AI agents are rapidly spawning non‑human identities, leaving organizations unsure about what exists, who owns it, and what data it can access. Netwrix explains why this growing identity footprint widens the security gap and why continuous visibility and governance are now essential.

Key Takeaways

  • Machine identities now outnumber human users up to 50:1 in many enterprises.
  • AI agents automatically create and inherit permissions, expanding the attack surface.
  • Continuous visibility, clear ownership, and lifecycle management are vital for effective identity security.

AI agents have fundamentally reshaped the identity management landscape. Forty‑four years after Blade Runner imagined replicants walking among us, today’s enterprises host more machine identities—service accounts, OAuth apps, workload identities—than human users. This shift not only adds technical complexity but also renders traditional human‑centric identity governance obsolete.

Background and Existing Gap

Traditional identity security was built around predictable human behavior: employees join, change roles, take vacations, and eventually leave. These lifecycle events formed the backbone of access reviews and permission revocation. Machine identities rarely follow this pattern; they can be spawned in seconds, linger for years, and often lack an obvious owner. According to the Non‑Human Identity Management Group, many environments now see a 50 to 1 ratio of machine to human accounts.

AI‑Driven Expansion Risks

In 2025, threat actor UNC6395 compromised an OAuth token linked to Salesloft’s Drift chat integration and used it to traverse Salesforce environments across hundreds of organizations. The token itself was not vulnerable; it was already trusted. From there, attackers harvested AWS credentials, Snowflake tokens, and other secrets. A single trusted machine identity became the gateway to many more. AI agents do not create this problem—they accelerate it. When organizations deploy AI agents that automatically generate identities, inherit permissions, and operate at machine speed, the lack of visibility turns these trusted credentials into a silent expansion of the attack surface.

Visibility Alone Is Not Enough

Netwrix’s 2026 Data and Identity Security Report found that organizations where AI significantly increased the number of identities reported a 43 % breach rate in the prior year, compared with only 11 % where AI had little impact on identity footprints. The surprising insight was not the breach rate itself but who got breached. Even organizations with relatively strong governance—monitoring shadow AI, governing non‑human identities, and maintaining continuous data visibility—still suffered breaches.

Strategic Recommendations

Security teams need continuous answers to four core questions: What identities exist? Who owns them? What can they access? When should they be retired? Without these answers, every new AI deployment quietly adds trusted identities, expanding risk. Netwrix’s AI Maturity Assessment benchmarks an organization’s identity, data, and AI governance, highlights blind spots, and delivers actionable recommendations to reduce AI‑related risk.