A production deployment that succeeds and is never looked at again, and a credential issued eighteen months ago that nobody has revoked: that is the ordinary texture of privileged access inside most companies. It is also, Art Gilliland argued when we spoke at Black Hat this week, the most underused dataset in the enterprise. Delinea's Iris AI already reads pieces of that texture well, scoring a session's risk while the session is underway and flagging an admin when something looks wrong.
The harder question is what the same data could say about the company as a whole.
Every Consequential Action Passes Through the Access Layer
A database query, a configuration change, none of it happens without a privileged credential somewhere in the chain. That is the argument for why identity security sits closer to the center of enterprise operations than most other security categories, and it is also why a company operating without governance over that layer is not managing risk so much as guessing at it.
Delinea's own research backs up how wide that guessing gap runs. In a March 2026 survey of over 2,000 IT decision-makers, 80 percent of organizations said they cannot always explain why a non-human identity performed a privileged action, a traceability gap the report ties to weak AI governance (Delinea, 2026). The same survey found 87 percent of respondents confident their identity security posture was ready for AI-driven automation, while 46 percent of those same respondents admitted their governance around AI systems was deficient (Delinea, 2026). "Agentic AI demands agentic security," Gilliland said of an earlier version of the same finding (Delinea, 2025).
Iris AI Scores Each Session Alone, Not Against the Pattern
Delinea's Iris AI evaluates access requests against behavior, device, location, and policy context, and adjusts risk scores as that context shifts in real time (Delinea, 2025). A companion auditing feature analyzes recorded sessions after the fact, generating a heatmap of risky commands so an analyst can skip the footage that does not matter and focus on the footage that does (SiliconANGLE, 2025). Delinea's own documentation describes the system as built to keep a human in the loop rather than to act on its own, evaluating each access request individually before a person reviews or overrides the outcome.
That is real sophistication, and it solves a genuine problem. It is also scoped entirely to the request or session in front of it. A system that flags one unusual session is different in kind from a system that could say a department's access requests have climbed thirty percent faster than its headcount over two quarters, or that five teams are all touching the same production database in ways procurement should know about before the next contract renewal. One is threat detection. The other is the same underlying data, asked a different question.
Delinea has spent five years building the plumbing for a question the rest of identity security has not answered yet.
Delinea Is Also Widening What the Log Records
Runtime authorization, which Delinea released on July 29 and demonstrated at Black Hat this week, evaluates individual actions inside a session rather than only the session itself, extending policy enforcement to database queries, Kubernetes commands, and calls to Model Context Protocol servers (Delinea, 2026). Every one of those actions becomes a new data point. The volume of behavioral telemetry Delinea can now collect is growing. The company's use of that telemetry beyond real-time enforcement remains the open question.
Prediction Asks a Company to Trust a Model Over a Rule
Moving from per-session risk scoring to cross-session pattern prediction is not a small step. A rule-based system can tell an auditor exactly why access was denied. A predictive system trained on months of behavioral data has to explain a probability instead of a policy, and that is a harder conversation with a regulator or a board. Delinea's own design choice, keeping a human in the loop on every authorization decision rather than automating the call outright, reads as a deliberate hedge against that exact liability question. The caution is reasonable. It is also the reason the predictive layer has not shipped yet, at Delinea or anywhere else in the category.
What Happens Next
Three questions worth tracking. Does Iris AI's roadmap move from per-session scoring toward pattern prediction across the organization, or does the human-in-the-loop design stay the permanent ceiling? Does a competitor get there first, given that Palo Alto Networks' new Idira platform already routes identity signals into a broader security operations product? And when a vendor does ship pattern-based prediction, will auditors accept a probabilistic access decision the way they have accepted a rule-based one, or does explainability set the ceiling on how far any of this can go?
Ask your identity security vendor one question before the next renewal: what happens to a privileged session's data six months after the session ends? If the honest answer is that it sits in an audit log until compliance needs it, you are paying for incident response. Five years of acquisitions have put Delinea closer than most of the category to the alternative, a vendor that can show you a pattern caught by comparing this quarter's access requests against the last four. Ask how close.
Ordman, Justin. "Delinea Report Finds 90% of Organizations Pressure Security Teams to Loosen Identity Controls for AI." Delinea, 18 Mar. 2026, https://delinea.com/news/delinea-report-finds-90-of-organizations-pressure-security-about-ai-governance.
Delinea. "Delinea Report Reveals Only 44% of Organizations Are Fully Equipped to Support Secure AI." GlobeNewswire, 3 Sept. 2025, https://www.globenewswire.com/news-release/2025/09/03/3143579/0/en/Delinea-Report-Reveals-Only-44-of-Organizations-Are-Fully-Equipped-to-Support-Secure-AI.html.
Delinea. "Delinea Iris AI: Practical AI for the Modern Enterprise." Delinea, 5 Aug. 2025, https://delinea.com/blog/iris-ai-practical-ai-for-the-modern-enterprise.
"Delinea Introduces Iris AI to Enhance Identity Security with Real-Time Access Control." SiliconANGLE, 5 Aug. 2025, https://siliconangle.com/2025/08/05/delinea-introduces-iris-ai-enhance-identity-security-real-time-access-control/.
Delinea. "Delinea Authorization Powered by Iris AI." Delinea, docs.delinea.com.
Delinea. "Delinea Delivers Runtime Authorization for AI Agents, the Only Platform to Enforce Policy on Actions Before They Execute." GlobeNewswire, 29 July 2026, https://www.globenewswire.com/news-release/2026/07/29/3335183/0/en/delinea-delivers-runtime-authorization-for-ai-agents-the-only-platform-to-enforce-policy-on-actions-before-they-execute.html.
