← Back to News

SailPoint (SAIL) Rides the Identity Security Wave as AI Agents Multiply

SailPoint (SAIL) Rides the Identity Security Wave as AI Agents Multiply

SailPoint (SAIL) stock rose close to 14% in one session, moving with other cyber names. Palo Alto Networks (PANW) climbed, and partner CrowdStrike (CRWD) rose about 14-15% the same day. The gains followed morning commentary tied to strong security demand.

Enterprise demand and the AI security tension

SailPoint (SAIL) sells to mid-to-large enterprise customers. This year many of those customers moved past pilots and trials toward much wider adoption planned for 2026. That creates a pull in two directions: enterprises want the speed and efficiency of AI, and they hold real worries about security, especially the security of agentic AI. The result is a "foot on the gas, foot on the brake" pattern in customer environments. They want to move fast, and they need to trust that proper security controls are in place. SailPoint (SAIL) positions itself as a large part of that answer.

The numbers

The company delivered 25% ARR growth, reaching $1.23 billion. SaaS ARR grew 36%. Several demand drivers stayed healthy. Security budgets have run through cycles over time but remain fairly strong. On top of that, AI initiative budgets are now being tapped to make sure AI gets deployed securely. Both sources feed money into these projects.

Growth is being driven by real spending, not just experiments. Customers are saying they must put security controls in place for the growth they are seeing in the market.

Human identities still matter

A big theme: the human identity problem is still not fully solved, even as attention shifts to non-human, agentic identities. Companies want to know all their non-human identities, what those identities can do, and whether there are signals to catch when they start to go wrong.

Two incidents show different risks. The Mythos moment a few months back was about how a bad actor could use a large language model to attack a company. The Hugging Face case was different: no bad actor was involved. Tools acting with good intent, the agents, were not guard-railed well and went off the rails. Both show that the lack of controls around agents today causes serious worry, and companies feel they must get positioned for it.

The AI-driven pipeline has more than doubled since the investor day less than three months ago.

Why humans stay central to agent security

Non-human identities and agents will outnumber human identities. That is either already true or fast becoming true at almost every company. But agents will be directed by humans for the foreseeable future. In the co-pilot style, an agent works directly alongside a person. Even in newer setups with digital workforces, swarms of agents working together, people still direct the work in an enterprise. If a bank wants a digital workforce to rethink its loan origination process, a person who owns that business process still sets the policies, the data that can be accessed, and the rules for what is appropriate.

So teams need to understand humans and their privileges - what they can access, and what data they can see or change - and then how that flows down to the agents. The volume of agents will greatly outnumber humans, yet humans stay a core part of the system. If you do not understand the human side, you will probably not be good at governing and securing the agentic side.

The CrowdStrike partnership and platform strategy

SailPoint (SAIL) expanded its partnership with CrowdStrike (CRWD), putting SailPoint identity intelligence directly into the SOC (security operations center). Security has been viewed for decades through separate lenses: the network, the device or endpoint, the cloud, mobile devices. Each of those subsegments has dominant vendors. Identity as an organizing principle for security is still a fairly new idea for many companies and vendors.

Firewalls, device security, and network security carry real value, but they are "identity blind." They see a threat or bad behavior, but they cannot tie it to an identity. When a signal of bad or threatening behavior appears, the key question is who or what is affected, and that needs identity context. This is where SailPoint (SAIL) fits. The other tools in the SOC need identity awareness to make good decisions about handling a threat as it unfolds. That gap is the main opening for partnership inside customer environments, and it points to SailPoint (SAIL) becoming part of the broader cybersecurity platform rather than a standalone identity product.

Comments