What’s next in IAM? From the EIC 2026 conference floor to practical reality

Intro: EIC signals for what might be next in IAM

EIC 2026 is behind us and we are still buzzing from the conversations, inspiration, explorations and presentations. Many moments, meetups and memorable knowledge sharing made our IAM hearts beat a bit faster. We reflected and did our best to move our conference floor takeaways into what organisations can practically do with this right now.

Much of our EIC nuggets sat in between and around the formal programming. The latter (keynotes, panels, vendor presentations, technical deep dives, roadmaps and sessions) typically shows where our field is placing its attention. The first (conversations, meetups, exchanges ‘behind the scenes’) places that more in the context of practical realities.

One theme in our reflections is that the next phase of IAM is driven by technological development and innovation as much as it is defined by how well we organise everything – governance, standards and communication protocols, policies, security, use cases – around the technology.

Innovation and developments move fast, specifically around AI, and present questions that do not all have answers yet. Navigating those double clicks the importance of being clear on knowing who (and what) has access to what, why, and how. It also underscores the usefulness of visibility, ownership, governance, and an operating model sturdy enough for control and flexible enough to adapt as the landscape continues to change.

A note on the perspective: With Henk Marsman and André Koot on the ground (do take a look at their LinkedIn for their daily EIC diary notes!), this recap naturally reflects the sessions, conversations and themes they chose to explore and attend, shaped by their expertise in digital identity, wallets, ethics, access management, non-human identities, business alignment, and all things access control and governance.

Our three main EIC signals

AI Agents are changing the way we look at access questions

Roughly 20 years ago we saw one of the larger turning points in IAM. In reflecting on our EIC experience we realised the shift around AI in IAM now feels in some ways similar.

Back then, we needed better ways to manage digital identity and access across growing numbers of users, systems and applications. Around that time, we started to see the Laws of Identity, federation and protocols such as OAuth, access models such as RBAC, and early IGA tooling. Even the ABAC concepts were born at that time. The years since were largely about improving, implementing and automating those.

AI brings a new set of challenges. This time around a new actor operating in and around our environments. AI agents are not a regular employee and they don’t originate from a single HR identity source. They may act autonomously on delegation from a person or another agent and may access data through paths outside traditional controls. This asks us to consider new questions also: why does this identity need access to this resource, why does it want to perform this task, and how can we manage that?

Much of EIC focused on actively exploring this and working its way through blind spots, considering guardrails, policy models, protocol flows, traceability and “on behalf of” and intent concepts as potential and partial pieces of answers that we do not yet have. We also saw some promising developments in protocol development, for instance the AuthZen working group winning an EIC award, and, more strategically, in ways of thinking about AI governance for which Patrick Parker (EmpowerID) came up with a first draft of his laws of AIdentity.

However, consensus was also that we cannot afford to wait for answers to settle before moving. Developments move quickly and AI solutions are already entering orgs through employees and experiments (and shadow AI), before governance and policy are ready.

Digital wallets are moving from promise to practice

EIC presented a lot of movement around digital wallets. We talked EUDI Wallets, eIDAS, verifiable credentials, signing, identity binding and wallet-provider business models, and noticed conversations becoming less promise and more practical. Pilots, use cases and technical implementations are starting to show how wallets may work at scale.

Two examples: SURF’s eduwallet initiative brings wallets into education and research, with practical use cases, a PoC, and work on risks and conditions for safe adoption, and Germany’s SPRIND-led EUDI Wallet work points towards open, prototype-driven development to test solutions for the future German wallet ecosystem.

Questions floating around EIC were about making wallets work in practice, designing for inclusivity and public values, and building trusted, sustainable business models. Conversations explored how to reliably connect identity to a user, device or credential, and prevent over-dependency on specific providers. Discussions focused on country and sector readiness, assurance frameworks and certification schemes, security standards, key management and identity binding, or looked at human-centred design.

This is exciting, because it signals that legal, technical, organisational, and human perspectives are coming together in a combination that creates space for digital identity and wallet solutions to not just be useful and secure but also lasting and manageable.

Sovereignty, values, and geopolitics in identity conversations more directly

Something that set EIC 2026 apart from previous editions for us was discussions around identity systems, public values, vendor dependency and autonomy being about more directly than technical features and capabilities. This surfaced for example in conversations around safeguards for systems carrying identity information to ensure they continue to be used for their intended purposes when political, legal or commercial interests change. Important considerations given that such systems hold information about people, organisations, credentials and access, potentially also about behaviours, and increasingly support critical societal and organisational continuity.

We also saw this in conversations around alternatives to big tech, Europe-based services, open source and sovereignty. One example is that all EU-based vendors we encountered made an explicit mention in some way shape or form to sovereignty, autonomy. Another is that organisations investigating alternatives along those lines seem to now look further than the place a service or vendor is located or hosted, and include ownership, applicable jurisdiction, and the amount of acceptable dependency.

Questions in support of next steps

Bringing the conference floor into organisational reality sits in asking the right kind of questions. Questions that help to understand which developments are relevant now and how, where IAM maturity stands and what it needs to absorb those developments, and what to build first before adding something new.

  • IAM hygiene and maturity: on the top of the list remains the basic IAM hygiene question: do you see and know who (and what) has access to what, how, and why?

  • Inventory AI and AI Agents: then, for AI agents, consider if you know where and how they are being used, formally and informally and a central place to inventory.

  • Beyond the technical: ask how ownership, governance and the operating model around identities and access is organised, in general and specifically for agents, prompts, policies, security rules and decisions.

  • A strong IAM setup: see where your IAM basics need strengthening first before adding on top. Evaluate your IAM setup and vendor strategy against dependencies – if you ever had to pivot fast, would your IAM help you do so or would it slow you down?

  • Partnerships that help you grow: for new solutions and tools, critically question the actual problems they solve, what policies and protocols they support, what assumptions they make, and what blind spots they leave.

Conclusion

EIC showed what might be next for IAM. Our field is moving quickly and our most immediate EIC signals are in AI and non-human identities changing access questions, in digital wallets moving from promise into practical implementation, and in conversations around identity decisions increasingly moving beyond technical considerations and features.

For us, our broader take away from that is practical and grounded: as new developments accelerate, IAM basics and IAM maturity continues to matter greatly. Strong foundations, interoperable architectures, and continued knowledge exchange all help organisations navigate what might be next without losing visibility, ownership or governance along the way.

That last bit is important. In a fast moving field no single expert, vendor, or organisation typically has the full picture. Platforms for open discussion, exchange and assumption and concept testing like IDPro and OpenID Foundation and, in the Netherlands, PviB help bring ideas, standards, research and practical experience together so we may turn them into knowledge we can all continue to build on.

It was an amazing week packed with inspiration, connections and knowledge sharing. Many thanks to all that were part of it!

For organisations, the value now rests in translating EIC signals into practicalities: what matters now, what maturity is needed, how to keep identity visible, governable and accountable as the landscape changes.

Footnotes and closing remarks

This article came together through the reflections of Henk Marsman and André Koot on EIC 2026

Further reading and more information

As SonicBee, we work with organisations to make identity, access and authorisation visible, governable and understandable. This strives to make overall operations smarter, more secure and more efficient. We do this through business-driven advisory, practical delivery, close partnership and a strong security lens.