Skip to content
Analysis

When machines outnumber people, IAM has to change

By Callum Budd

Row of humanoid robots working on a factory production line

Identity and access management was once largely a people problem.

An employee joined an organisation, received an account, changed roles and eventually left. Controls were built around a relatively stable population of people with recognisable jobs and predictable patterns of access.

That population is no longer the majority.

Palo Alto Networks’ 2026 Identity Security Landscape research reports that organisations now manage an average of 109 machine identities for every human identity, up from 82 to one a year earlier. Organisations also expect AI agent identities to grow by a further 85% over the next 12 months.

What counts as a machine identity?

Machine identities belong to workloads, applications, services, containers, devices, automated processes and AI agents.

The identity is the actor. An API key, certificate, token or secret is one of the ways that actor proves who or what it is.

This distinction matters because changing a credential does not necessarily address the underlying identity problem. An organisation still needs to know why the machine exists, who owns it, what it can access and when that access should end.

Gartner describes machine-to-machine interactions as ubiquitous and argues that organisations need a dedicated practice for modern machine identity and access management.

Human-scale processes cannot keep up

A human account may remain in place for years. A container or automated workload might exist for hours, minutes or seconds.

Machine identities can be created every time infrastructure is deployed, software is released or an agent begins a new task. Manual inventories and quarterly access reviews cannot reliably keep pace with that volume.

AI agents make the problem harder again. They may move between tools, inherit human permissions or use shared service accounts. Research reported by the Cloud Security Alliance found that 68% of organisations could not accurately distinguish AI agent activity from human activity. Nearly three-quarters said agents were often given more access than necessary, while only 22% applied access frameworks consistently.

The credential lifecycle needs to become automatic

A modern machine identity programme should be able to discover identities continuously, associate each one with an owner and purpose, and apply policy without waiting for a manual review.

Credentials should be created when they are needed, limited to the task and removed when the task ends. Rotation and revocation should happen automatically, with monitoring capable of identifying unusual access or privilege changes.

This does not mean removing people from the process. People still define acceptable use, ownership and risk. Automation ensures those decisions can be enforced at the same speed as the machines they govern.

The result is a shift from storing credentials safely to controlling authority throughout its lifecycle.

This is also a market maturity issue

Not every organisation is at the same stage.

Some are still trying to identify how many machine identities they have. Others have centralised secrets but lack automated ownership and revocation. More mature organisations are beginning to apply short-lived, workload-specific access and real-time behavioural controls.

For technology vendors, these differences matter. A message about runtime policy will not resonate with a buyer who is still struggling to build a reliable inventory.

Research can help organisations understand the maturity of their market, identify the barriers holding customers back and develop propositions that match the buyer’s current reality.

As machines increasingly become the users of enterprise technology, IAM must become capable of operating at machine speed too.

To understand how machine identity priorities and maturity differ across your target market, contact Callum Budd at callum@mra-research.co.uk.

Ready to understand your market?

Get in touch to discover what research could reveal about your competitive position.

Get In Touch