As enterprises move from generative AI assistants to autonomous AI agents, cybersecurity is confronting a fundamentally different identity problem. AI agents can access applications, retrieve sensitive data, invoke tools and execute business processes at machine speed. Traditional identity governance, designed largely around human users and relatively predictable application identities, was not built to continuously govern this level of autonomous action.
Omada’s acquisition of Ohio-based EmpowerID directly targets this emerging gap. Announced on September 24, 2026, the deal integrates EmpowerID’s AI-agent governance and runtime authorization capabilities with Omada’s Identity Governance and Administration platform. The combined approach is intended to govern human, non-human and AI-agent identities through a common identity and policy framework.
The important shift is from governing access to governing action. Conventional IAM asks whether an identity is permitted to access a resource. Agentic AI introduces another question: once an agent has access, what exactly should it be allowed to do, at this moment, and under whose authority?
EmpowerID’s technology can discover agents, establish accountable ownership, associate them with approved missions and evaluate proposed actions at runtime. On supported governed execution paths, authorization can occur before an agent invokes a tool or performs a consequential action; denied actions can be blocked and the decision preserved as evidence.
For enterprises, this creates the possibility of applying least privilege dynamically, rather than granting an AI agent broad standing permissions and reviewing activity only after something goes wrong. Every authorization, governance decision and review can also contribute to an audit trail, strengthening accountability and compliance.
The acquisition reflects a larger cybersecurity transition. As autonomous agents proliferate, enterprises will increasingly need to govern not only who has access, but which agent is acting, what authority it possesses, what tools it can invoke, what action it is attempting and whether that action should be permitted in real time.
In the agentic era, identity security is becoming execution security.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.

