Non-human identities now outnumber humans 45 to 1 as a greatly expanded landscape incorporates OT devices like medical
equipment, IoT gear, and factory assets. These non-human identities, many ephemeral by design, are spun up and down at machine speed, provisioned programmatically, granted broad permissions, and rarely deprovisioned when work is done. They operate with access, permissions, and potential exposure, but do so under the radar of legacy identity tools.
The identity problem isn’t just the difference between managing humans vs. machines. It’s also about oversight of devices vs. systems. Legacy models were built on the assumption that identity is stable — a user, a role, a set of permissions reviewed on a quarterly cycle. But that’s not the case with non-human identities and AI agents. “They need to be treated as a first-class identity with its own lifecycle, least privilege model,
and behavioral monitoring,” Schroeder says. “This isn’t a modernization problem. The legacy model can’t be patched.”
Even when legacy platforms can keep track of identities and highlight risks, it’s difficult to understand what particular cyber asset is affected,
the services that might be impacted, or how extensive the damage will be. There’s no intelligence on how and why a particular identity risk
matters to business operations, which undermines any ability to respond efficiently and effectively. Permissions pile up, dormant accounts
stay active, and ungoverned identities quietly accumulate in the background. The dynamic creates new entry points for threat actors to
actively exploit.
The shortfall puts companies in the crosshairs: 90% of organizations are experiencing identity-related breaches; 97% of organizations
that suffered an AI-related breach lacked proper access controls. The stakes are high, but often no one grasps the full picture until it’s too late. Breach investigations, regulatory scrutiny, and potential fines are on the table, eroding trust at every level. Organizations can lose confidence
and momentum, putting AI strategy and business goals at risk. Closing this gap is foundational to sustaining trust and momentum as
AI strategies expand.
“CISOs are accountable for autonomous entities that can modify themselves at machine speed,” David says. “Without a layer of continuous visibility, they are governing a workforce they cannot even see.”