In the face of the rapid adoption of artificial intelligence agents, enterprise security is faced with an increased challenge, as organizations struggle to maintain an increasing number of non-human identities gaining access to sensitive information and critical systems. In an increasingly automated world, security experts warn that each new AI agent introduces another trusted identity into the organization.
The use of machine identities increases an organization's attack surface without proper oversight, making it harder for security teams to maintain a complete inventory of privileged accounts and monitor their interactions with critical business systems if they are not monitored properly. As opposed to human users, AI agents, service accounts, OAuth applications, and workload identities do not follow traditional employee lifecycles.
There are many advantages to generating them automatically, inheriting permissions, interacting across multiple systems, and often remaining active long after the applications that generated them cease to exist. In the opinion of security experts, this emerging ecosystem is leading to weaknesses in identity governance that many organizations have yet to address. According to the Non-Human Identity Management Group, machine identities outnumber human users by up to 50 to 1 in many enterprise environments.
Some of these technologies exist only temporarily, while others continue to operate without any clear ownership for years, making it difficult to determine who created them, what resources they are allowed access to, and whether they are still necessary for security teams to monitor. During a cyber campaign conducted in 2025, threat actor UNC6395 exploited a trusted OAuth token associated with Salesloft's Drift chat integration, demonstrating the risk.
Instead of exploiting a software vulnerability, the attackers exploited an already trustworthy machine identity in order to access AWS credentials, Snowflake tokens, and other sensitive data across Salesforce environments. The incident demonstrated how compromised machine identities can become gateways to broader enterprise cyberattacks. Security professionals emphasize that artificial intelligence itself is not creating new cybersecurity problems but rather accelerating existing ones.
With organizations deploying AI-powered agents to automate business processes, the number of privileged identities is continuing to increase, increasing the attack surface if governance processes do not keep pace. Additionally, experts maintain that AI agents are not simply software tools but should be regarded as a distinct class of digital identity instead.
With AI systems increasingly accessing enterprise applications, making decisions, and executing workflows independently, organizations must provide each AI agent with a unique identity, clear permissions, and full accountability in order to ensure that its actions can be monitored and audited.
The Netwrix Data and Identity Security Report 2026 reported that organizations with significant increases in the number of identities experienced a 43% breach rate over the previous year, compared to 11% among organizations with no significant changes in their identity landscape due to artificial intelligence. There is no doubt that visibility alone is not sufficient to address the concerns of many affected organizations, as they already invested in identity governance and monitoring.
There is also a growing concern regarding agent sprawl, in which organizations deploy artificial intelligence assistants and autonomous agents rapidly without establishing governance frameworks. As the number of machine identities within an organization increases, cybersecurity experts warn that this can cause duplicate AI agents, inconsistent permissions, and increased operational, security, and compliance risks.
As well as stressing the importance of identifying machine identities, the report stresses the imperative of continuous identity governance which tracks ownership, permissions, lifecycles, and access rights throughout the lifespan of every AI agent and non-human identity. The accumulative nature of trusted identities can increase the likelihood that unauthorized access and misuse can occur without ongoing governance. The following four key questions should be answered continuously by organizations for every identity in their environment: What identities exist?
Who owns them? What can they access? When should they be retired? Unless clear ownership and lifecycle management are in place, AI-driven identities may silently accumulate excessive privileges and provide an opportunity for attackers. Experts also recommend that AI agents be subject to the Zero Trust security principles.
The same way that human users require continuous verification and least privilege access, AI agents should be given only the appropriate permissions to accomplish their duties. Keeping detailed audit logs and implementing lifecycle controls (including the capability of quickly eradicating or retiring unnecessary agents) can reduce security risks over the long term.
A growing number of industries are adopting artificial intelligence, which requires cybersecurity strategies to evolve beyond traditional user-focused identity management strategies. It has been recommended that organizations establish stronger governance for non-human identities, identify an owner for each AI agent, and periodically review their permissions.
A lack of such controls could result in trusted AI-powered identities becoming one of the most overlooked attack vectors in today's enterprise environments, according to experts.
