75/25: The Quarter That Won't Automate
AI is automating the productized three-quarters of identity work and barely touching the operational quarter — the one with no owner. It doesn't pave the last mile. It lengthens it.
In the last piece I argued that identity breaks in a mile of work no one owns. The obvious hope is that AI will pave that mile. It won't. It will make it longer — and this post is about why.
The claim
Identity work splits, roughly, into two parts. One part is productized: deploying the provider, wiring the integrations, configuring policy, writing the connectors, provisioning the accounts. It is well-specified, repeatable, and shaped like code. Call it three-quarters of the visible effort — 75, if you want a number, though the exact figure isn't the point. The other part is operational: keeping posture under control across every system, every day, forever — the contextual, judgment-laden, cross-system, accountable work. Call it the 25.
AI is devouring the 75 and barely touching the 25. The deployable, repeatable work is exactly what large models are best at, and it is getting cheap and fast in front of our eyes. The operational quarter resists, because it is messy, per-client, and — the part that matters most — accountable. So the ratio is inverting: the productized share collapses toward automation, and what's left for humans to actually own is, increasingly, just the 25. And the 25 is precisely the part that already had no owner. That is the whole argument. AI doesn't close the last mile. It strips away everything around it until the ownerless quarter is most of what remains.
Why now
Look at what AI is good at and you'll see why it eats the 75 first. Generating a connector, standing up an identity provider, mapping a schema, scaffolding conditional-access policy, writing the provisioning script — these are bounded, specified, code-shaped tasks, and they are getting automated at a pace that would have sounded absurd a couple of years ago. The day-1 deployment of identity is on its way to being nearly free.
The day-2 operation isn't, because it's a different kind of work. "Is MFA actually enforced on every account right now, including the legacy tenant someone spun up last week" is not a code-shaped question; it's a continuous, contextual judgment that spans systems no single tool owns. You can automate pieces of it, but you cannot hand the responsibility for it to a script and walk away — and that responsibility is the expensive part.
And here is the twist that makes the timing sharp rather than gradual: AI doesn't just fail to shrink the operational quarter — it actively grows it. Every AI tool and agent connected to a system is a new non-human identity holding a standing grant, handed out faster than anyone governs it. The automation is manufacturing exactly the kind of day-2 burden it can't absorb. We watched a forgotten OAuth token to an AI tool become the way into a major platform; that is not an edge case, it is the leading edge.
The evidence
I don't have to argue this prospectively, because the shift is already visible in the incidents I've been documenting. The earliest ones in the archive are about human credentials — phished passwords, replayed sessions, fatigued MFA. The most recent ones are about machine identities and OAuth grants: a stolen integration token reaching seven hundred companies, an unenforced setting across customer accounts, an AI tool's leftover authorization. The center of gravity has moved from "a person was fooled" to "a non-human identity was never governed." That move is the 75/25 inversion happening in real time: the human-authentication problem we spent a decade productizing is fading, and the machine-identity governance problem — pure day-2, pure operational quarter — is what's left, and growing.
To be honest about the numbers: I'm using 75/25 as a way to picture a direction, not as a measured statistic. I don't know the true ratio and neither does anyone else. What I'm confident about is the vector — automation pulls value and effort out of the productized side and concentrates both risk and remaining human work in the operational side. The arrow, not the fraction, is the claim.
The objection
The strongest counter is the one everyone reaches for: you're underestimating AI. It won't stop at the deployable 75. Agents will run identity operations too — enforce posture, review grants, rotate secrets, watch the estate. The operational quarter automates next.
Some of it will, and that's good — I want the tasks automated. But this confuses automating the work with supplying an owner, and the last mile is an ownership problem, not a labor problem. Three things follow that the optimistic version skips.
First, an agent that runs identity operations is itself a non-human identity with broad, standing access to everything it manages — which means you've added one more powerful machine identity to the population you already can't govern. The automation arrives carrying exactly the risk it's meant to reduce. Second, when an automated control fails — and controls fail — someone is still accountable for the breach. Automation relocates the work; it does not relocate the responsibility, because responsibility is assigned, not coded. "The agent was supposed to enforce that" is not a thing you can tell a regulator, a customer, or yourself. Third, deciding what the agents should do — which posture to hold, which exceptions are acceptable, what "under control" means for this specific client — is judgment that has to be owned by someone who is answerable for the outcome. You can automate the enforcement. You cannot automate being the one who is accountable when it's wrong.
So automation without an owner of accountability isn't a solution to the last mile. It is a new, faster-moving layer of it.
What follows
If AI commoditizes the productized 75, then the economic center of identity moves. The deployable layer gets cheap, which means its value falls — anyone can stand up the stack. The scarce, valuable, and dangerous thing becomes owning the operational quarter: holding posture, governing the exploding population of non-human identities, and being accountable for the outcome across an estate that no longer fits in anyone's head. As AI advances, the operator who genuinely owns the mile becomes more valuable, not less, because the part they own is the part that didn't automate and the part where everything now breaks.
The practical implication for anyone running identity is to stop budgeting as though AI shrinks the identity problem. It shrinks the deployment problem and grows the ownership problem. Plan for governance of machine identities as a first-class, continuous function. Assume the agents and tools you're adding are new identities to be inventoried and watched, not just productivity. And put a name — a human, accountable name — on the question "who owns posture across all of this," because that question is the only part of identity that AI is guaranteed not to answer for you.
Where this is going
If the operational quarter is where the value and the risk now concentrate, the next question is unavoidable: who can actually own it? Not who should — who is structurally positioned to stand on that mile, across many clients, continuously, and be accountable for it. That's the next piece, and the answer is more specific, and more uncomfortable, than "the client should try harder."
The principles behind all of this are written down separately; the incidents keep proving them.