SANS survey finds machine identities surge as 76% of organisations report growth and Agentic AI exposes new governance gaps

SANS survey finds machine identities surge as 76% of organisations report growth and Agentic AI exposes new governance gaps

Research highlights widespread credential hygiene failures and emerging governance gap as Agentic AI enters enterprise environments.

The 2026 SANS Identity Threats & Defences Survey reveals that non-human and AI-driven identities are multiplying faster than organisations can secure them.

In a global survey of over 500 security professionals, SANS found that non-human identities (NHIs), such as service accounts, API keys, automation bots and workload identities, are now the fastest growing identity category, with three out of four organisations reporting growth.

The number of identities operating inside organisations has ‘quietly doubled or tripled’, not because of more employees, but because machine to machine processes now underpin core business operations.

Credential hygiene crisis in NHIs

Despite this rapid expansion, governance practices have not kept pace. Credential rotation remains a basic defence against long-term compromise, yet 92% of organisations fail to rotate machine credentials on a 90-day cycle, creating a ‘forever access’ problem.

The failure to rotate credentials often stems from ‘operational fear’. Changing machine credentials can break service accounts, causing downtime. This leads teams to prioritise system availability over credential hygiene – leaving high-privilege keys unchanged for months or years.

The challenge is also structural. Many organisations continue to rely on human centric processes, such as manual access reviews, ticket based provisioning, and periodic rotation, which don’t scale to environments with large volumes of continuously authenticating machine identities across cloud, DevOps and SaaS systems. While adoption of controls such as secrets vaults, automated rotation, and scoped least privilege access is increasing, scaling these measures to match the growth of non-human identities remains a key priority.

Agentic AI creating new governance gap

Alongside NHI growth, the survey identifies a second identity risk category – Agentic AI. Nearly three-quarters (74%) of organisations are deploying AI systems that require credentials and access permissions to operate autonomously. These autonomous actors often interact directly with critical infrastructure and data, effectively granting them privileged access across environments.

Unlike traditional NHIs, which follow fixed logic, Agentic AI interprets instructions and can take unpredictable, nondeterministic actions. In practice, an ungoverned AI agent behaves like an over privileged insider operating at machine speed, with the potential to escalate errors or hallucinate actions.

Yet governance remains minimal. No single safeguard (approvals, sandboxing, audit trails) is used by more than 40% of organisations, and 5% of security leaders don’t know whether Agentic AI is already active in their environment.

Summary of key statistics:
• 76% of organisations report growth in non-human identities
• 74% of organisations are already using AI agents or automations that require credentials, yet 5% of security leaders don’t know if Agentic AI is running in their environment
• 15% admit they don’t even know their machine credential rotation rate
• The majority (59%) rotate fewer than half of their NHI credentials quarterly

“Organisations are giving AI systems real decision making power faster than they’re building the governance to control it. We’ve already seen what happens when non-human identities scale without guardrails, and Agentic AI is moving even faster. The early signs of governance are encouraging – nearly four in ten organisations have now use human in-the-loop approvals for AI agent actions – but the real challenge is staying ahead of these systems as they shift from pilots to core operations,” said Richard Greene, Certified Instructor, SANS Institute.

Browse our latest issue

Intelligent CISO

View Magazine Archive