by Joshua Shale
This is Part 2 of a four-part series on the trends shaping identity management and data in 2026. We reviewed more than a dozen industry reports — from IAM vendors and security analysts to data platform leaders like IBM and Accenture — looking for patterns that showed up again and again, not just within one industry, but across both. Each post in this series covers one of those shared trends and explains why it matters for your business.
Governance used to be a document nobody read until an auditor asked for it. Not anymore. Across both identity and data, regulators are turning governance into an operational requirement, and the penalties for skipping it are getting real.
• The EU AI Act reaches full effect on August 2, 2026, with fines up to €35 million or 7% of global revenue. That single deadline is reshaping how companies handle both the data feeding their AI systems and the identities of everyone (and everything) accessing them. It’s one of several new rules — alongside a growing patchwork of U.S. state privacy laws and Canada’s AI and Data Act — pushing governance from a “nice to have” to a legal necessity.
• Consumers and regulators are demanding ownership over personal data, and identity systems are being redesigned around it. Frameworks like GDPR and CCPA, plus the rapid global spread of open banking rules (now adopted in more than 75 countries), are pushing organizations toward identity models that give individuals more control over their own credentials and data, rather than locking everything inside a company’s own systems.
• Most organizations say governance matters, but few can prove it. Industry surveys find that only about 15% of companies have mature data governance, and just 4% are strong in both data governance and AI governance at the same time. The gap between what companies say and what they can actually demonstrate is exactly what regulators — and auditors — are starting to probe.
• The cost of skipping governance is now measurable, not theoretical. Analysts project that a significant share of AI projects will be abandoned in the next year due to poor data quality and weak governance, while identity-related fraud — including deepfake scams and fraudulent hiring schemes — has already cost individual companies tens of millions of dollars. Governance failures aren’t just compliance risk anymore; they’re a direct hit to the bottom line.
The takeaway: Whether it’s data governance or identity governance, 2026 is the year regulators stop accepting good intentions and start expecting proof. Building governance into everyday operations, not just policy binders, is becoming the price of doing business.