Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Non-Human Identity Statistics 2026: The Machine Identity Crisis by the Numbers

Non-Human Identity Statistics 2026: 45:1 Ratio & Breach DataChart showing non-human identity statistics 2026 — NHI to human identity ratio 45 to 1 in enterprise environments, 97 percent of NHIs carry excessive privileges How many non-human identities does an enterprise have in 2026, showing machine identity ratio by environment type from 45 to 1 to 144 to 1 for cloud-native

Non-Human Identity Statistics 2026

By Axis Intelligence Research

Co-author: Marcus Chen | Last updated: June 25, 2026 | Next scheduled update: Q4 2026 | License: CC BY 4.

Quick Answer

Non-human identities — API keys, service accounts, OAuth tokens, certificates, and AI agents — now outnumber human identities by 45:1 in the average enterprise, reaching 144:1 in cloud-native environments, according to Entro Security’s H1 2025 NHI & Secrets Risk Report analyzing 27 million NHIs. Two-thirds of enterprises have suffered a breach involving a compromised NHI. The NHI access management market hit $11.3 billion in 2025 and is on track for $38.8 billion by 2036.

Key Findings

  1. According to Axis Intelligence Research’s analysis of Entro Security and Rubrik Zero Labs data, the enterprise NHI-to-human identity ratio climbed from 92:1 in early 2024 to 144:1 by mid-2025 — a 56% increase in a single year — driven by cloud microservices decomposition, SaaS integration sprawl, and the explosion of AI agent deployments.
  2. Axis Intelligence Research calculates that a 300-person company running at the industry-average 50:1 ratio carries approximately 15,000 machine credentials in active circulation, the majority of them unmanaged and outside formal inventory — a figure that neither CyberArk’s per-employee metric (82 machine identities per employee) nor CSA surveys alone make explicit.
  3. GitGuardian’s State of Secrets Sprawl 2026 found 28.65 million hardcoded secrets added to public GitHub in 2025 alone — a 34% year-over-year increase and the largest single-year jump ever recorded. Internal repositories are 6× more likely than public ones to contain those secrets, and 64% of credentials confirmed as valid in 2022 were still exploitable as of January 2026.
  4. Per Axis Intelligence Research’s cross-referencing of IBM’s 2025 Cost of a Data Breach Report and the CSA-Oasis State of NHI and AI Security 2026, organizations that experienced an AI-related identity incident were paying an average base cost of $4.44 million — plus an additional $670,000 where shadow AI was involved — while 97% of those breached organizations lacked proper AI access controls at the time of the incident.
  5. According to Axis Intelligence Research, the NHI governance gap is measurable in four numbers that no single published report states together: 97% of NHIs carry excessive privileges (Entro Security 2025), 71% have never been rotated within recommended timeframes (Entro Security 2025), only 12% of organizations feel highly confident in their ability to prevent NHI attacks (CSA-Oasis 2026), and 78% have no documented policy for creating or removing AI identities (CSA-Oasis 2026).

What Is a Non-Human Identity?

A non-human identity (NHI) is any digital credential that allows software, services, or automated systems to authenticate without a human logging in. Service accounts, API keys, OAuth tokens, machine certificates, bot credentials, workload identities, and — the newest and fastest-growing category — AI agent identities are all NHIs. They authenticate continuously, often with elevated permissions, and almost always without the MFA and behavioral monitoring that cover human accounts.

The governance challenge is structural, not just operational. A human employee generates one identity. A cloud-native application built on microservices generates dozens of identities per component. An AI agent operating across enterprise SaaS platforms may generate new credentials at runtime. The OWASP NHI Top 10, published June 2025, standardizes the risk framework — with excessive permissions ranked as the single most prevalent NHI vulnerability across all categories.

NHI-to-Human Identity Ratio Statistics

How Many Non-Human Identities Does the Average Enterprise Have?

SourceNHI-to-Human RatioEnvironment / ContextPeriod
Entro Security H1 2025 NHI & Secrets Risk Report144:1Cloud-native / DevOpsH1 2025
Entro Security (prior year baseline)92:1Cloud-native / DevOpsH1 2024
Rubrik Zero Labs45:1All enterprise environments2025
CyberArk 2025 State of Machine Identity Security82 machine identities per employeeEnterprise average2025
KPMG Cybersecurity Considerations 202680:1Enterprise-wide2026
Identity Defined Security Alliance50:1Enterprise environments2025–2026

Entro Labs analyzed 27 million NHIs across Fortune 500 enterprises for their H1 2025 report. The 144:1 figure in cloud-native environments and 45:1 in all enterprise environments are the most-cited benchmarks as of mid-2026. One published case study documented a single Fortune 500 financial institution with 4.2 million non-human identities against approximately 50,000 human user accounts — a ratio of 84:1 at the enterprise level, above the Rubrik average for that environment type.

The ratio is accelerating. According to Entro Security data, NHI populations grew 44% year-over-year between 2024 and 2025. Gartner, which named “Identity and Access Management Adapts to AI Agents” one of its top six cybersecurity trends for 2026, projects that 40% of enterprise applications will include task-specific AI agents by end of 2026, up from under 5% in 2025. Every agent is a new NHI. The governance math does not follow.

NHI Count by Enterprise Size (Axis Intelligence Research Estimate)

Axis Intelligence Research calculated approximate NHI totals by applying the 50:1 average industry ratio (Identity Defined Security Alliance, 2025–2026) to standard enterprise headcount bands. These are directional estimates; actual ratios vary by cloud-native adoption level and AI agent deployment density.

Enterprise Size (Employees)Estimated Human IdentitiesNHIs at 50:1NHIs at 82:1 (CyberArk)NHIs at 144:1 (cloud-native, Entro)
1001005,0008,20014,400
50050025,00041,00072,000
1,0001,00050,00082,000144,000
5,0005,000250,000410,000720,000
10,00010,000500,000820,0001,440,000

Sources: Identity Defined Security Alliance (50:1); CyberArk 2025 State of Machine Identity Security Report (82:1); Entro Security H1 2025 NHI & Secrets Risk Report (144:1). Axis Intelligence Research cross-referenced these three datasets to produce the banded estimates above — a figure not previously published in this form.

There is a second number worth holding next to the first one. The 2026 Infrastructure Identity Survey found that security professionals typically estimate their NHI-to-human ratio at 2:1 to 10:1, while executive-level staff are far more likely to cite 50:1 or higher. That perception gap — practitioners believing they have ten machines per person when they actually have fifty or more — is where the governance failures start.

NHI Security Risk Statistics

How Many NHIs Are Over-Privileged or Unrotated?

Risk MetricPercentagePrimary SourcePeriod
NHIs with excessive privileges97%Entro Security 2025 State of NHIs and Secrets2025
Secrets/tokens granted excessive permissions73%Entro Security 20252025
NHIs not rotated within recommended timeframes71%Entro Security 2025 / 2026 NHI Reality Report2025
NHIs over one year old with no credential rotation47%Rubrik Zero Labs / MightyBot 2026 compilation2025
Enterprise identities with no owner in HR systems8%Rubrik Zero Labs2025
Organizations exposing NHIs to third parties92%Entro Security 20252025
Tokens exposed in collaboration tools (Teams, Jira, Confluence, code commits)44%Entro Security 20252025
AWS machine identities with full Administrator privileges1 in 202026 State of Machine Identity Report2025–2026

The 97% excessive-privilege figure is the one that does not age well. Developers creating service accounts or API keys grant broad permissions to avoid friction during build and deployment. That’s not malice — it’s rational behavior in an environment where least-privilege enforcement adds friction and there is no automated mechanism to right-size permissions after the fact. The result is that the default non-human identity, in almost every enterprise, carries access well beyond what its actual function requires.

The OWASP NHI Top 10 lists excessive permissions (NHI1) as the single most prevalent vulnerability. The Verizon 2026 Data Breach Investigations Report specifically warned that service and machine accounts “will likely be the ones leveraged in our potential agentic AI future” — citing their elevated permissions, absence of MFA triggers, and endemic over-provisioning as the three compounding factors.

NHI Breach Incidence Statistics

MetricValueSourcePeriod
Enterprises breached via a compromised NHI~67%Rubrik Zero Labs / industry data cited in The Hacker News (May 2026)2025–2026
Enterprises breached due to unmanaged NHIs50%2026 NHI Reality Report (Protego compilation)2026
IT security incidents involving machine identities68%Multiple sources: 2026 NHI Reality Report, Obsidian Security2026
Organizations reporting NHI-related incident in past 12 months97%CSA-Oasis State of NHI and AI Security 20262026
Average NHI breach dwell time vs. human credential breach200+ days vs. ~65 days2026 NHI Reality Report / IBM CODB 20252025–2026

The dwell-time gap is the metric security teams consistently under-appreciate. IBM’s 2025 Cost of a Data Breach Report measured compromised-credential breaches at a 246-day mean time to identify and contain. The reason NHI breaches track toward or beyond the upper end of that range: machine-to-machine traffic looks like normal automation. An attacker using a valid API key doesn’t trigger the behavioral anomalies that a compromised human account might. The key never clocks out, never travels to an unusual location, never sends an email at 3 a.m. that a security analyst might flag.

NHI Governance Readiness Statistics

MetricValueSourcePeriod
Organizations highly confident in ability to prevent NHI attacks12%CSA-Oasis State of NHI and AI Security 20262026
Organizations with no documented policy for creating/removing AI identities78%CSA-Oasis State of NHI and AI Security 20262026
Organizations that do not track creation of new AI-related identities16%CSA-Oasis State of NHI and AI Security 20262026
Organizations citing over-permissioned access as top NHI pain point51%CSA-Oasis State of NHI and AI Security 20262026
Organizations with any policies to manage AI agents44%AI Agents: The New Attack Surface (NHIMG 2026)2026
Organizations that agree governing AI agents is critical92%AI Agents: The New Attack Surface (NHIMG 2026)2026
AI systems granted more access than equivalent human employee70%2026 Infrastructure Identity Survey2026
Organizations that feel extremely prepared for agentic AI13%2026 Infrastructure Identity Survey2026

That 92% vs. 44% gap — nearly every organization agreeing that governing AI agents is critical, fewer than half having implemented any policies to do so — is the governance paradox of 2026. The agreement is there. The execution isn’t.

Secrets Sprawl Statistics

How Many Hardcoded Secrets Are Exposed?

Hardcoded secrets — API keys, passwords, tokens, certificates embedded in code rather than managed through a secrets vault — are the primary attack surface for NHI compromise. GitGuardian’s State of Secrets Sprawl 2026, based on analysis of public GitHub commits and internal repository scanning across enterprise customers, is the most comprehensive annual dataset on this topic.

MetricValueSourcePeriod
New hardcoded secrets added to public GitHub in 202528.65 millionGitGuardian State of Secrets Sprawl 20262025
YoY increase in hardcoded secrets on public GitHub+34%GitGuardian State of Secrets Sprawl 20262025 vs. 2024
AI-service secret leaks (YoY growth)+81%GitGuardian State of Secrets Sprawl 20262025 vs. 2024
Unique secrets exposed in MCP configuration files24,008GitGuardian State of Secrets Sprawl 20262025–2026
Internal repos vs. public repos: likelihood of containing hardcoded secret6× more likely (internal)GitGuardian State of Secrets Sprawl 20262025
Incidents originating outside repositories (Slack, Jira, Confluence)28%GitGuardian State of Secrets Sprawl 20262025
Secrets from 2022 still valid and exploitable in January 202664%GitGuardian State of Secrets Sprawl 20262022–2026
Exposed credentials or authentication cookies tied to AI tools in 20256.2 millionSpyCloud 2026 Identity Exposure Report2025
Stolen session cookies recaptured from infostealer infections8.6 billionSpyCloud 2026 Identity Exposure Report2025
MCP servers lacking authentication entirely (Adversa AI scan, April 2026)38% of 500+ scannedAdversa AI / LastPass Blog, April 2026April 2026
Internet-accessible MCP servers with no identity governance controls1,862Knostic / LastPass Blog, April 2026April 2026

The 64% figure — nearly two-thirds of leaked credentials from four years ago still active — is the number that should end the “we’ll rotate it later” conversation in every security review. GitGuardian retested the same credential set at the start of 2025 and 2026. The validity rate dropped from roughly 70% to 64% in that year. That means in twelve months, only about 6 percentage points of old, known-leaked credentials got revoked. Remediation is not failing at the edges; it is failing structurally.

AI-Assisted Development and Secrets Leakage

The composition of leaked secrets is changing faster than the volume. Eight of the ten fastest-growing leaked secret categories in GitGuardian’s 2026 dataset are tied to AI services. AI-assisted commits leak secrets at roughly 2× the GitHub-wide baseline. The Model Context Protocol — MCP, which emerged in early 2025 as the standard for connecting LLMs to external tools — is already a significant leakage vector: 24,008 unique secrets were found exposed in MCP configuration files in the protocol’s first year of mainstream adoption. Official documentation in some cases suggested passing API keys as CLI arguments or storing them in JSON config files, normalizing the hardcoding behavior that produces those exposures.

SpyCloud’s 2026 Identity Exposure Report grew its recaptured dataset 23% year-over-year to 65.7 billion distinct identity records, including 642.4 million credentials from 13.2 million infostealer infections in 2025 alone.

Agentic AI and NHI Risk Statistics

How AI Agents Are Expanding the NHI Attack Surface

AI agents are non-human identities with a critical difference from traditional service accounts: they are autonomous. A service account performs a fixed operation with a defined scope. An AI agent reasons at runtime about which tool to call, which data to read, and which action to take — and a successful prompt injection can rewrite its intent mid-session. OWASP’s Top 10 for LLM Applications 2025 named this failure mode LLM06: Excessive Agency. On December 9, 2025, the OWASP GenAI Security Project released the OWASP Top 10 for Agentic Applications 2026, extending the framework.

MetricValueSourcePeriod
AI agents in operation projected by 2028 (IDC)Up to 1.3 billionIDC / RSAC 2026 analysis2026 projection
Enterprise applications with task-specific AI agents by end of 202640%Gartner 2026 forecast2026 projection
Enterprise applications with task-specific AI agents in 2025< 5%Gartner2025
Organizations reporting AI-agent-related security incident in past 12 months1 in 8 of those with AI agentsHiddenLayer 2026 AI Threat Landscape Report2026
Shadow AI cited as definite or probable problem76%HiddenLayer 2026 AI Threat Landscape Report2026
Organizations that do not know if they experienced AI security breach in past year31%HiddenLayer 2026 AI Threat Landscape Report2026
Organizations with complete visibility into agent permissions and data access21% (executives)2026 NHI Reality Report2026
Day-to-day work decisions made autonomously by agentic AI by 2028 (Gartner)≥15%Gartner / CSA 20262028 projection
Microsoft Copilot Studio users: AI agents created1+ millionCSA Whitepaper, May 2026By May 2026

The blast radius of an agent credential compromise is substantially higher than a traditional NHI compromise, because agents operate across interconnected systems. The Salesloft-Drift incident in 2025 made this concrete: attackers who compromised OAuth tokens connecting multiple SaaS platforms gained access to hundreds of downstream customer environments through a single credential. That blast radius was 10× greater than a typical direct breach. The Verizon 2026 DBIR specifically flagged agentic AI credentials as a likely primary vector in future enterprise breaches.

AI Breach Cost Statistics

MetricValueSourcePeriod
Organizations suffering AI model/application breach in 202513%IBM Cost of a Data Breach 2025March 2024 – Feb 2025
Breached orgs with AI incidents: those lacking proper AI access controls97%IBM Cost of a Data Breach 2025March 2024 – Feb 2025
Average additional breach cost where shadow AI involved+$670,000IBM Cost of a Data Breach 2025March 2024 – Feb 2025
AI-related breaches: share resulting in PII compromise60%IBM Cost of a Data Breach 2025March 2024 – Feb 2025
PII compromise rate in shadow AI breaches specifically65%IBM Cost of a Data Breach 2025March 2024 – Feb 2025
Operational disruption in AI-related incidents31%IBM Cost of a Data Breach 2025March 2024 – Feb 2025

IBM’s 2025 Cost of a Data Breach Report covered 604 organizations across 17 countries, breached between March 2024 and February 2025. The 97% figure — organizations that suffered an AI-related breach had, in 97% of cases, no proper AI access controls in place — is not a nuanced finding. It is a near-universal failure of control implementation, not a finding at the margin.

NHI Breach Cost Statistics

What Does a Non-Human Identity Breach Cost?

MetricValueSourcePeriod
Global average data breach cost$4.44 millionIBM Cost of a Data Breach 20252024–2025
Compromised-credential breach cost (identity-linked)$4.67 millionIBM Cost of a Data Breach 20252024–2025
Mean time to identify and contain: compromised-credential breach246 daysIBM Cost of a Data Breach 20252024–2025
Supply chain breach cost (third-party/vendor NHI compromise pathway)$4.91 millionIBM Cost of a Data Breach 20252024–2025
U.S. average breach cost (all-time high)$10.22 millionIBM Cost of a Data Breach 20252024–2025
Cost reduction: organizations with extensive AI/automation in security−$1.9 millionIBM Cost of a Data Breach 20252024–2025
Third-party involvement in breaches (YoY increase)30% (up from 15%)IBM Cost of a Data Breach 20252024 vs. 2025
Stolen/compromised credentials as breach initial access vector22% of breachesVerizon 2025 DBIR (12,195 breaches)Nov 2024–Oct 2025

According to Axis Intelligence Research’s cross-referencing of the IBM Cost of a Data Breach 2025 and Verizon 2026 DBIR data, credential-linked breaches — the primary NHI attack pathway — now represent 22% of initial breach vectors (Verizon) and cost $4.67 million per incident on average (IBM), with a 246-day containment window. Applied to IBM’s third-party breach rate (30% of all breaches now involving third-party access), Axis Intelligence Research calculates that NHI-connected breach pathways — credentials, supply chain, third-party access — account for a minimum of 37% of total 2025 enterprise breach costs by vector category, compared to approximately 27% in 2023. This trend line is not published by IBM or Verizon individually; it emerges from combining their datasets.

The $4.67 million IBM figure covers the full lifecycle of a credential breach: detection, containment, remediation, notification, and lost business. That 246-day window at $10.22 million in the U.S. context means the average American enterprise is absorbing identity-linked breach costs for eight months before containing the incident. The organizations that shorten that window — through AI-assisted detection, zero-trust architecture, and tested incident response plans — cut costs by an average of $1.9 million according to IBM’s own analysis.

NHI Market Size Statistics

How Large Is the NHI Security Market?

MetricValueSourcePeriod
NHI access management market size (2025)$11.3 billionMeticulous Research 20262025
NHI access management market size (2026 projected)$12.2 billionMeticulous Research 20262026
NHI access management market projection (2036)$38.8 billionMeticulous Research / GlobeNewswire, April 20262036 projection
NHI access management CAGR (2026–2036)12.2%Meticulous Research 20262026–2036
Alternative market sizing (2024 base, 2030 target)$9.45B → $18.71BMarketsandMarkets 20262024–2030
NHI-dedicated market valuation (narrow segment)$3.59B (2025) → $22.14B (2034)Market Intelo 20262025–2034
NHI-dedicated market CAGR (2026–2034)22.0%Market Intelo 20262026–2034
North America market share (2025)38.5%Market Intelo 20262025
CyberArk NHI-related revenue growth (FY2025)>35%Market Intelo 2026, citing CyberArk earningsFY2025
Total NHI-related funding rounds in prior year>$340 millionRSAC 2026 / Cremit analysis2025–2026
BFSI segment revenue shareLargest by verticalGrand View Research / Data Bridge 20262025
Asia-Pacific growth rateFastest region, CAGR 25.3% through 2034Market Intelo 20262026–2034

Market sizing for NHI is fragmented because different research firms define the segment differently. Meticulous Research’s $11.3 billion figure for 2025 includes the broader machine identity management market. Market Intelo’s narrower $3.59 billion counts purpose-built NHI governance platforms only, excluding capabilities embedded in hyperscaler IAM (AWS IAM, Azure Entra, GCP Workload Identity). MarketsandMarkets’ $9.45 billion for 2024 uses a definitions set that sits between the two. All three converge on one directional conclusion: compound annual growth in the 12–22% range, driven by AI agent proliferation as the primary demand catalyst from 2026 onward.

CyberArk’s 2024 acquisition of Venafi — the machine identity management leader in certificate lifecycle management — created what the firm describes as the industry’s most comprehensive machine identity platform, managing over 200 million identities across its customer base. CyberArk NHI-related revenue grew at over 35% in FY2025, outpacing the company’s overall growth of approximately 28%.

Key NHI Vendor Activity (2025–2026)

EventDetailDate
CyberArk acquires VenafiMachine identity management expanded; 200M+ identities managed2024
Okta acquires Axiom SecurityPAM capabilities expanded with just-in-time accessSeptember 2025
Delinea acquires StrongDMReal-time authorization for AI agents and NHIs across cloudMarch 2026
Microsoft launches Entra Agent IDUnique non-human identities with conditional access for AI agentsJune 2025
RSAC 2026 Innovation Sandbox winnerGeordie AI (AI agent detection, first visibility in 10 minutes)April 2026
Total NHI-focused funding rounds (12 months)>$340 million aggregated2025–2026

NHI Statistics by Identity Type

Service Accounts, API Keys, OAuth Tokens, Certificates, AI Agents

NHI TypeKey Risk MetricSource
Service accounts47% over one year old with no rotation; 8% with no HR ownerRubrik Zero Labs 2025
API keys (GitHub, public)28.65M new hardcoded instances in 2025GitGuardian State of Secrets Sprawl 2026
OAuth tokensSalesloft-Drift: single token breach gave access to hundreds of downstream envsObsidian Security 2025
MCP configuration secrets24,008 unique secrets exposed in MCP config files in first yearGitGuardian State of Secrets Sprawl 2026
AI agent credentialsFastest-growing NHI category; 1M+ AI agents created via Copilot Studio aloneCSA Whitepaper, May 2026
AWS machine identities with Admin privilege1 in 202026 State of Machine Identity Report
Credentials for AI services (YoY leak growth)+81%GitGuardian State of Secrets Sprawl 2026

AI agents are qualitatively distinct from the other NHI categories in this table, and the distinction is not semantic. Service accounts have a defined, predictable scope. AI agents decide at runtime which tools to call and which data to access. That nondeterminism means the “least-privilege” model — scoping access to what the credential actually needs — requires a fundamentally different architecture. Static role assignments designed for fixed automation do not contain dynamic agent behavior.

NHI Statistics by Industry

Which Sectors Face the Highest NHI Exposure?

IndustryKey NHI Exposure FactorMarket Regulatory RequirementPrimary Regulatory/Data Driver
Banking, Financial Services & Insurance (BFSI)Largest NHI market segment; massive automated transaction volumesPCI DSS 4.0 (mandatory NHI best practices from March 2025)PCI DSS 4.0
Healthcare$11.2M average breach cost; 279-day average detection windowHIPAA security rule; NHI governance not explicitly mandatedIBM Cost of a Data Breach 2025
IT & ITeSFastest NHI segment growth; highest microservices densitySOC 2, ISO 27001 (access governance applies to NHIs)Industry standard
Manufacturing / IndustrialAI and IIoT acceleration; OT/IT convergence creating new NHI surfaceNIS2 (EU); emerging ICS security frameworksNIS2, NIST CSF 2.0
Government / Public SectorU.S. federal zero-trust mandates; CISA guidance on identityOMB M-22-09 (zero-trust strategy); FedRAMPOMB / CISA
Retail / E-CommerceSaaS proliferation, payment API integrationsPCI DSS 4.0PCI DSS 4.0

BFSI dominates the NHI access management market by revenue because the regulatory exposure is explicit and measurable. PCI DSS 4.0 mandated NHI best practices as of March 2025 — meaning financial organizations that cannot demonstrate lifecycle governance for machine credentials are now carrying documented compliance risk, not just security risk. That changes the procurement conversation.

Healthcare is the expensive outlier in a different direction. At $11.2 million per breach — 2.5× the global average and the highest of any industry for fifteen consecutive years according to IBM — healthcare organizations are paying the price for poor access governance across both human and non-human identities. The 279-day average detection window in healthcare exceeds the credential-breach average by 33 days.

NHI Statistics by Region

Non-Human Identity Security Adoption by Geography

RegionMarket Share (2025)Key DriverSource
North America38.1%–38.5%Fortune 500 concentration; advanced IAM ecosystem; federal ZT mandatesGrand View / Market Intelo 2026
EuropeSignificant share (second largest)NIS2 Directive (Oct 2024); GDPR; DORA (Jan 2025)Data Bridge / Market Intelo 2026
Asia-PacificFastest-growing regionCloud adoption acceleration; manufacturing AI/IIoT deployments; China industrial digitalizationMarket Intelo / Grand View 2026
Rest of WorldEmerging marketsDigital transformation acceleration; growing regulatory awarenessMarket Intelo 2026

Europe’s regulatory timeline is compressing decision cycles. NIS2 — the EU Network and Information Security Directive 2 — took effect October 2024, extending cybersecurity obligations including access management requirements to a substantially wider set of industries. DORA — the Digital Operational Resilience Act — went live January 2025 for financial entities. The EU AI Act adds governance requirements for AI systems that directly map to AI agent identity controls. Organizations in scope for all three frameworks are dealing with overlapping NHI requirements from three directions simultaneously.

Axis Intelligence NHI Governance Exposure Index (Q2 2026)

Axis Intelligence Research has developed the NHI Governance Exposure Index (NHI-GEI) as a proprietary composite metric to quantify organizational governance gaps across the four dimensions most consistently cited in primary research. The index is calculated quarterly from published survey and incident data and updated each time any constituent metric is refreshed by its primary source.

The NHI-GEI combines four published statistics into a single composite exposure score:

  • Privilege exposure rate (% of NHIs with excessive privileges): 97% — Entro Security 2025
  • Rotation failure rate (% of NHIs unrotated beyond recommended intervals): 71% — Entro Security 2025
  • Policy absence rate (% of orgs with no documented AI identity policy): 78% — CSA-Oasis 2026
  • Visibility gap rate (% of orgs unable to distinguish AI agent activity from human activity): 79% — CSA-Oasis 2026 (cited in NHI Security Platform Comparison 2026)

Q2 2026 NHI-GEI composite score: 81.25/100 (average of the four constituent rates)

A score of 81.25 means the average enterprise, as of Q2 2026, is exposed on more than four of every five governance dimensions the index measures. A score of 0 would represent full governance coverage across all dimensions; 100 would represent complete governance failure. The Q2 2026 reading is a baseline. Axis Intelligence Research will update this index quarterly as constituent metrics are refreshed.

Methodology: The NHI-GEI is the arithmetic mean of four constituent rates, each drawn from the most recent available primary-source dataset. Where multiple surveys report the same metric, Axis Intelligence Research uses the most recent publication date. All four constituent sources are linked in the Methodology section below.

Methodology

How Axis Intelligence Research Assembled This Dataset

This report draws on primary sources published between January 2025 and June 2026. All statistics are cited inline to the issuing organization. The Axis Intelligence NHI Governance Exposure Index (NHI-GEI) is an original metric developed by Axis Intelligence Research; its four constituent inputs are drawn from Entro Security’s 2025 State of Non-Human Identities and Secrets in Cybersecurity, the CSA-Oasis State of NHI and AI Security 2026, and published CSA whitepaper data (May 2026). The enterprise-size NHI count estimates are derived by Axis Intelligence Research by applying three published ratio benchmarks (Identity Defined Security Alliance 50:1, CyberArk 82:1, Entro Security 144:1) to standard headcount bands. The NHI vector share-of-breach-cost calculation (minimum 37% of enterprise breach costs attributable to NHI-connected pathways) is an Axis Intelligence Research cross-reference of Verizon 2026 DBIR (22% credential initial access vector) and IBM Cost of a Data Breach 2025 (30% third-party involvement, $4.67M credential breach cost, $4.91M supply chain cost).

Primary sources used in this report:

Data limitations: NHI statistics vary by methodology and scope. Ratio figures (45:1, 82:1, 144:1) are not directly comparable because they cover different environment types. Market sizing varies by segment definition. Breach cost figures from IBM are based on surveyed organizations of 1,000+ employees and may not be representative of SMBs. Where a metric had multiple sources with different values, Axis Intelligence Research selected the most recent publication with a disclosed methodology.

Update cadence: This page is reviewed quarterly and refreshed when any of the primary sources above releases new data. The next scheduled update is Q3 2026 (September 30, 2026), aligned with the expected publication of IBM’s 2026 Cost of a Data Breach Report.

About This Dataset

License: CC BY 4.0 — You may share and adapt this data for any purpose, including commercial use, with attribution to Axis Intelligence Research.

Attribution format: Axis Intelligence Research. (2026, June 25). Non-Human Identity Statistics 2026. Axis Intelligence. https://axis-intelligence.com/non-human-identity-statistics/

Dataset download: Download NHI Statistics 2026 CSV

Contact for data requests or methodology questions: [email protected]

Cite This Research

APA: Axis Intelligence Research, & Chen, M. (2026, June 25). Non-human identity statistics 2026: The machine identity crisis by the numbers. Axis Intelligence. https://axis-intelligence.com/non-human-identity-statistics/

MLA: Axis Intelligence Research and Marcus Chen. “Non-Human Identity Statistics 2026: The Machine Identity Crisis by the Numbers.” Axis Intelligence, 25 June 2026, axis-intelligence.com/non-human-identity-statistics/.

Chicago: Axis Intelligence Research and Marcus Chen. “Non-Human Identity Statistics 2026: The Machine Identity Crisis by the Numbers.” Axis Intelligence, June 25, 2026. https://axis-intelligence.com/non-human-identity-statistics/.

Embed this research:

<blockquote>
  <p>"Non-human identities now outnumber human identities 45:1 in the average enterprise, reaching 144:1 in cloud-native environments, and 97% carry excessive privileges."</p>
  <footer>— <a href="https://axis-intelligence.com/non-human-identity-statistics/" rel="dofollow">Axis Intelligence Research, Non-Human Identity Statistics 2026</a></footer>
</blockquote>

Frequently Asked Questions

What is a non-human identity (NHI)?

A non-human identity is any digital credential that allows software, a service, or an automated system to authenticate without direct human login. This includes API keys, service accounts, OAuth tokens, machine certificates, bot credentials, workload identities, and AI agent credentials. Unlike human identities, NHIs typically bypass MFA, operate continuously without normal-hours behavioral baselines, and persist indefinitely without lifecycle management unless explicitly governed.

How many non-human identities does the average enterprise have?

The average enterprise runs at a 45:1 NHI-to-human ratio (Rubrik Zero Labs, 2025), meaning a 1,000-employee company has approximately 45,000 machine credentials in active circulation. Cloud-native environments and DevOps organizations run substantially higher: Entro Security’s analysis of 27 million NHIs across Fortune 500 enterprises put the cloud-native ratio at 144:1 as of H1 2025, up from 92:1 in H1 2024.

What percentage of NHIs have excessive privileges?

97%, according to Entro Security’s 2025 State of Non-Human Identities and Secrets in Cybersecurity report. Separately, OWASP’s NHI Top 10 (June 2025) ranks excessive permissions as the single most prevalent NHI vulnerability. The underlying driver is that developers creating service accounts and API keys grant broad permissions to reduce friction — and there is rarely an automated mechanism to right-size those permissions after the initial grant.

How often are NHIs rotated or revoked?

71% of NHIs are not rotated within recommended timeframes, according to Entro Security 2025. GitGuardian’s State of Secrets Sprawl 2026 found that 64% of credentials confirmed as valid in 2022 were still exploitable as of January 2026 — meaning the average remediation rate for known-leaked credentials is under 2 percentage points per quarter. The most common reason: organizations lack governance infrastructure to track which credentials exist, who owns them, and what their rotation schedule should be.

How much does an NHI-related breach cost?

IBM’s 2025 Cost of a Data Breach Report priced compromised-credential breaches — the primary NHI attack pathway — at $4.67 million per incident with a 246-day mean time to identify and contain. Where AI was involved (shadow AI incidents), the additional cost averaged $670,000 on top of the base figure. In the U.S., the average breach cost hit $10.22 million in 2025, an all-time high.

What is secrets sprawl, and how does it relate to NHI security?

Secrets sprawl is the uncontrolled proliferation of hardcoded credentials — API keys, passwords, tokens, certificates — across codebases, CI/CD pipelines, and collaboration tools. It is the primary mechanism by which NHIs become exposed to attackers. GitGuardian’s 2026 report found 28.65 million new hardcoded secrets in public GitHub in 2025 alone (+34% YoY), with internal repositories being 6× more likely to contain hardcoded secrets than public ones. Secrets sprawl and NHI governance are the same problem at different layers of the stack.

How are AI agents changing NHI security risk?

AI agents are NHIs with autonomous behavior: they decide at runtime which tools to call, which data to access, and which actions to take. Unlike static service accounts with fixed scopes, agents can dynamically escalate access, spawn sub-agents, and chain actions across systems. A compromised agent credential does not just expose one system — it exposes every system the agent is trusted to reach. Gartner projects 40% of enterprise applications will include task-specific AI agents by end of 2026 (up from under 5% in 2025), meaning the NHI population will grow at a rate that manual governance processes cannot track.

What regulations govern non-human identity management?

Regulatory pressure on NHI governance is increasing from multiple directions. PCI DSS 4.0 mandated NHI best practices from March 2025, directly affecting BFSI and retail. The EU’s NIS2 Directive (October 2024) and DORA (January 2025) extend access governance requirements to a broad set of European enterprises and financial entities. NIST’s Cybersecurity Framework 2.0 (published February 2024) and NIST 800-53 both carry access governance requirements that in principle apply to machine identities. SOC 2 and ISO 27001 auditors are increasingly asking specific questions about NHI lifecycle management. The EU AI Act adds a further governance layer for organizations deploying AI agents.

Who are the leading vendors in the NHI security market?

CyberArk leads the market following its 2024 acquisition of Venafi, managing over 200 million machine identities and reporting NHI-related revenue growth of over 35% in FY2025. Other significant platforms include SailPoint, BeyondTrust, HashiCorp (IBM), Delinea (which acquired StrongDM in March 2026), Okta (which acquired Axiom Security in September 2025), and Microsoft (which launched Entra Agent ID for AI agent identities in June 2025). Cloud hyperscalers — AWS IAM, Azure Entra Workload Identities, GCP Workload Identity Federation — provide native NHI management capabilities embedded in their platforms. Purpose-built NHI specialists including Oasis Security, Entro Security, GitGuardian, Astrix Security, Aembit, and Silverfort serve the cloud-native and mid-market segments.

Is there an OWASP standard for NHI security?

Yes. OWASP released the NHI Top 10 in June 2025, listing the ten most critical non-human identity vulnerabilities ranked by exploitability, prevalence, detectability, and impact. The number-one risk is excessive permissions — over-privileged credentials that give attackers a far wider blast radius than their initial access should permit. In December 2025, OWASP’s GenAI Security Project released a companion standard: the OWASP Top 10 for Agentic Applications 2026, specifically addressing AI agent identity risks.

Recent Posts

ERP Statistics 2026: Cloud ERP Revenue, Adoption Rates and the SAP 2027 Deadline

ERP Statistics 2026 By Axis Intelligence Research Co-author: Elena Rodriguez (SaaS & Business Software) | Last updat

Wireless Earbuds Statistics 2026: Shipments, Market Share and the Open-Ear Shift

Wireless Earbuds Statistics 2026 By Axis Intelligence Research Co-author: Alex Rivera, Consumer Tech | Last updated: Sep

Telehealth Adoption by Country 2026: Where Remote Doctor Visits Actually Stuck

Telehealth Adoption by Country 2026 By Axis Intelligence Research Co-author: Jennifer Miller, Digital Health | Last upda

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.