Share with your CISO
Non-human identities (NHIs), the API keys, authentication tokens, service accounts, and AI agents that act on behalf of humans inside enterprise systems, have surpassed phishing as the leading initial access vector in identity-related breaches, according to SpyCloud’s 2026 Identity Threat Report. Surveying 750 cybersecurity leaders at organizations with 500-plus employees across the US, UK, Canada, and Europe, the report found that 31% of organizations hit by identity events traced the initial breach to compromised or overprivileged NHIs, nearly twice the 17% that named phishing. NHI misuse was the most frequently reported identity event type overall, at 42%.
What this means for your business
The sharpest number in this report isn’t the breach rate, it’s the perception gap. Ninety-five percent of organizations say they have adequate visibility into AI and NHI exposure. Only 36% actually monitor those identities. That 59-point spread is the operative risk: organizations are treating confidence as a substitute for instrumentation. If your AI agents are accessing internal systems and your security tooling wasn’t built to log and alert on machine-to-machine credential use, you’re almost certainly in that 64% without knowing it.
The governance picture compounds the monitoring gap. Ninety-one percent of organizations have AI tools or agents touching internal systems, but only 56% have formal ownership and governance over the privileges those agents carry. The remaining 41% operate on informal or partial processes, which in practice means no single person owns the blast radius when an agent’s credentials are stolen. AI adoption inside the enterprise has outrun the identity governance frameworks built for human employees, and attackers clearly understand this before most security teams do. SpyCloud sells remediation tooling into exactly this gap, so the urgency framing is commercially motivated, but the underlying data from 750 practitioners is directionally hard to dismiss.
Third-party exposure is where this problem compounds fastest. Nearly 40% of organizations have no consistent process to confirm that a vendor or partner identity exposure has actually been remediated, not just reported. As more AI agents are provisioned to interact with external systems, the API keys and tokens they carry become supply chain risk. The organizations that reported lower identity event rates had one thing in common: visibility into stolen session cookies, a strong proxy for whether continuous exposure monitoring is actually running. The budget question isn’t whether to invest in NHI monitoring; it’s whether your current identity security vendor can tell you, right now, which AI agents in your environment hold standing privileges they haven’t used in 90 days.
Concept deep-dive: Non-human identities (NHIs)
A non-human identity is any credential or access token assigned to software rather than a person: an AI agent, a scheduled script, an API key connecting two cloud services, or a service account running an automated workflow. Unlike employee logins, NHIs rarely expire automatically, often accumulate excessive permissions over time, and almost never trigger multi-factor authentication challenges. Think of them as employee badges that never get deactivated when the job function changes. As AI agents multiply, each one typically receives its own NHI, expanding the credential surface that security teams must track.
Based on reporting from AI Agents and Machine Identities Widen Enterprise Security Exposure, originally published 2026-09-11 16:48:00.
