Cybersecurity cybercrime internet scam business, Cyber security platform privacy protection 3D AI robot safety icon, Identity Programs, computer virus attack defense, identity privacy data hacking protection firewall

target readers-cv

By Patricia Titus

Machine identities now vastly outnumber and outrank human ones in most enterprises, yet almost none of them are governed.

Machine identities, including APIs, service accounts, tokens, and now AI agents, have quietly become the most powerful actors in the enterprise. Research estimates organisations now manage more than 100 machine identities for every human on. Most security programs still aren’t built to govern them. Patricia Titus, Field CISO at Abnormal AI, argues this isn’t a tooling gap. It’s a governance failure.

For years, identity security has been built around people. Logins, MFA, lifecycle reviews, least privilege, all designed to answer one question: does this person have the right access? But now, that question no longer covers most of what’s really operating inside the enterprise.

Machine identities, APIs, service accounts, tokens, and most recently AI agents, have overtaken human ones by a wide margin. Palo Alto Networks 2026 Identity Security Landscape report, based on a survey of nearly 3,000 cybersecurity decision-makers, puts the ratio at 109 machine identities for every human one, up from 82:1 just a year earlier. Of those 109, roughly 79 are AI agents.  AI agents alone now make up almost three-quarters of the machine identity population, not API keys and service accounts.

The scale is only part of the story, however the bigger issue is authority.

A CFO can approve a payment, while an API can approve millions. An employee might access one database, but an AI agent can rapidly sweep dozens.

These identities don’t log in, so there’s no login to flag. They don’t trigger MFA, so there’s nothing to challenge. When one is compromised, an attacker doesn’t break in. They execute quietly, programmatically, and at scale, often without tripping a single alert built for human behaviour.

Why identity programs weren’t built for this

This gap is the result of decades spent designing identity governance around interactive users. Every framework, every lifecycle control, every access review assumes a human is on the other end, someone who logs in, gets challenged, and can be held accountable.

Machine identities were never built into that model. They were treated as infrastructure, plumbing to keep systems talking to each other, rather than as identities in their own right. Nobody assigned them the same scrutiny because nobody expected them to hold the same power.

The consequences of that oversight show up everywhere once you look for them. Ask most enterprises who owns an API key, and what it can access, and the answer is often silence. Environments are full of orphaned service accounts, undocumented integrations and third-party connections nobody remembers approving. Only 37% of organisations can revoke an AI agent’s credentials on demand, and only 30%  have immutable audit logging for what those agents actually do once they’re running.

It’s a governance failure more than a tooling gap, and systems were missing a whole category rather than any specific category. Until machine identities are governed with the same rigour as human ones, that blind spot will keep growing.

How AI has accelerated the problem

If machine identities were already outpacing governance, AI has widened the gap further and faster than almost anyone predicted. AI agents don’t just call APIs the way a traditional integration might. They chain them together, pulling data from one system, triggering a workflow in another, and making decisions across several more, often with limited human oversight at any single step.

Each of those interactions expands the attack surface. Compromise a single API credential sitting in a CI/CD pipeline, and an attacker doesn’t need to phish anyone or trigger a login alert. They can move directly into production, pivot through trusted connections, and operate under the cover of what looks like legitimate traffic.

This is what makes the current moment different from the machine identity sprawl of a few years ago. The risk isn’t new, but what’s really changed is the speed and privilege at which it now operates. Unit 42’s Incident Response Report found that AI-assisted attacks can move from initial access to exfiltration in 25 minutes.  An identity program that couldn’t fully account for static service accounts has no chance of accounting for an AI agent chaining a dozen actions together before anyone on the security team has finished their coffee.

What CISOs need to do about it

None of this calls for a clean-slate overhaul. It calls for a practical roadmap with several distinct steps:

  • Start with visibility. Before chasing perfection, map what machine identities actually exist across the environment. Most organisations can explain what an AI agent is for. Far fewer can say what it can access, how that access is limited, or when it gets revoked. Visibility comes first because you can’t govern what you can’t see.
  • Kill standing access. Static keys and long-lived tokens create permanent trust in an environment that demands continuous validation. Just-in-time access replaces that with short-lived, tightly scoped credentials, bound to a specific workload or transaction, that expire automatically after use. It doesn’t slow anything down. It just removes the permanent open door.
  • Embed governance in the dev workflow. Identity decisions get made every day in CI/CD pipelines, in how credentials are stored, how long they persist, how broadly they’re scoped. If governance sits outside that workflow, it will always lag behind it. Build it into the pipeline itself, and it stops being an afterthought.

Underpinning all three is a simple contrast. Human identity still gets logins, MFA, and manual review; machine identity often gets none of that. A person’s access is bounded and role-based; a machine’s is frequently broad and standing. When a human account is compromised, an anomalous login or behaviour usually raises an alert. When a machine identity is abused, nothing does.

CISOs don’t need to solve all of this at once. They need to start by prioritising the highest-risk identities first, and reduce standing privilege steadily over time. That’s progress. Perfection was never the bar.

Conclusion

With 79 of every 109 non-human identities now an AI agent, and only a third of organisations able to revoke one on demand, the exposure isn’t theoretical anymore.  It’s sitting in production today. The organisations that treat Machine identity with the same governance rigour as their people, visibility first, standing access second, workflow integration third, will be the ones still standing when the next credential gets compromised. The rest will find out the hard way that silence isn’t the same as security.

LEAVE A REPLY

Please enter your comment!
Please enter your name here