ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

When your most privileged users aren't people

For years, identity security focused primarily on people. Employees, contractors and third parties were the users security teams needed to manage and monitor, but that assumption is becoming increasingly outdated.

 

As organisations expand their use of cloud services, automation and artificial intelligence, non-human identities (NHIs) such as service accounts, machine identities, APIs and AI agents are proliferating across enterprise environments. In many organisations, they now outnumber human users by a significant margin.

 

According to Veza’s 2026 State of Identity & Access report, non-human identities outnumber human identities by a factor of 17. At the same time, 38% of accounts were found to be dormant, while large volumes of permissions remained ungoverned, creating a growing surface of attacks that many organisations struggle to fully understand.

 

The challenge is not simply one of scale; unlike human users, non-human identities are often created automatically, operate continuously and can remain active long after their original purpose has disappeared. Many are granted privileged access to applications, databases and cloud environments, yet ownership and oversight frequently remain unclear.

 

The rapid adoption of AI is adding another layer of complexity. As highlighted in TechRadar’s recent analysis of non-human identities, many security teams already struggle to maintain visibility over machine identities and service accounts spread across increasingly complex environments. The emergence of AI agents is creating an entirely new category of identities that require access to systems, data and business processes.

 

The risks are already becoming visible. According to Sophos’ State of Identity Security 2026 report, 71% of organisations experienced at least one identity-related breach during the previous 12 months. Researchers identified weak identity controls, excessive permissions and poor visibility across machine identities as growing concerns as environments become more automated and interconnected.

 

For security leaders, the issue highlights a broader shift in identity security. Traditional identity and access management programmes were built around human behaviour, authentication and user lifecycle management. Increasingly, however, organisations must account for machine identities that operate at scale, interact directly with systems and often hold extensive permissions.

 

As a result, security teams are placing greater emphasis on visibility, governance and least-privilege access across both human and non-human identities. The objective is no longer simply knowing who has access to what. It is understanding which machines, applications and AI agents have access as well.

 

Identity remains one of the most common paths used by attackers. As non-human identities continue to multiply, organisations that fail to govern them effectively may find that some of their most privileged users are not people at all.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543