Skip to content
← Insights Hub
Cybersecurity4 min read

Securing Non-Human Identities: The New Perimeter

Machine and AI-agent identities outnumber humans by a median 45 to 1, yet 92% say legacy IAM can't manage them. Here's how to bring non-human identities under control in 2026.

Securing Non-Human Identities: The New Perimeter

Most security programmes were built around a single, unspoken assumption: the thing logging in is a person. In 2026 that assumption quietly broke. AI agents now authenticate, hold API keys, read databases, and act on a customer's behalf — with no face, no laptop, and no working day. They join the service accounts, workload identities, and machine credentials that were already there, and together these non-human identities now outnumber human users by a median of 45 to 1 — up from 17:1 in 2023. Some 2026 datasets put it far higher still: an average of 109:1, and approaching 500:1 in estates heavy with cloud-native and AI workloads. That is the new perimeter, and for most organisations it is almost entirely ungoverned.

Why this is suddenly urgent

Two things changed at once: the number of non-human identities exploded, and the autonomy of some of them (AI agents) went up. AI agents are the accelerant — they already account for roughly 72% of machine identities, and agent identities are forecast to grow a further 85% over the next 12 months, outpacing machine identities overall (+77%) and human ones (+56%). The result is a governance vacuum:

  • 92% say their legacy IAM tooling cannot manage AI and non-human identity risk.
  • Only 28% can trace an agent's actions back to a human sponsor across all environments.
  • 78% have no documented policy for creating or removing AI identities — and about half report no clear ownership or accountability for agent identities at all.

An attacker doesn't need to phish a human if a workload's long-lived API key is sitting in a config file, or if an over-permissioned agent can be nudged into doing something it shouldn't. This is the same lesson as identity-first security — that the modern breach is an abused identity, not a breached firewall — extended to the identities that now do most of the work.

What "good" looks like in 2026

You don't fix this by buying one product. You give every non-human identity the same lifecycle you already give an employee — created, owned, scoped, reviewed, retired:

The lifecycle a non-human identity needs: it is created, given a named human owner, scoped to least privilege with a short-lived credential, then reviewed on a recurring basis and revoked or allowed to expire. Identities with no owner and no expiry are where risk concentrates.CreatedOwner assigneda named humanScopedleast privilege, short-livedReviewedrevoked, or expiresrecurring reviewAn identity with no owner and no expiry is where the risk concentrates — you cannot review what nobody owns.

Concretely, that is four moves:

  • Inventory first. You cannot protect identities you cannot see. Discover every non-human identity across your estate, and give each one a human owner. Unknown and orphaned identities are where the risk concentrates.
  • Kill standing secrets. Long-lived API keys and static credentials are the liability. The industry is moving to short-lived, cryptographic identities (frameworks like SPIFFE and OIDC) — tokens that exist only for the duration of a specific task and then expire.
  • Move to intent-based access. The old question was "is this identity allowed?" The 2026 question is contextual: "is this agent, acting for this user, allowed to do this specific thing, right now?" Authorise the action in context, not just the identity — a natural extension of zero-trust's "verify explicitly" to non-human actors.
  • Govern the lifecycle. Every non-human identity needs an owner, a lifecycle, and periodic access reviews — exactly like an employee. No identity should outlive its purpose or accumulate access unchecked.

Start where the risk is

You don't have to boil the ocean. Start by finding the identities you don't know about — the orphaned service accounts, the shared keys, the agents someone stood up for a project and forgot. Then apply least privilege and short-lived credentials to your most sensitive systems first, and put an owner against every one. It's the same order-of-impact approach that makes zero-trust affordable for the mid-market: secure the crown jewels first, then extend the pattern.

The bottom line

The perimeter didn't disappear — it multiplied and went non-human. AI agents and machine identities are now the majority of "users" in your environment, and they're the ones most likely to be over-permissioned, unmonitored, and unowned. Treating them with the same rigour you give people — inventory, ownership, least privilege, short-lived credentials, and access reviews — is the defining identity task of 2026, and it's central to our cybersecurity and resilience work.

Not sure how many non-human identities are in your estate — or who owns them? Let's find out.

Free guide
Zero-Trust Readiness for the Mid-Market

Adopt zero-trust in order of impact, on a real budget, using the Microsoft security tools you likely already own.

Download the PDF →

Have a similar challenge? Talk to us.