Recap EIC 2026: Which Identity Security Topics Matter Today
Recap EIC 2026: Which Identity Security Topics Matter Today
More than 1,500 attendees, over 300 renowned speakers, and around 230 sessions across four days: that was the European Identity and Cloud Conference (EIC) 2026. As it does every year, the event once again showed that it is more than just an industry gathering. It is a barometer for the key topics shaping identity security — today and tomorrow. From agentic AI and modern authorization to Zero Trust, non-human identities, and digital sovereignty, the impulses are still resonating. One of our key takeaways: many discussions are now centered on new standards.
OpenID Federation: A New Standard
The EIC 2026 had barely been open for an hour before we already had to choose between five highly compelling panels. We opted for the “OpenID Workshop”. The central question was how proven federation approaches from the SAML-driven education and research world can be transferred into today’s OpenID Connect and OAuth landscape. Broad federated identity ecosystems have existed in this space for years. In many modern web, mobile, and cloud scenarios, however, OpenID Connect is now far more widespread.
With OpenID Federation, the OpenID Foundation provides a standard designed to establish trust between participating organizations, identity providers, and applications in a more scalable and automated way. This is particularly relevant for large federation ecosystems such as eduGAIN, which have so far been heavily based on SAML, while the digital world is increasingly revolving around OpenID Connect and OAuth.
Agentic AI Reveals Gaps in the Standards
Agentic AI was another major topic of discussion this year. In his keynote, “When Software Becomes Staff: Governance, Security & Safety for Agentic AI,” Nat Sakimura from the OpenID Foundation addressed several key questions: On whose behalf do agents act — delegated authority and the “Ultimate Bot Owner,” or OBO? How precisely can agent rights be limited through fine-grained authorization? Which signals need to feed into access decisions, such as risk signals?
Answers are urgently needed. AI agents are already acting on behalf of humans, accessing tools, and therefore require clarity around identity, ownership, permissions, and responsibility. Existing standards still have gaps — for example when it comes to workload identities, fine-grained access control, risk signals, trust anchors, and the ability to prove intent, action, and outcome.
The core message: companies and standards bodies now need to create the evidence and governance structures that make accountability, liability, and insurability for agentic AI possible in the first place. Technical usability alone is not enough. AI agents must be controllable, traceable, and accountable.
Fine-Grained Authorization: Where Standards Show Their Impact
Fine-grained authorization appeared repeatedly on the EIC agenda in 2025. In 2026, it became even more prominent. Why? Because AI agents, dynamic workloads, and short-lived identities mean that the traditional role-based logic many organizations still rely on is no longer sufficient. Agentic AI intensifies this need because it does not merely read — it actively takes action. Granting a user or machine broad rights once and leaving it at that is no longer enough. Authorization must be fine-grained, context-dependent, and evaluated at runtime.
This is where AuthZEN comes in. The new standard creates a common pattern for decoupling authorization decisions from applications and mapping them interoperably across systems, policy engines, and orchestration layers. Figuratively speaking, AuthZEN is the Lego brick needed in many parts of modern IAM frameworks — especially where agents, workloads, and APIs interact dynamically. AuthZEN was therefore recognized with an award at EIC together with cidaas.
For Umbrella, this was a special moment. Around three years ago, we laid the groundwork for exactly this. At Identiverse 2023, we discussed the idea that authorization needs a standard if it is to gain a firm foothold in the industry. That thinking ultimately led to the formation of the AuthZEN Working Group under the umbrella of the OpenID Foundation. For our team, it is a clear sign that the groundwork began at exactly the right time — and that the first results are now beginning to bear fruit.
And the excitement did not end there: in his keynote, “AI @ cidaas: From Vibe Coding to Agent Identity – Rethinking Authentication in the Age of AI,” Sadrick Widmann offered a very practical look at how cidaas implements agentic AI. AuthZEN played a role here as well. Umbrella was able to support cidaas some time ago in adopting a valuable building block for its product stack early on — well ahead of the competition.
Authorization Models: Leveraging Strengths, Minimizing Weaknesses
On the final day, umbrella.associates — represented by Roland — took to the stage itself. As part of the panel “Master in Authorization Models: xBAC etc al.,” the discussion centered on one key question: which authorization model is the right one? The answer was found quickly: it depends. Every model has its advantages and disadvantages. Depending on the use case and business requirements, the different models need to be examined carefully.
The experts agreed on one point: the future lies in xBAC. Decision-makers should therefore think in terms of hybrid models. The goal is to leverage the best characteristics of each model in order to compensate for the weaknesses of others. That is also why we are clear on one point: role-based authorization is not dead by default, even if the identity community often claims it is. The approach is simply no longer sufficient on its own. New models help close these gaps, but that does not mean organizations need to abandon RBAC entirely. What matters most today is using different approaches in a way that creates value for the specific use case. Companies need to position themselves accordingly — and in a future-proof way.
A Look into the Near Future
Identity Fabric Workshops: Keeping an Eye on Change
Every year, the EIC organizer — KuppingerCole Analysts — provides exciting insights through its Identity Fabric Workshops. These sessions focus on the components that interact within Identity and Access Management, and above all on how these components evolve over time. In his keynote, “From Workforce to Everything: The Next Chapter of Identity Security & Governance,” Martin Kuppinger made it clear that the IAM reality has changed massively — moving away from static, centralized infrastructure toward the management of non-human identities, AI agents, expanding CIAM networks, and much more.
Agentic AI in particular plays a major role in this shift and creates new requirements for secure, efficient, and transparent Identity and Access Management. The main reason: AI agents and dynamic workloads operate at machine speed. An identity can be created, complete a task, and disappear again shortly afterward. Processes that used to take hours or days may soon run in minutes or seconds.
Companies therefore need more automation, orchestration, and real-time evaluation. Signals are also becoming more important, as access decisions are increasingly context-dependent. Behavior, risk, context, device, identity types, trust levels — all of these are relevant signals that teams will need to pay closer attention to going forward. The rule here is clear: as identities become more short-lived and more diverse, organizations need reliable trust anchors.
Orchestration, in turn, ensures that signals are processed at the right moment. A sample logic might look like this:
- The AI agent performs an action.
- A risk signal is triggered.
- Through orchestration, the policy or authorization framework is informed.
- Access is restricted, stopped, or reassessed.
The Other Side of the World
On Wednesday, Sebastian Rohr took to the stage to report from the other side of the world — on the efforts of the World Bank, UNICEF, KfW, and the IADB to give children around the world access to good medical care, education, and support. His contribution focused on birth certificates and civil registration systems — or rather, on the need to first establish the necessary foundation for such systems using new approaches such as OpenCRVS and MOSIP.
Business Wallets: Coming soon!?
A closer look at the EIC 2026 agenda quickly showed that business wallets came up again and again. Even though there is still no comprehensive concept in place, the progress is clear, with more and more technology studies being presented. Various scenarios are also being prepared based on existing technologies. The industry is taking a practical approach to exploring the topic, even though a binding regulatory framework is still missing.
From the perspective of the identity community, business wallets could develop into a central identity building block over the coming years. After all, they offer one key advantage: today, digital identities are still often closely tied to central identity providers, large platforms, or individual accounts. Business wallets could break up this logic and support the decoupling of identities from central platforms. Instead of registering separately for every platform or logging in via central providers such as Google, users could in future prove their business identity directly through a business wallet. Similar to a physical ID, they could therefore become a trust anchor for industry — by digitally proving organizational affiliation, roles, authority to represent, or permissions.
Conclusion
Four insightful days are behind us, and there is one thing we especially want to say: thank you to KuppingerCole Analysts for organizing such a wonderful event once again. We are already looking forward to EIC 2027 in Berlin and are keeping May firmly reserved in our calendars.
Does all of this sound exciting, but you are wondering how individual topics could be implemented in your organization? We would be happy to take a look under the hood of your company.
Book a meeting