AI & Agents

You have more AI agents than employees, and no one's counting them

Non-human identities now outnumber human ones 82 to 1 inside the average enterprise. Most security teams could not tell you where a third of them live, let alone what they can reach.

AI agents and other non-human identities now outnumber human users 82 to 1 in enterprise environments. Almost none of that population is inventoried.

The number that should stop a board meeting

Only 21% of organizations maintain a real-time registry of active agents, and only 28% can trace an agent's actions back to a human sponsor across all the environments it touches. Two out of every three non-human accounts are set up locally inside the application itself, invisible to the central identity program. Put plainly: for roughly four out of five agents running inside a typical enterprise today, nobody could currently answer "who is responsible for this, and what can it do."

The legacy toolset was never built for this population

92% of security professionals say they are not confident their legacy identity and access management systems can handle AI and non-human identity risk, and 78% have no documented policy for creating or retiring an agent identity. That is not a tooling gap that a new dashboard fixes. Traditional IAM was designed around a human lifecycle — hire, role change, offboard — with a person to interview at each step. An agent's lifecycle has no interview. It can be spun up by a script, inherit permissions from whatever spawned it, and spawn sub-agents of its own, multiplying the population faster than any manual review process can track it.

Standards are arriving faster than enterprise practice

To its credit, the industry is not starting from zero. The IETF published a draft Agent Identity Management System in March, combining existing frameworks like SPIFFE/SPIRE and OAuth 2.0 into something purpose-built for machine identities, and NIST published a companion concept paper the month before. Standards existing is progress. Standards being adopted is a separate, much slower project, and right now the adoption curve is nowhere near the growth curve of the agents themselves.

The question every CIO should be able to answer this quarter, and mostly cannot: how many agents are running, under what identity, and what can each one actually reach. If that answer is a guess, the org does not have an AI agent program. It has an unmanaged population of accounts that happen to be very good at their jobs — until one of them is compromised, at which point nobody will know how far the blast radius extends.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.