Search for Author, Title, Keyword
RESEARCH PAPER
Artificial Intelligence-Driven Continuous Identity Risk Assessment and Adaptive Access Control for Automated Cybersecurity
 
 
More details
Hide details
1
Head of Identity and Access Management, S&P Global, Raleigh, NC, United States
 
 
Submission date: 2026-01-31
 
 
Final revision date: 2026-04-30
 
 
Acceptance date: 2026-05-04
 
 
Online publication date: 2026-07-15
 
 
Publication date: 2026-08-12
 
 
Corresponding author
Karimulla Syed   

Head of Identity and Access Management, S&P Global, Raleigh, NC, United States
 
 
Applied Cybersecurity & Internet Governance 2026;5(2):176-200
 
KEYWORDS
TOPICS
ABSTRACT
Conventional Identity and Access Management (IAM) systems depend on static, rule-based policies that cannot adapt to the pace and sophistication of modern cyber threats. This paper presents an artificial intelligence (AI)-driven framework for continuous identity risk assessment and adaptive access control, integrating autoencoder-based anomaly detection, Bayesian probabilistic risk scoring, and a Q-learning reinforcement learning agent for real-time access policy adjustment. It is further augmented by graph-theoretic centrality analysis to elevate the risk priors of structurally privileged accounts within the enterprise permission network, ensuring that high-exposure identities receive proportionately heightened scrutiny. The framework is evaluated against a concretely defined three-rule static IAM baseline using logon event data drawn from the publicly available Computer Emergency Response Team (CERT) Insider Threat Dataset (release r4.2), a peer-reviewed benchmark published by Carnegie Mellon University’s Software Engineering Institute (SEI), where a stratified subsample of 5000 logon events (preserving the dataset’s empirically observed anomaly prevalence of approximately 3%) is partitioned using a 60/20/20 train/validation/test split, with all reported metrics computed exclusively on the held-out test set ($n = 1{,}000$ events). On the test set, the proposed framework achieves 95% classification accuracy against 85% for the static baseline, reduces the false-positive rate from 18% to 3%, lowers mean response latency from 45 s to 15 s, and attains a generalisation error of 6% under mild distributional shift, compared with 18% for the baseline, demonstrating that an integrated AI-driven IAM pipeline can substantially outperform static rule-based approaches under controlled benchmark conditions.
FUNDING
This research received no external funding.
CONFLICT OF INTEREST
No potential competing interest was reported by the author.
REFERENCES (26)
1.
A.G Femi, M Medugu, “ Enhancing adaptive cybersecurity risk management through AI-driven threat detection,” International Journal of Trendy Research in Engineering and Technology, vol. 9, no. 2, pp. 103–110, 2025, doi: 10.54473/IJTRET.2025.9210.
 
2.
R Nzeako, R.A Shittu, “ Leveraging AI for enhanced identity and access management in cloud-based systems to advance user authentication and access control,” World Journal of Advanced Research and Reviews, vol. 24, no. 3, pp. 1661–1674, 2024, doi: 10.30574/wjarr.2024.24.3.3501.
 
3.
D Simon. (2024). “ AI-augmented identity and access management (IAM) for cybersecurity.” [Online]. Available: https://www.researchgate.net/publication/390114040. [Accessed: Apr. 28, 2026].
 
4.
S Samant, P.K Goel, H Tyagi, “ Security fortifying critical infrastructure: AI-based identity and access management for industrial automation,” in AI Enhanced Cybersecurity. Hershey, PA: IGI Global, 2025, pp. 12–29, doi: 10.4018/979-8-3373-3241-3.ch021.
 
5.
R Hariharan, “ AI-driven identity and access management in enterprise systems,” International Journal of IoT, vol. 12, no. 3, pp. 110–120, 2025, doi: 10.55640/ijiot-05-01-05.
 
6.
M Hamalainen, Analysis of Artificial Intelligence in Cybersecurity Identity and Access Management: Potential for Disruptive Innovation. Master’s thesis, LUT University, Lappeenranta, Finland, 2024. [Online]. Available: https://lutpub.lut.fi/handle/10024/168740. [Accessed: Apr. 28, 2026 ].
 
7.
S Phanireddy, “ AI-driven identity access management (IAM), ” SSRN Preprint, 2021, doi: 10.2139/ssrn.5257695.
 
8.
M.T.H Sarker, M.S Rahman, “ Artificial intelligence enhanced identity and access management: Preventing unauthorized access in modern enterprises, ” SSRN Preprint, 2024, doi: 10.2139/ssrn.5050769.
 
9.
S Tiwari, “ AI-driven approaches for automating privileged access security: Opportunities and risks, ” SSRN Preprint, 2021, doi: 10.2139/ssrn.5259381.
 
10.
J.-S Lee, T.-H Chen, C.J Chew, P.Y Wang, Y.Y Fan, “ Unconsciously continuous authentication protocol in zero-trust architecture based on behavioural biometrics,” IEEE Transactions on Reliability, vol. 74, pp. 2591–2604, 2025, doi: 10.1109/TR.2025.3541224.
 
11.
S Mandru, “ How AI can improve identity verification and access control processes,” Journal of Artificial Intelligence and Cloud Computing, vol. 1, no. 4, pp. 56–65, 2022, doi: 10.47363/JAICC/2022(1)E101.
 
12.
K.R Muppa, “ Enhanced identity and access management with artificial intelligence: A strategic overview,” International Journal of Information Security and Cybercrime, vol. 13, no. 2, pp. 9–17, 2024, doi: 10.19107/IJISC.2024.02.01.
 
13.
S Vitla, “ The future of identity and access management: Leveraging AI for enhanced security and efficiency,” Journal of Computer Science and Technology Studies, vol. 7, no. 2, pp. 27–40, 2024, doi: 10.61925/jcsts.v7i2.298.
 
14.
Y Sharma, “ The role of AI & machine learning in identity governance,” International Journal of Computer Trends and Technology, vol. 73, no. 6, pp. 1–6, 2025, doi: 10.14445/22312803/IJCTT-V73I6P101.
 
15.
S Mandru and A Gunuganti, “ Compliance-driven identity and access management (IAM) in critical infrastructure,” in Proc. 2025 International Conference on Computational Engineering, Sensing Technology and Management (ICCETM), Sydney, Australia, 2025, pp. 1–6, doi: 10.1109/ICCETM66557.2025.11558087.
 
16.
M.A.A Jude, “ The role of AI in zero trust architecture: Automating identity verification and access control.” ResearchGate Preprint, 2025. [Preprint, publication status unconfirmed]. [Online]. Available: https://www.researchgate.net/publication/396922039. [Accessed: Apr. 28, 2026].
 
17.
A Wickramasinghe, “ An evaluation of big data-driven artificial intelligence algorithms for automated cybersecurity risk assessment and mitigation,” International Journal of Cybersecurity Risk Management, Forensics, and Compliance, 7(12), 1–15, 2023.
 
18.
G Sunkara, “ AI-driven cybersecurity: Advancing intelligent threat detection and adaptive network security in the era of sophisticated cyber attacks,” Well Testing Journal, vol. 31, no. 1, pp. 185–198, 2022. [Online]. Available: https://welltestingjournal.com/index.php/WT/article/view/226. [Accessed: Apr. 28, 2026].
 
19.
B Schölkopf, J.C Platt, J Shawe-Taylor, A.J Smola, R.C Williamson, “ Estimating the support of a high-dimensional distribution,” Neural Computation, vol. 13, no. 7, pp. 1443–1471, 2001, doi: 10.1162/089976601750264965.
 
20.
C.J.C.H Watkins, P Dayan, “ Q-learning,” Machine Learning, vol. 8, no. 3, pp. 279–292, 1992, doi: 10.1007/BF00992698.
 
21.
B Lindauer, Insider Threat Test Dataset. Pittsburgh, PA: Carnegie Mellon University, 2020.
 
22.
J Glasser, B Lindauer, “ Bridging the gap: A pragmatic approach to generating insider threat data,” in Proceedings 2013 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, 2013, pp. 98–104, doi: 10.1109/SPW.2013.37.
 
23.
Verizon. (2025). Data breach investigations report. Technical report. Basking Ridge, NJ: Verizon Communications. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/. [Accessed: Apr. 28, 2026].
 
24.
MITRE Corporation. (2024). Common vulnerabilities and exposures (CVE) database. [Online]. Available: https://cve.mitre.org/. [Accessed: Apr. 28, 2026].
 
25.
S Rehman, A Ali, “ AI-driven identity and access management: Enhancing authentication and authorisation security.” ResearchGate Preprint, 2024. [Preprint, publication status unconfirmed]. [Online]. Available: https://www.researchgate.net/publication/388525692. [Accessed: Apr. 28, 2026].
 
26.
J Vegas, C Llamas, “ Opportunities and challenges of artificial intelligence applied to identity and access management in industrial environments,” Future Internet, vol. 16, no. 12, Art. no. 469, 2024, doi: 10.3390/fi16120469.
 
 
CITATIONS (1):
1.
Introduction to Special Issue on Cybersecurity in Digital Systems: Emerging Trends, Models and Technologies
Joanna Kołodziej, Matteo Repetto
Applied Cybersecurity & Internet Governance
 
eISSN:2956-4395
ISSN:2956-3119
Journals System - logo
Scroll to top