The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that detects anomalous authentication and access patterns indicating compromised credentials or insider threats. Includes impossible travel detection and privilege escalation alerting; distinct from zero-trust policy enforcement which defines access rules rather than detecting violations.
Identity and access anomaly detection is a proven, operationally mature practice with persisting deployment challenges at scale. ML-driven behavioral analytics—flagging impossible travel, privilege escalation, and credential misuse—have been standard across major SIEM and identity platforms since the early 2020s, with recent Forrester TEI studies documenting ROI at 310% with 6-month payback periods. Hyperscale deployment validates the approach: Microsoft alone analyzes 38 million identity risk detections daily (2026), and tier-1 vendors (CrowdStrike, Palo Alto, Sentinel, Exabeam) ship mature anomaly detection as core capability. Yet organizational breach rates continue climbing (69% globally, 92% in Australia per RSA 2026), with Palo Alto Networks 2026 survey showing 9 of 10 organizations experienced identity-related breaches despite widespread UEBA availability, revealing the core tension: the practice's technology viability is settled; the question is operational adoption quality. Real-world barriers persist—false positive fatigue, tuning overhead, and critical coverage gaps for non-human identities that now vastly outnumber human users (machine identity ratios reaching 109:1 in typical enterprises). Organizations deploying identity-centric controls (behavioral anomaly detection + governance + response automation) show measurable improvement (Docker achieved 85% YoY false positive reduction through disciplined tuning; Exabeam customers report 50% investigation time savings); those deploying without sustained engineering investment face alert saturation that erodes SOC trust. The practice is firmly good-practice—capable and broadly available—but adoption velocity is constrained by operational execution, not technical readiness.
The vendor ecosystem has fully consolidated around platform-integrated behavioral analytics with accelerating non-human identity coverage through August 2026. CrowdStrike achieved ITDR Overall Leader status in KuppingerCole's 2025 Leadership Compass and Frost & Sullivan's Company of the Year (May 2026), validating cross-domain correlation (identity + endpoint + cloud + SaaS) as the standard detection architecture; independently, CrowdStrike demonstrated 100% detection and prevention capability in MITRE ATT&CK's 2025 Enterprise evaluation and maintains 4x year-over-year ARR growth (Falcon Shield) driven by non-human identity governance adoption. Exabeam extended Agent Behavior Analytics to Google Cloud (1,100+ deployments with 50% investigation time reduction, GA August 2026) and doubled agent detection patterns to 90 (July 2026), while Ping Identity GA-launched Identity for AI with runtime behavioral monitoring for autonomous agents (April 2026). LogRhythm-Exabeam merger (finalized January 2026) consolidated SIEM with AI-driven behavioral analytics; Microsoft Sentinel UEBA behavior layer (GA January 2026), Entity Analyzer (GA April 2026), and Defender for Cloud Apps anomaly detection (GA August 2026) introduced explainable AI-driven identity risk analysis with ML-based false positive suppression. Splunk Enterprise Security 8.6.0 (GA July 2026) added UEBA Content App for Cloud with cloud-specific detection capabilities. CrowdStrike extended Falcon Identity Protection to Microsoft Entra ID (May 2026). Market consolidation: $25B Palo Alto/CyberArk, Okta/Axiom, Delinea/StrongDM deals (May 2026) all targeting unified identity threat detection and AI agent governance. Cloud Security Alliance published NHI governance framework (July 2026) establishing continuous anomaly detection baseline establishment for non-human identities distinct from human user patterns. Analyst frameworks evolved: Forrester elevated identity detection to a first-class detection surface in its Q2 2026 XDR Wave research, recognizing identity anomaly detection as essential for modern threat detection. Market momentum sustained: 95% of organizations plan increased cybersecurity budgets (74% double-digit growth), 44% driven by AI expansion; UEBA market forecast 47.2% CAGR (USD 4.35B 2025 → USD 65.1B 2032); ITDR market projected 25.17% CAGR (USD 3.42B 2026 → USD 10.51B 2031).
The capability-outcome gap persists despite operational maturity. RSA 2026 survey (2,100 professionals, June) shows 69% of organizations globally (92% in Australia) experienced identity breaches with 45% facing costs exceeding $10M—despite widespread UEBA availability. SANS 2026 ITDR survey reveals detection-response gap: 68% detect identity attacks within 24 hours but only 55% contain within 24 hours. Operational friction documented: Docker achieved 85% YoY false positive reduction after disciplined Okta/CloudTrail tuning, confirming that consistent engineering investment produces results but remains resource-intensive. Sophos survey (5,000 IT leaders, June 2026): 14% unable to detect/stop most significant identity breaches timely, with smaller organizations disproportionately affected. False positives remain a critical barrier: practitioners report 30-day baselines generating 200 daily anomalies with only 5 worth investigating, Microsoft's impossible travel detection triggers false alerts from Microsoft infrastructure, and analysts face choice between alert fatigue or detection gaps. Deployment practice maturity is increasing—Google Cloud published UEBA methodology guide (June 2026), Netwrix identified tuning and organizational ownership gaps as adoption barriers—but organizations continue deploying without discipline: Panther analysis (May 2026) found 42% of teams deploy UEBA without baseline tuning, leading to behavioral drift.
Non-human identity anomaly detection remains the acknowledged frontier, limited by governance architecture more than technology. Netwrix survey (June 2026): organizations where AI expanded identities experienced 43% breach rate versus 11% baseline, with 76% lacking visibility into non-human identities—quantifying the expansion-detection gap as AI agent adoption accelerates. Real incidents validate this gap: Tata Motors (2025) lost 70TB via hardcoded AWS credentials in application code; CDK Global suffered centralized IAM compromise through a single phished credential, taking 15,000 dealerships offline; Volkswagen Cariad exposed GPS locations of 800,000 EV owners through misconfigured cloud IAM policies—all cases where hardcoded or poorly governed non-human identities enabled at-scale compromise without behavioral anomaly detection triggering because the access patterns appeared legitimate. Orchid Security telemetry (April 2025–March 2026): 67% of non-human accounts created directly in applications (invisible to centralized IAM), 57% of enterprise identity invisible to IAM, 70% of applications overprivileged, 40% of accounts orphaned. Machine identities now outnumber humans 109:1 with only 12% automated lifecycle management (ManageEngine Q1 2026; Palo Alto Networks 2026 survey). Vendor frameworks announced at RSAC 2026 but gaps persist: dynamic scope creep, non-deterministic audit trails, cross-agent context poisoning, governance model misalignment. Cloud Security Alliance argues the architectural problem: machine identities operate as "autonomous trust executors"; single-token compromise cascades across systems differently than user compromise, requiring behavioral detection models fundamentally distinct from user-centric baselines. The practice's scaling barrier is organizational (governance, ownership, tuning discipline) more than technical (vendors ship mature, credible tools), but non-human identity anomaly detection remains structurally immature.
A critical detection blindspot emerged in June 2026: the Meta AI Support Bot case study demonstrated that authorized agent compromise is structurally invisible to behavioral anomaly detection. When HTS (the automated chatbot) was manipulated to reset 20,225+ Instagram passwords including accounts of Barack Obama and the US Space Force Chief Master Sergeant, the attack generated no anomalous login spikes, no behavioral deviations—from the detection layer's perspective, the HTS agent was an authorized actor executing legitimate password recovery operations. This exposure reveals that behavioral anomaly detection's foundational assumption—that deviations from normal behavior signal compromise—fails when legitimate actors (human or agent) become compromised or over-privileged. Vendor responses signal practice adaptation: Exabeam announced Agent Behavior Verification (ABV) extending anomaly detection upstream to pre-deployment verification of agent authorization scope; SANS analysis argues agents break existing detection models altogether (intent validation at execution layer, not behavioral baselines); Daylight AI documented a complementary structural limitation in human user anomaly detection itself—UEBA's false positive epidemic stems from class imbalance in model training (representing users by statistical mean rather than distribution), creating an actively unsolved research problem of simultaneous false positive/false negative reduction. These documented gaps—authorized agent blindspot, UEBA modeling class imbalance, behavioral signature ineffectiveness against agent-speed execution—position the practice at a critical juncture: technological maturity is unquestioned (68% of Fortune 1000 CISOs prioritize real-time identity revocation; market forecast 24.1% CAGR through 2034), but operational readiness for the AI-agent era remains contingent on architectural evolution beyond behavioral baselines.
— Analyst report on identity security adoption: Falcon Shield ARR grew 4x YoY; named healthcare customer deployed Falcon Next-Gen Identity and SGNL in seven-figure deal explicitly to control AI agent access—concrete evidence of non-human identity anomaly detection driving production deployment.
— Technical analysis identifying structural detection gaps: AI agents operate through legitimate identities and approved tools; risk develops through sequences of low-signal actions over time, not discrete violations; traditional rules and short correlation windows miss agent-specific behavior patterns.
— Ecosystem signal: Exabeam's behavioral analytics integrated into Google Security Operations addressing insider threat detection and AI agent anomaly detection gap; cloud-scale identity anomaly detection now embedded in major cloud vendor security platforms.
— Official Microsoft documentation of GA identity anomaly detection with ML-based false positive suppression, dynamic threat detection, 7-day learning baselines, and context-aware impossibile travel detection across 30+ risk indicators.
— Real-world UEBA deployment: Exabeam flagged anomalous behavior (malicious executables, C2 connections, VPN software) within 24 hours of infiltrator's first login, contained threat in 4-6 hours; demonstrates behavioral anomaly detection effectiveness on sophisticated insider threat bypassing static controls.
— Updated SaaS-focused technical case study documenting impossible travel detection challenges (VPN false positives, Microsoft infrastructure misclassification), production baseline approach using geographic clustering, and cross-service compromise detection with practical tuning guidance for enterprise deployments.
— CSA working group guidance establishing NHI-specific anomaly detection: continuous discovery, identity graphs, real-time behavioral baselines adapted to machine identities (not human travel/login patterns); phased implementation from discovery to automation to optimization.
— Major vendor GA release: new UEBA Content App for Cloud, AI-powered detection builder, entity risk scoring, and SOAR integration demonstrates production-scale behavioral analytics for identity and entity anomaly detection at enterprise scale.