SpyCloud’s 2026 Identity Threat Report, based on a survey of 750 organizations and covered by SecurityInfoWatch, found that non-human identities — AI agents, service accounts, and API keys — were the leading initial-access vector in 31% of identity-related security incidents.
The report found a significant confidence gap: 95% of surveyed organizations believe they have adequate visibility into their AI agents and non-human identities, but only 36% actually monitor those identities in practice.
Why it matters: As enterprises deploy AI agents with their own credentials and permissions across more systems, the attack surface represented by non-human identities is growing faster than most organizations’ identity-governance programs, creating a widening gap between perceived and actual security posture — a pattern directly relevant to any critical-infrastructure operator now integrating AI agents into operational workflows.
Source: SecurityInfoWatch.com, September 11, 2026, citing SpyCloud’s 2026 Identity Threat Report.

Leave a Reply