What do you have to lose?
- Ajit Gupta

- Jul 1
- 4 min read

For one bank, the answer starts with more than USD 15 million in five year software licensing savings. That is before the cost of running a simpler stack, before reduced operational overhead, and before the strategic value of growing a digital business without being penalised for every new customer, transaction, environment, or channel.
For years, enterprises treated CIAM as a premium software category. That made sense when the market was less mature, open source was harder to operationalise, and banks needed proven platforms for authentication, registration, session management, federation, consent, API access, and high availability at scale.
The market has changed.
We are now seeing this across multiple banks: active migrations and live RFPs where organisations are moving from leading commercial CIAM platforms to Red Hat build of Keycloak. That distinction matters. This is not a move from enterprise software to unsupported open source. It is a move to an enterprise supported Keycloak platform, backed by Red Hat, combined with Midships engineering and our accelerator for regulated CIAM migration.
The important point is not simply that banks are moving to Keycloak. It is that they are doing it without accepting a lower enterprise standard. With the Midships accelerator, banks and regulated enterprises can target the same outcomes expected from a leading commercial platform:
Zero downtime architecture
Headless customer journeys
High availability across critical channels
Migration without business disruption
Strong DevSecOps and automated deployment
Modern authentication and federation
Enterprise support through Red Hat
A simpler operating model, not a weaker one.
This is not a theoretical open source discussion. It is already happening in the market, and the financial case is hard to ignore. One bank expects to save more than USD 15 million over five years on software licensing alone.
The licence saving is only the beginning. A simpler Keycloak based stack is easier to operate, easier to train teams on, and easier to resource. Engineers who understand Keycloak, Kubernetes, pipelines, APIs, configuration as code, and cloud native platforms are easier to find than specialists in a single proprietary product.
The long term cost of enterprise software was never just the licence. It was the training burden, the dependency on a small pool of expensive specialists, the time required to make change, and the commercial friction every time the business wanted to scale.
AI led SDLC sharpens this further. The future operating model will not need large teams of niche platform specialists making every change by hand. It will need strong engineering patterns, automation, governance, reusable accelerators, and AI supported delivery. That is where the economics become very different.
Most banks are trying to grow digital adoption, improve onboarding, expand self service, reduce fraud, and launch new products. Yet the CIAM commercial model often works against that strategy. More users, more transactions, more environments, more cost.
At some point, the identity platform stops supporting digital growth and starts taxing it.
This is where commoditisation matters. Commoditisation does not mean the problem is simple. CIAM is still complex, banking identity is still high risk, and migration still demands serious engineering discipline. Security, resilience, auditability, and customer experience still matter. But it does mean enterprises should challenge whether they still need to pay premium licensing for capabilities that can now be delivered through a more open, enterprise-supported, and operationally efficient model.
The question is no longer commercial CIAM or unacceptable risk. It is what architecture, operating model, support model, and commercial model are right for the next five years of digital growth. For many organisations, that answer will increasingly include Red Hat build of Keycloak.
There is a further question coming. As enterprises move from traditional applications to AI agents and autonomous workflows, identity alone will not be enough. They will need runtime governance: purpose control, auditable action boundaries, and assurance that AI-driven actions stay within approved business intent. That is why this architecture comes ready to integrate with agentic AI runtime governance frameworks and products, such as Icebreaker.
CIAM, Keycloak, and AI runtime governance are not separate conversations. They are part of the same future architecture for secure digital business.
For banks, insurers, telcos, and large enterprises, this is not only a technology question. It is a question of margin, scalability, talent, vendor dependency, supportability, and governance. It is a question of whether your identity architecture supports business growth or quietly taxes it.
At Midships, we have spent years delivering complex CIAM programmes for large enterprises. We understand the commercial platforms, the operational realities, and the risk of migration. We know why boards, CIOs, CISOs, and digital leaders cannot afford disruption in customer identity. That is exactly why we built our accelerator. Not to make CIAM cheap, but to make enterprise-grade CIAM more efficient, more portable, more scalable, more governable, and more commercially sustainable.
We will be at KeycloakCon Japan in Yokohama on 28 July 2026. If you are looking at CIAM cost, Keycloak, migration risk, vendor dependency, enterprise support, AI runtime governance, or the future economics of digital identity, come and speak to us.
For one bank, doing nothing was the most expensive option on the table.
Writer’s Overview
Ajit Gupta – Co-Founder & CEO, Midships
Ajit leads Midships Group’s transition from a specialist identity consultancy to a portfolio of autonomous, AI-native business units. He focuses on long-term business relevance through platform thinking, customer outcomes, and scalable operating models.
Short bio: Ajit is a strategic founder with deep expertise in IAM, platform delivery, and AI services, driving Midships’ expansion across Asia, the Middle East, and beyond.


Comments