? Explore these resources:

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Emme Reichert

As the Marketing Manager, Emme Reichert leads all aspects of the company’s marketing efforts and executes content that resonates with customers, partners, and influencers. She has experience with marketing in the healthcare and tourism industries.