
Machine Identities Outnumber Humans 82 to 1: The Breakdown of Human-First Identity Models
Active Directory, LDAP, and early PAM were originally designed for humans, not AI agents and machines. However, the landscape has shifted dramatically, with machines now outnumbering humans by 82 to 1. This rapid growth of machine identities is challenging the traditional human-first identity model at a pace that is difficult to keep up with.
AI agents are a prime example of this shift, as they are the fastest-growing and least-governed class of machine identities. These agents not only authenticate but also take action, leading to significant security risks. Companies like ServiceNow have already invested billions in security acquisitions, signaling a shift towards making identity the control plane for managing enterprise AI risk.
Research by CyberArk in 2025 confirms the staggering ratio of machine identities to human identities. With predictions from Gartner indicating that a quarter of enterprise breaches by 2028 will be linked to AI agent abuse, the urgency of addressing this issue is clear.
The Challenges of Legacy Architectures at Machine Scale
Legacy architectures struggle to handle the unique requirements of machine identities, leading to issues such as shadow agents and over-permissioned service accounts. Traditional IAM approaches designed for humans fall short in managing machine identities, posing significant risks to organizations.
The governance gap is evident, with a disconnect between the number of machine identities and the focus on human identities as privileged users. This discrepancy results in machine identities having higher rates of sensitive access than humans, creating potential vulnerabilities.
Visibility into machine identities is also lacking, with a significant portion operating outside security’s purview. This lack of oversight can compromise an organization’s security and integrity, highlighting the need for a cohesive machine IAM strategy.
The Rise of Agentic AI and Its Impact on Identity
The emergence of AI agents requiring their own credentials presents a new challenge for traditional systems. Agentic AI introduces a category of machine identity that legacy systems were not designed to handle, requiring meticulous scoping to adhere to the principle of least privilege.
Platforms that unify identity, endpoint, and cloud telemetry are becoming essential to detect and contain agent abuse in real time. Machine-to-machine interactions operate at a speed and scale that human governance models are ill-equipped to manage.
Addressing Dynamic Service Identity Shifts
Gartner suggests that dynamic service identities, defined as ephemeral, policy-driven credentials, are the way forward. Transitioning to dynamic service identities can reduce the attack surface and improve security posture, emphasizing just-in-time access and zero standing privileges.
Unified platforms that integrate identity, endpoint, and cloud security are crucial for detecting and mitigating agent abuse across the identity attack chain.
Practical Steps for Security and AI Builders
Security and AI builders can take several steps to address the challenges posed by machine identities:
-
Conduct a comprehensive discovery and audit of all accounts and credentials.
-
Build and manage agent inventory before production.
-
Transition to dynamic service identities and excel in managing them.
-
Implement just-in-time credentials and least-privilege defaults.
-
Establish auditable delegation chains and deploy continuous monitoring.
-
Evaluate posture management and enforce agent lifecycle management.
-
Prioritize unified platforms over point solutions.
Anticipating Future Challenges in Machine Identity Management
The gap between what AI builders deploy and what security teams can govern is expected to widen in 2026. Organizations must adapt to the changing landscape of machine identities to prevent security breaches and mitigate risks associated with the proliferation of machine-to-machine attacks.
By embracing dynamic service identities, just-in-time access, and zero standing privileges, organizations can strengthen their security posture and effectively manage the growing number of machine identities in the digital ecosystem.
It’s crucial to recognize that legacy identity security models are no longer sufficient in the face of evolving threats posed by machine identities. Embracing a proactive approach to identity management is key to safeguarding against the escalating challenges of machine identity management in the years to come.
