Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityleaked-secret-api-keycloud-misconfiguration

AI and Non-Human Identity Sprawl Expands IAM Attack Surface

Updated 19d agoFirst seen Feb 2, 202612 sources

Reporting and commentary warn that AI-driven non-human identities (NHIs) are rapidly increasing the number and turnover of credentials inside enterprise IAM programs, amplifying long-standing weaknesses such as credential sprawl, unclear ownership, and inconsistent lifecycle controls. The Cloud Security Alliance’s findings highlight that many organizations treat AI identities like traditional service accounts or API keys, causing them to inherit existing governance gaps while adding new scale and speed pressures as identities are created programmatically, distributed across environments, and used continuously.

CSO Online describes the operational drivers behind the surge—microservices, Kubernetes auto-scaling, CI/CD pipelines (e.g., GitHub Actions), and infrastructure-as-code (e.g., Terraform) generating large volumes of short-lived tokens and service principals—then argues that agentic AI further accelerates risk because these identities may be authorized to execute commands, move data, and change configurations autonomously. The net risk emphasized is that over-privileged AI agents and other NHIs can create breach conditions that may not resemble traditional intrusion, instead appearing as “normal” automated activity due to excessive permissions and weak visibility into post-authentication behavior.

Share:
AI and Non-Human Identity Sprawl Expands IAM Attack Surface
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 14, 20261mo ago

Palo Alto report says machine identities outnumber humans 109 to 1

Palo Alto Networks’ 2026 Identity Security Landscape report said organizations now manage an average of 109 machine identities for every human identity and projected AI agent growth of 85% over the next year. The report also said weak lifecycle and privilege controls are leaving enterprises exposed, while Unit 42 found fragmented identity investigations across more than 750 incidents in 2025 slowed response efforts.

Machine identities outnumber humans 109 to 1 - Help Net Security
Apr 30, 20262mo ago

Anthropic withholds Mythos model after it finds thousands of vulnerabilities

Anthropic reportedly decided not to publicly release its Mythos model after the system discovered thousands of previously unknown vulnerabilities in major operating systems and web browsers. The decision was cited as an example of the dual-use security risks posed by advanced AI agents.

Everyone’s building AI agents. Almost nobody’s ready for what they do to identity. | CyberScoop
Feb 3, 20265mo ago

Report says rapid AI agent adoption is creating an identity security crisis

Reporting on the CSA findings, outlets said organizations are deploying autonomous AI agents without sufficient governance, creating many agentic identities with access to sensitive data and little oversight. The coverage emphasized a widening preparedness gap around AI identity threats and the risks posed by these poorly governed non-human identities.

Feb 2, 20265mo ago

Cloud Security Alliance report highlights AI identity governance weaknesses

The Cloud Security Alliance published findings in "The State of Non-Human Identity and AI Security" showing that organizations often manage AI identities like other non-human identities, causing them to inherit weaknesses such as credential sprawl, unclear ownership, and inconsistent lifecycle controls. The report said AI systems continuously create and use identities across environments, outpacing legacy IAM tools and leaving security teams with poor visibility and slow revocation processes.

One Identity predicts a major breach tied to an over-privileged AI agent by 2026

CSO Online cited a One Identity prediction that by 2026 a major breach would be traced to an over-privileged AI agent. The warning framed agentic AI as a growing identity risk because its actions may appear to be normal authorized system behavior.

Feb 1, 20265mo ago

Obsidian reports breaches tied to compromised machine identities

Obsidian Security reported in February 2026 that many organizations had already suffered breaches linked to compromised machine identities such as service accounts, API keys, certificates, bots, and AI agents. The research also found that only a small minority had fully automated lifecycle management for these identities, underscoring operational security gaps.

How the explosion in machine identities is changing cyber defense | IT Pro
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
1 linked
Operator
Organizations
16 linked
Palo Alto NetworksThe RegisterObsidian SecurityVisaAnthropicSalesloftCloud Security AllianceOpenaiNetskopeDarktraceDeloitteMicrosoft CorporationSC MediaVorlonGooglePaladin Global Institute
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AI and Non-Human Identity Sprawl Expands IAM Attack Surface | Mallory