Machine Identity Statistics 2026
By Axis Intelligence Research and Marcus Chen | Updated 2026 | Last updated: June 15, 2026 | Next scheduled update: Q3 2026 (September)
Quick Answer
Machine identities now outnumber human identities by 109 to 1, according to Palo Alto Networks’ 2026 Identity Security Landscape report — up from 82 to 1 just one year earlier, a 32.9% jump in the ratio itself. Of those 109 machine identities per human, 79 are AI agents. According to Axis Intelligence’s cross-vendor analysis, averaging this figure against three other independently-published 2025-2026 ratios (Veza’s 17:1, Entro Labs’ 144:1, and Rubrik Zero Labs’ 45:1) produces a Machine Identity Ratio Composite of approximately 79:1 — with a median of 77:1 — illustrating both the scale of the shift and how widely individual vendor methodologies diverge. Separately, GitGuardian’s 2026 report found 28.65 million new hardcoded secrets exposed on public GitHub in 2025 (+34% YoY), with AI-service-related leaks surging 81.5%.
Key Findings
- Machine identities outnumber humans 109:1 in 2026, up from 82:1 in 2025 (+32.9%), according to Palo Alto Networks’ 2026 Identity Security Landscape report, based on a survey of 2,930 cybersecurity decision-makers worldwide.
- AI agents account for 79 of every 109 machine identities (72.5%) — and companies expect AI agent identities specifically to grow 85% over the next 12 months, faster than machine identities overall (+77%) or human identities (+56%).
- According to Axis Intelligence, averaging four independently-published 2025-2026 machine-to-human identity ratios (109:1, 17:1, 144:1, and 45:1) produces a Machine Identity Ratio Composite of ~79:1 (median 77:1) — a single benchmark for a metric that currently varies more than 8-fold depending on which vendor’s survey is consulted.
- GitGuardian detected 28.65 million new hardcoded secrets on public GitHub in 2025 (+34% YoY, the largest single-year jump on record), with AI-service-related credential leaks growing 81.5% — and 64% of secrets confirmed valid in 2022 remain exploitable as of January 2026.
- The CA/Browser Forum’s approved timeline cuts maximum TLS certificate validity from 398 days today to 47 days by March 2029 — an 8.47x increase in annual renewal frequency — while 90% of organizations report having suffered an identity-related breach in the past 12 months.
Every enterprise now runs on a population of digital identities that almost nobody can see in full: service accounts, API keys, workload certificates, OAuth tokens, and — increasingly — autonomous AI agents, each one authenticating, accessing data, and acting on systems without a human directly behind the keyboard. In 2025, that population grew faster than security teams could track it, and in 2026 the gap between how many machine identities exist and how many are actually governed has become one of the defining metrics in cybersecurity.
This report compiles verified 2025-2026 data from Palo Alto Networks’ 2026 Identity Security Landscape report (the successor to CyberArk’s annual survey following Palo Alto’s acquisition of CyberArk), Veza’s State of Identity & Access 2026, Entro Labs’ NHI & Secrets Risk Report, Rubrik Zero Labs, GitGuardian’s State of Secrets Sprawl 2026, the CA/Browser Forum’s certificate validity reduction timeline, and a December 2025 NIST/CISA interagency report on machine credential security. It also introduces two original Axis Intelligence cross-source metrics: the Machine Identity Ratio Composite and the AI Identity Acceleration Premium.
The Machine-to-Human Identity Ratio: 2026 Landscape
The single most-cited statistic in identity security took a sharp jump this year. Palo Alto Networks’ 2026 Identity Security Landscape report — based on responses from 2,930 cybersecurity decision-makers worldwide, and the direct successor to CyberArk’s “Identity Security Landscape” series following Palo Alto’s acquisition of CyberArk — found that machine identities, including AI agents, now outnumber human identities 109 to 1. That figure is itself a significant jump: the same report series put the ratio at 82:1 just one year earlier, meaning the ratio increased by nearly a third (+32.9%) in a single year.
The composition of that 109:1 figure is what makes 2026’s data different from prior years. Of the 109 machine identities per human, 79 are AI agents — meaning AI agents alone account for roughly 72.5% of all machine identities in the average enterprise. Respondents expect this to keep accelerating: organizations project machine identities overall will grow 77% over the next 12 months, human identities will grow 56%, and AI agent identities specifically will grow 85% — the fastest of the three.
The operational reality behind these numbers is sobering. Ninety-nine percent of organizations have adopted AI agents, and 91% are already running autonomous agents in production — but governance has not kept pace. Only 37% of organizations can revoke an AI agent’s credentials, and only 30% have immutable audit logging for what those agents do, even though 40% of deployed AI agents already have access to organizational data. Ninety percent of organizations report at least one identity-related breach in the past 12 months, and 83% report two or more. Fragmented identity tooling compounds the problem operationally: 97% of practitioners report that fragmented tools add time to identity-related incident response, with an average of 12 additional hours per incident.
According to Axis Intelligence: The Machine Identity Ratio Composite
“How many machine identities exist for every human identity?” is the single most-quoted statistic in this field — and yet four major reports published within the same 12-month window give answers that differ by more than 8x. No source currently averages them into a single benchmark. Axis Intelligence’s Machine Identity Ratio Composite does exactly that.
| Source | Ratio (Machine:Human) | Scope |
|---|---|---|
| Palo Alto Networks, 2026 Identity Security Landscape | 109:1 | General enterprise, global |
| Entro Labs, NHI & Secrets Risk Report H1 2025 | 144:1 | Cloud-native / DevOps environments |
| Rubrik Zero Labs | 45:1 | General enterprise |
| Veza, State of Identity & Access 2026 | 17:1 | General enterprise |
| Axis Composite (average) | ~79:1 | — |
| Axis Composite (median) | 77:1 | — |
According to Axis Intelligence’s analysis, averaging these four independently-published 2025-2026 ratios produces a composite of approximately 79:1, with a median of 77:1 — both landing close to Palo Alto’s own prior-year figure of 82:1, even though the four source reports individually range from 17:1 to 144:1. That range itself is a finding: the highest reported ratio (Entro Labs’ 144:1) is specific to cloud-native and DevOps environments, where ephemeral containers, CI/CD pipelines, and service meshes generate far more short-lived identities than a typical enterprise average — while Veza’s 17:1, the lowest, reflects a broader enterprise population that includes many organizations earlier in cloud adoption.
Methodology and stated assumptions. Axis Intelligence flags three caveats:
- Methodology heterogeneity. The four source reports use different methodologies — Palo Alto and Veza rely on practitioner surveys, while Entro Labs and Rubrik Zero Labs derive figures from direct telemetry/scanning of customer environments. Survey-based and telemetry-based ratios are not strictly equivalent, but both are commonly cited as “the” machine-to-human ratio in industry discourse, which is precisely why a composite is useful.
- Population scope. Entro Labs’ 144:1 is explicitly scoped to cloud-native/DevOps environments, which structurally produce more machine identities than a cross-industry average. Including it raises the composite but reflects a real and growing segment of the enterprise population.
- Time alignment. Figures span H1 2025 (Entro Labs) through 2026 (Palo Alto, Veza), an approximately 12-month window — treated as “current” for composite purposes given how rapidly this ratio is changing (Palo Alto’s own figure moved 33% in one year).
This composite will be recalculated as each underlying report releases its next annual edition — and given Palo Alto’s own ratio grew from 82:1 to 109:1 in one year, Axis Intelligence expects the next composite to rise as well.
Secrets Sprawl: GitGuardian’s 2026 Findings
If machine identities are the population, secrets — API keys, tokens, passwords, certificates, and connection strings — are what each identity uses to authenticate. GitGuardian’s State of Secrets Sprawl 2026, the fifth edition of its annual report, found that 28.65 million new hardcoded secrets were detected in public GitHub commits in 2025 — a 34% increase over 2024 and the largest single-year jump the company has recorded since it began publishing the report.
The report’s central finding is that AI adoption is the primary accelerant. AI-service-related credential leaks — API keys for OpenAI, Anthropic, and similar services — surged 81.5% year-over-year, more than double the overall growth rate. The Model Context Protocol (MCP), which emerged as a standard for connecting AI models to external tools and data sources in 2025, already shows the same pattern: GitGuardian found 24,008 unique secrets exposed in MCP-related configuration files in its first year of widespread adoption, of which 2,117 (8.8%) were verified as live, valid credentials — driven in part by official MCP setup guides that recommend embedding API keys directly into configuration files or command-line arguments.
Remediation is the report’s starkest finding. 64% of secrets confirmed valid in 2022 remain exploitable as of January 2026 — meaning the majority of credentials exposed four years ago have neither been rotated nor revoked. Internal repositories, collaboration tools, and self-hosted infrastructure compound public exposure: internal repositories are six times more likely than public repositories to contain hardcoded secrets, and roughly 28% of secrets-related incidents originate in collaboration and productivity tools rather than code at all. The “Shai-Hulud 2” supply-chain attack illustrated the real-world consequence: across 6,943 compromised machines, GitGuardian identified 294,842 secret occurrences, with 59% of compromised machines being CI/CD runners rather than individual developer workstations.
Longitudinally, the trend is widening rather than narrowing: since 2021, leaked secrets have grown 152% while GitHub’s public developer base grew 98% — secrets sprawl is outpacing the growth of the developer population that creates them, a gap that AI-assisted coding appears to be widening further, with AI-assisted commits leaking secrets at roughly twice the baseline rate across public GitHub.
According to Axis Intelligence: The AI Identity Acceleration Premium
Two independent 2025-2026 reports — Palo Alto Networks’ identity survey and GitGuardian’s secrets-exposure telemetry — each measured how much faster AI-specific activity is growing compared to the broader machine-identity/secrets trend they were already tracking. Neither report compared its own AI-specific growth rate to the other’s. Axis Intelligence’s AI Identity Acceleration Premium does.
| Source | AI-Specific Growth | Overall Growth | Premium |
|---|---|---|---|
| Palo Alto Networks (projected AI agent identity growth vs. overall machine identity growth, next 12 months) | +85% | +77% | +8.0 points |
| GitGuardian (AI-service secret leak growth vs. overall secret leak growth, 2025) | +81.5% | +34% | +47.5 points |
| Axis Average Premium | — | — | +27.8 points |
According to Axis Intelligence’s cross-source calculation, AI-specific identity and credential growth outpaces overall machine-identity growth by an average of 27.8 percentage points across these two independent measurements — confirming, from two unrelated data sources measuring two different things (identity counts vs. leaked credentials), that AI is not just part of the machine-identity explosion but its primary accelerant.
Methodology and stated assumptions:
- Different units, same direction. Palo Alto’s figures measure projected identity counts; GitGuardian’s measure observed credential leak volume. These are not the same metric, but both express “AI-specific growth relative to a broader baseline the same report already measures” — which is the quantity this Index isolates.
- Forward-looking vs. retrospective. Palo Alto’s figures are 12-month projections from survey respondents; GitGuardian’s are observed 2025 actuals. The premium therefore blends expectation and observation — a limitation Axis Intelligence will be able to resolve once Palo Alto’s 2027 edition reports actuals against this year’s projection.
- Wide individual variance. The two premiums (+8.0pp and +47.5pp) differ substantially — GitGuardian’s secrets-exposure data shows a far steeper AI-specific acceleration than Palo Alto’s identity-count projections. The average smooths this, but the underlying spread is itself notable: it suggests AI’s impact may be most visible first in credential exposure (a leading indicator) before it fully shows up in identity counts (a lagging one).
This connects directly to Axis Intelligence’s AI agents statistics hub, which tracks the deployment-side growth of agentic AI systems — the AI Identity Acceleration Premium quantifies the identity-security shadow that deployment growth casts.
The Certificate Lifecycle Shift: 47-Day TLS Certificates by 2029
TLS certificates are themselves a category of machine identity — and the rules governing how long they can live are about to change more dramatically than at any point in the history of the public web. On April 11, 2025, the CA/Browser Forum’s Server Certificate Working Group approved Ballot SC-081v3, originally proposed by Apple, by a vote of 29 in favor and none opposed. The approved timeline phases down maximum public TLS certificate validity from the current 398 days (in effect since September 2020) to 200 days starting March 15, 2026, to 100 days starting March 15, 2027, and finally to 47 days starting March 15, 2029.
The operational consequence is an 8.47x increase in annual renewal frequency: a certificate that needed renewing roughly once a year today will need renewing every six to seven weeks by 2029. The ballot’s stated rationale is that shorter-lived certificates reduce the window during which a compromised private key or outdated validation remains exploitable, and accompanying reductions to domain-control-validation reuse windows are designed to force continuous re-verification rather than one-time setup.
For organizations already struggling with the 109:1 machine identity ratio described above, this timeline compounds an existing problem: certificates are one of the credential types that GitGuardian’s MCP findings show being mishandled, and Gartner’s PKI and Certificate Lifecycle Management guidance — cited across multiple certificate-automation vendors — now identifies certificate lifecycle complexity as a bigger operational challenge for many organizations than multi-factor authentication deployment. The 2026 deadline (200-day maximum) is the first to take effect, giving organizations roughly nine months from this report’s publication to establish automated certificate lifecycle management before manual renewal processes become operationally unsustainable.
US Policy: NIST and CISA Guidance on Machine Identity Security
Federal guidance on machine credential security advanced significantly in late 2025. On December 22, 2025, CISA and NIST jointly released a draft interagency report, NIST IR 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse”, with a public comment period that ran through January 30, 2026. The report provides implementation guidance for federal agencies and cloud service providers on protecting identity tokens and assertions — the credentials that machine identities and AI agents use to authenticate to systems — building on updates to NIST SP 800-53 and responding to a White House cybersecurity executive order amending Executive Orders 13694 and 14144.
The timing places this guidance squarely inside the trends documented above: it was published two months before Palo Alto’s 2026 survey found that only 37% of organizations can revoke an AI agent’s credentials, and as the CA/Browser Forum’s certificate-validity reductions begin taking effect. Read together, federal guidance on token security, the certificate lifecycle timeline, and the AI Identity Acceleration Premium all point in the same direction: machine credentials — however they’re implemented, as tokens, certificates, or API keys — are converging as the top identity-security priority for both regulators and enterprises simultaneously. This connects to the broader regulatory landscape tracked in Axis Intelligence’s AI governance statistics hub.
Machine Identity Management: Market Size and Outlook
The vendor response to this problem is itself measurable. The global machine identity management market was valued at $21.39 billion in 2026 and is projected to grow at a CAGR of 12.25% through 2035, according to eMudhra’s market analysis. Nearly 60% of machine identity management deployments are now cloud-based, reflecting the broader shift away from on-premises infrastructure documented throughout this report, and roughly 35% of solutions now integrate AI-driven anomaly detection — using AI to help govern the very AI-driven identity growth that is straining existing tools.
Despite this growing market, the underlying governance gap remains stark: an estimated 97% of non-human identities in organizations today carry over-privileged access, a figure consistent with the broader pattern Axis Intelligence has documented in its data breach statistics hub, where over-privileged credentials are a recurring root cause. The distinction between this report’s focus and Axis Intelligence’s identity theft statistics hub is worth making explicit: identity theft concerns the compromise of human identities (stolen SSNs, account takeovers, fraud), while machine identity security concerns an entirely separate — and numerically far larger — population of service accounts, API keys, certificates, and AI agents that most organizations cannot fully inventory, let alone protect.
Methodology
This report compiles data from six primary sources: Palo Alto Networks’ 2026 Identity Security Landscape report (2,930 respondents, the successor to CyberArk’s annual identity survey post-acquisition) for machine-to-human identity ratios and AI agent data; Veza’s 2026 State of Identity & Access report; Entro Labs’ NHI & Secrets Risk Report (H1 2025) for cloud-native/DevOps-specific ratios and credential aging data; Rubrik Zero Labs for breach-correlation data; GitGuardian’s State of Secrets Sprawl 2026 (its fifth annual edition) for credential exposure data; the CA/Browser Forum’s Ballot SC-081v3 for certificate lifecycle timelines; NIST/CISA’s IR 8587 (December 2025) for federal policy context; and eMudhra’s market analysis for machine identity management market sizing. All figures were live-verified via direct source retrieval on June 15, 2026.
The two original Axis Intelligence elements — the Machine Identity Ratio Composite and the AI Identity Acceleration Premium — each combine figures from independently-published reports using different survey populations, methodologies, and measurement windows. Each element’s calculation section above states the specific assumptions made. Given how rapidly these figures are moving — Palo Alto’s own ratio grew 33% in a single year — both elements are expected to shift materially at each quarterly refresh, and Axis Intelligence will track that movement explicitly rather than treating any single snapshot as stable.
About This Dataset
The complete dataset behind this report — 53 individual data points spanning identity ratios, secrets sprawl, certificate lifecycle data, machine identity market sizing, and both original Axis Intelligence indices — is available for download as a CSV file under a CC BY 4.0 license, free to use, share, and adapt with attribution to Axis Intelligence. Each row includes the metric, value, unit, geographic/environmental scope, time period, source organization, and source URL for independent verification.
This dataset will be refreshed quarterly. Palo Alto Networks, Veza, and Entro Labs publish their flagship identity-security reports annually (typically Q2 for Palo Alto and Veza, and at H1/H2 intervals for Entro Labs); GitGuardian publishes its State of Secrets Sprawl report annually each March; the CA/Browser Forum’s certificate-validity timeline has fixed milestone dates (March 2026, March 2027, March 2029) against which this report will track industry compliance; and NIST/CISA’s IR 8587 is expected to move from draft to final following its January 2026 comment period close. Both Axis original indices will be recalculated at each refresh using the most current figures from each underlying source — and as new annual editions of the underlying reports are published, additional vendor ratios will be incorporated into the Machine Identity Ratio Composite where methodology permits.
Explore the Data: Interactive Dashboard
The dashboard below visualizes the machine-to-human identity ratio trend, the Machine Identity Ratio Composite, GitGuardian’s secrets sprawl data, and the certificate lifecycle timeline from this report. (Editorial note: insert the following Custom HTML block at this position in Gutenberg.)
<div id="axis-machine-id-stats-wrap" style="border:1px solid #21262D;border-radius:10px;overflow:hidden;margin:32px 0;">
<iframe id="axis-machine-id-stats-iframe" src="/wp-content/dashboard/stats-machine-identity-statistics-dashboard.html" width="100%" height="1050" frameborder="0" scrolling="no" title="Machine Identity Statistics 2026 — Axis Intelligence Research" loading="lazy" style="display:block;">
</iframe>
</div>
<script>
(function(){
var iframe = document.getElementById("axis-machine-id-stats-iframe");
window.addEventListener("message", function(e){
if (e.data && e.data.axisIframeHeight) {
iframe.style.height = e.data.axisIframeHeight + "px";
}
});
})();
</script>
How to Cite This Research
APA: Axis Intelligence Research Desk & Chen, M. (2026). Machine Identity Statistics 2026: Non-Human Identity Ratios, Secrets Sprawl, and Certificate Lifecycle Data. Axis Intelligence. https://www.axis-intelligence.com/machine-identity-statistics/
MLA: Axis Intelligence Research Desk, and Marcus Chen. “Machine Identity Statistics 2026: Non-Human Identity Ratios, Secrets Sprawl, and Certificate Lifecycle Data.” Axis Intelligence, 2026, axis-intelligence.com/machine-identity-statistics/.
Chicago: Axis Intelligence Research Desk, and Marcus Chen. “Machine Identity Statistics 2026: Non-Human Identity Ratios, Secrets Sprawl, and Certificate Lifecycle Data.” Axis Intelligence. 2026. https://www.axis-intelligence.com/machine-identity-statistics/.
Frequently Asked Questions
What is the machine-to-human identity ratio in 2026?
Machine identities outnumber human identities 109 to 1 in 2026, according to Palo Alto Networks’ 2026 Identity Security Landscape report, based on a survey of 2,930 cybersecurity decision-makers worldwide.
How much did the machine identity ratio grow from 2025 to 2026?
The same report series found the ratio was 82:1 in 2025, meaning it grew by 32.9% in a single year — from 82 machine identities per human to 109.
What percentage of machine identities are AI agents?
Of every 109 machine identities per human, 79 are AI agents — approximately 72.5% of the total. AI agent identities are also projected to grow faster (85% over the next 12 months) than machine identities overall (77%) or human identities (56%).
What is the Axis Intelligence Machine Identity Ratio Composite?
It is an Axis Intelligence original metric averaging four independently-published 2025-2026 machine-to-human identity ratios — Palo Alto Networks (109:1), Entro Labs (144:1, cloud-native/DevOps), Rubrik Zero Labs (45:1), and Veza (17:1) — into a single composite of approximately 79:1, with a median of 77:1.
How many secrets were exposed on GitHub in 2025?
GitGuardian’s State of Secrets Sprawl 2026 found 28.65 million new hardcoded secrets exposed in public GitHub commits in 2025, a 34% increase over 2024 and the largest single-year jump on record. AI-service-related leaks grew 81.5% over the same period.
What is the AI Identity Acceleration Premium?
It is an Axis Intelligence original metric that averages two independent measurements of “AI-specific growth relative to overall growth”: Palo Alto Networks’ AI agent identity growth (+85%) versus overall machine identity growth (+77%), an 8-point premium; and GitGuardian’s AI-service secret leak growth (+81.5%) versus overall secret leak growth (+34%), a 47.5-point premium. The average across both is +27.8 percentage points.
When will TLS certificate validity drop to 47 days?
Under CA/Browser Forum Ballot SC-081v3, approved unanimously (29-0) on April 11, 2025, maximum public TLS certificate validity drops from 398 days to 200 days starting March 15, 2026, to 100 days starting March 15, 2027, and to 47 days starting March 15, 2029 — an 8.47x increase in annual renewal frequency from today’s baseline.
What is NIST IR 8587?
NIST IR 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” is a draft interagency report jointly released by NIST and CISA on December 22, 2025, providing implementation guidance for federal agencies and cloud service providers on securing the identity tokens and credentials used by machine identities and AI agents. Its public comment period closed January 30, 2026.
How big is the machine identity management market?
The global machine identity management market was valued at $21.39 billion in 2026 and is projected to grow at a 12.25% CAGR through 2035, according to eMudhra’s market analysis. Approximately 60% of deployments are cloud-based.
What percentage of organizations have experienced an identity-related breach?
90% of organizations report at least one identity-related breach in the past 12 months, and 83% report two or more, per Palo Alto Networks’ 2026 Identity Security Landscape report. Separately, Rubrik Zero Labs reports that two-thirds of enterprises have suffered a breach via a compromised non-human identity specifically — a pattern Axis Intelligence’s cybercrime statistics hub tracks across broader attack-vector categories.
