louis-columbus
December 31, 2025

Legacy IAM was built for humans — and AI agents now outnumber them 82 to 1

By Cloud Syndicate

Legacy IAM was built for humans

Active Directory, LDAP, and early PAM were built for humans. AI agents and machines were the exception. Today, they outnumber people 82 to 1, and that human-first identity model is breaking down at machine speed.

AI agents are the fastest-growing and least-governed class of these machine identities — and they don’t just authenticate, they act. ServiceNow spent roughly $11.6 billion on security acquisitions in 2025 alone — a signal that identity, not models, is becoming the control plane for enterprise AI risk.

CyberArk’s 2025 research confirms what security teams and AI builders have long suspected: Machine identities now outnumber humans by a wide margin. Microsoft Copilot Studio users created over 1 million AI agents in a single quarter, up 130% from the previous period. Gartner predicts that by 2028, 25% of enterprise breaches will trace back to AI agent abuse.

Why legacy architectures fail at machine scale

Builders don’t create shadow agents or over-permissioned service accounts out of negligence. They do it because cloud IAM is slow, security reviews don’t map cleanly to agent workflows, and production pressure rewards speed over precision. Static credentials become the path of least resistance — until they become the breach vector.

Gartner analysts explain the core problem in a report published in May: “Traditional IAM approaches, designed for human users, fall short of addressing the unique requirements of machines, such as devices and workloads.”

Their research identifies why retrofitting fails: “Retrofitting human IAM approaches to fit machine IAM use cases leads to fragmented and ineffective management of machine identities, running afoul of regulatory mandates and exposing the organization to unnecessary risks.”

The governance gap is stark. CyberArk’s 2025 Identity Security Landscape survey of 2,600 security decision-makers reveals a dangerous disconnect: Though machine identities now outnumber humans 82 to 1, 88% of organizations still define only human identities as “privileged users.” The result is that machine identities actually have higher rates of sensitive access than humans.

That 42% figure represents millions of API keys, service accounts, and automated processes with access to crown jewels, all governed by policies designed for employees who clock in and out.

The visibility gap compounds the problem. A Gartner survey of 335 IAM leaders found that IAM teams are only responsible for 44% of an organization’s machine identities, meaning the majority operate outside security’s visibility. Without a cohesive machine IAM strategy, Gartner warns, “organizations risk compromising the security and integrity of their IT infrastructure.”

The Gartner Leaders’ Guide explains why legacy service accounts create systemic risk: They persist after the workloads they support disappear, leaving orphaned credentials with no clear owner or lifecycle…

Read Full Article: VentureBeat

By Louis Columbus

Cloud Syndicate

Cloud Syndicate

Welcome to the 'Cloud Syndicate,' a curated community featuring short-term guest contributors, curated resources, and syndication partners covering diverse technology topics. Connect your technology article or news feed to our syndication network for broader visibility. Explore the intersections of Cloud computing, Cybersecurity, Big Data, and AI through insightful articles and engaging podcasts. Stay ahead in the dynamic world of technology with our platform for thought leadership and industry news.

Join us as we delve into the latest trends and innovations.
CloudTweaks Premium Thought Leadership
Become a featured voice in CloudTweaks’ branded Spotlight Interviews, podcasts, and thought leadership series. Elevate your brand, shape industry dialogue, and inspire tech professionals worldwide.
© 2026 CloudTweaks. All rights reserved.