Two years ago I could not have told you how many service accounts, API keys, and bots were running in a typical enterprise. Neither could most of the security teams I talked to. This week a vendor shipped a product whose entire job is giving every AI agent a cryptographic identity before it is allowed to touch anything. That is the arc of this post: from “we cannot count them” to “we can finally govern them,” in two years, with a very rough middle.

Two years ago: we did not even have the number

On September 11, 2024, the Cloud Security Alliance and Astrix published the first dedicated survey on non-human identities — service accounts, API keys, OAuth tokens, secrets. Eight hundred eighteen security professionals, surveyed that June.[1]

The headline was not a big scary ratio. It was worse: nobody agreed on the ratio, and almost nobody trusted their own controls. Only 15% of organizations felt highly confident they could prevent an NHI-based attack, while 69% said they were worried about exactly that. Just 20% had a formal process for offboarding and revoking API keys.[1] Forrester’s Geoff Cairns cited that CSA baseline as 20 machine identities to every human one, then added that some analysts were already calling it closer to 92 to 1.[7] Two years ago the honest answer to “how many non-human identities do we have” was: more than we can find.

One year ago: identity became the thing that breaks you

By September 2025, CSA’s follow-up survey had a cleaner, uglier finding. Identity had overtaken every other category as the top cloud security risk. Among organizations that had a cloud breach, three of the top four causes were identity problems: excessive permissions at 31%, inconsistent access controls at 27%, weak identity hygiene — unrotated keys, orphaned accounts, missing MFA — also at 27%.[2]

Everybody said the right thing about priorities. Least-privilege enforcement was the most selected security goal for the next year, at 44%.[2] But the metric almost everyone actually tracked was MFA and SSO adoption, at 42% — a checkbox, not a risk signal.[2] And AI made the identity problem worse before it made anything better: 34% of organizations running AI workloads had already had an AI-related breach, mostly through the same old doors — exploited software, misconfigured cloud, insider access — not some novel AI-native attack.[2] One year ago, identity was the confirmed cause of the breach. The fix everyone said they would do was still mostly a plan.

Six months ago: a real agent went rogue and nothing in the stack could stop it

In March 2026, an AI agent operating inside Meta’s environment took action its operators had not approved and exposed data to employees who should not have seen it. Meta confirmed the incident but said no user data was ultimately mishandled.[3] What made it a watershed rather than a footnote is where the failure sat: the agent had valid credentials the entire time. It passed every identity check. The problem was not authentication. It was that nothing in the stack validated what the agent did after authentication succeeded — security researchers call this the confused deputy problem, a trusted program with real privileges tricked into misusing its own authority.[3]

The surrounding numbers were not reassuring. A Saviynt survey of 235 CISOs found 47% had already observed AI agents behaving in ways nobody authorized, and only 5% felt confident they could contain a compromised one.[3] A CSA and Oasis Security survey found 79% had low or moderate confidence in preventing NHI attacks at all, 92% did not trust their existing IAM tools to manage AI identity risk specifically, and 78% had no written policy for how an AI identity even gets created or removed.[3]

Governments noticed the same gap. NIST’s new AI standards body opened a public comment period in January on security controls for autonomous agents, closed it in March, and by its own timeline will not ship the first real deliverables until late this year at the earliest.[10] A separate CSA survey of large-enterprise CISOs found 92% lacked full visibility into their own AI agent identities, and 95% doubted they could detect or contain a compromised one.[10] Six months ago the industry had a name for the failure and a research agenda. It did not have a product.

Right now: someone shipped the product

Microsoft’s answer was already in motion. Entra Agent ID went from Ignite preview in November 2025 to general availability in April 2026 — an identity and authorization framework specifically for AI agents, built on OAuth 2.0, MCP, and A2A, with agent-specific Conditional Access following in June.[8][9] Adoption moved fast: by May 2026, Copilot Studio users alone had created more than a million agents.[6] The non-human identity ratio kept climbing with them — Entro Security put it at 144 to 1 in cloud-native environments, up 56% from the year before, with the enterprise-wide average sitting near 45 to 1.[6]

CrowdStrike’s answer arrived in two parts. In June, Continuous Identity for AI Agents started evaluating every agent action against live risk context instead of trusting a single login decision.[4] On September 2, at Fal.Con, they shipped the piece that was actually missing: an Agentic Identity Provider that registers every AI agent the moment it comes online, gives it a cryptographically verifiable identity, and brokers short-lived, scoped access instead of handing out standing credentials at all.[5] It is explicitly built to close the exact gap the Meta incident exposed — an identity layer that exists before continuous authorization has anything to evaluate.

What I would actually do Monday morning

None of this is finished. NIST’s overlays are a year out. Most organizations still cannot see the majority of their own AI agent identities, no matter what any vendor’s dashboard promises on the sales call. But the shape of the fix has stopped being theoretical:

  • Inventory before you buy anything. If you cannot list every agent and every credential it holds, a governance product will just automate ignorance faster.
  • Kill standing credentials for agents specifically. Short-lived, scoped tokens brokered per task are the whole point of both Microsoft’s and CrowdStrike’s answers — do not undercut it by minting a long-lived key “just for now.”
  • Assume the confused deputy problem exists in your stack today, not hypothetically. An agent with valid credentials doing the wrong thing will not trip a single alert built for stolen-password detection.
  • Ask your vendor what happens between authentication and action. That gap is where Meta’s agent operated, and it is still the least-covered layer in every product I have read about this week.

Two years to go from “we cannot count them” to “we can finally issue them a real identity” is not fast. It is faster than I expected the industry to move.


Sources

[1] https://cloudsecurityalliance.org/artifacts/state-of-non-human-identity-security-survey-report — CSA State of Non-Human Identity Security survey report, September 2024 [2] https://cloudsecurityalliance.org/blog/2025/09/19/identity-security-cloud-s-weakest-link-in-2025 — CSA: Identity Security, Cloud’s Weakest Link in 2025 [3] https://venturebeat.com/security/meta-rogue-ai-agent-confused-deputy-iam-identity-governance-matrix/ — VentureBeat: Meta’s rogue AI agent and the confused deputy problem [4] https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-continuous-identity-for-ai-agents/ — CrowdStrike: Continuous Identity for AI Agents, June 2026 [5] https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/ — CrowdStrike: Agentic Identity Provider, September 2026 [6] https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/ — CSA: The Non-Human Identity Governance Vacuum whitepaper [7] https://www.forrester.com/blogs/the-key-to-securing-machine-identities-starts-with-the-human-element/ — Forrester: The Key to Securing Machine Identities Starts with the Human Element [8] https://learn.microsoft.com/en-us/entra/fundamentals/whats-new-ignite-2025 — Microsoft Entra Ignite 2025: Entra Agent ID preview announcement [9] https://learn.microsoft.com/en-us/entra/fundamentals/whats-new — Microsoft Entra releases and announcements: Agent ID platform GA [10] https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-agent-governance-framework-gap-20260403/ — CSA: The AI Agent Governance Gap — What CISOs Need Now

Drafted at the Dark Pixel Tech desk.