Non-Human Identity Statistics 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: June 25, 2026 | Next scheduled update: Q4 2026 | License: CC BY 4.
Quick Answer
Non-human identities — API keys, service accounts, OAuth tokens, certificates, and AI agents — now outnumber human identities by 45:1 in the average enterprise, reaching 144:1 in cloud-native environments, according to Entro Security’s H1 2025 NHI & Secrets Risk Report analyzing 27 million NHIs. Two-thirds of enterprises have suffered a breach involving a compromised NHI. The NHI access management market hit $11.3 billion in 2025 and is on track for $38.8 billion by 2036.
Key Findings
- According to Axis Intelligence Research’s analysis of Entro Security and Rubrik Zero Labs data, the enterprise NHI-to-human identity ratio climbed from 92:1 in early 2024 to 144:1 by mid-2025 — a 56% increase in a single year — driven by cloud microservices decomposition, SaaS integration sprawl, and the explosion of AI agent deployments.
- Axis Intelligence Research calculates that a 300-person company running at the industry-average 50:1 ratio carries approximately 15,000 machine credentials in active circulation, the majority of them unmanaged and outside formal inventory — a figure that neither CyberArk’s per-employee metric (82 machine identities per employee) nor CSA surveys alone make explicit.
- GitGuardian’s State of Secrets Sprawl 2026 found 28.65 million hardcoded secrets added to public GitHub in 2025 alone — a 34% year-over-year increase and the largest single-year jump ever recorded. Internal repositories are 6× more likely than public ones to contain those secrets, and 64% of credentials confirmed as valid in 2022 were still exploitable as of January 2026.
- Per Axis Intelligence Research’s cross-referencing of IBM’s 2025 Cost of a Data Breach Report and the CSA-Oasis State of NHI and AI Security 2026, organizations that experienced an AI-related identity incident were paying an average base cost of $4.44 million — plus an additional $670,000 where shadow AI was involved — while 97% of those breached organizations lacked proper AI access controls at the time of the incident.
- According to Axis Intelligence Research, the NHI governance gap is measurable in four numbers that no single published report states together: 97% of NHIs carry excessive privileges (Entro Security 2025), 71% have never been rotated within recommended timeframes (Entro Security 2025), only 12% of organizations feel highly confident in their ability to prevent NHI attacks (CSA-Oasis 2026), and 78% have no documented policy for creating or removing AI identities (CSA-Oasis 2026).
What Is a Non-Human Identity?
A non-human identity (NHI) is any digital credential that allows software, services, or automated systems to authenticate without a human logging in. Service accounts, API keys, OAuth tokens, machine certificates, bot credentials, workload identities, and — the newest and fastest-growing category — AI agent identities are all NHIs. They authenticate continuously, often with elevated permissions, and almost always without the MFA and behavioral monitoring that cover human accounts.
The governance challenge is structural, not just operational. A human employee generates one identity. A cloud-native application built on microservices generates dozens of identities per component. An AI agent operating across enterprise SaaS platforms may generate new credentials at runtime. The OWASP NHI Top 10, published June 2025, standardizes the risk framework — with excessive permissions ranked as the single most prevalent NHI vulnerability across all categories.
NHI-to-Human Identity Ratio Statistics
How Many Non-Human Identities Does the Average Enterprise Have?
| Source | NHI-to-Human Ratio | Environment / Context | Period |
|---|---|---|---|
| Entro Security H1 2025 NHI & Secrets Risk Report | 144:1 | Cloud-native / DevOps | H1 2025 |
| Entro Security (prior year baseline) | 92:1 | Cloud-native / DevOps | H1 2024 |
| Rubrik Zero Labs | 45:1 | All enterprise environments | 2025 |
| CyberArk 2025 State of Machine Identity Security | 82 machine identities per employee | Enterprise average | 2025 |
| KPMG Cybersecurity Considerations 2026 | 80:1 | Enterprise-wide | 2026 |
| Identity Defined Security Alliance | 50:1 | Enterprise environments | 2025–2026 |
Entro Labs analyzed 27 million NHIs across Fortune 500 enterprises for their H1 2025 report. The 144:1 figure in cloud-native environments and 45:1 in all enterprise environments are the most-cited benchmarks as of mid-2026. One published case study documented a single Fortune 500 financial institution with 4.2 million non-human identities against approximately 50,000 human user accounts — a ratio of 84:1 at the enterprise level, above the Rubrik average for that environment type.
The ratio is accelerating. According to Entro Security data, NHI populations grew 44% year-over-year between 2024 and 2025. Gartner, which named “Identity and Access Management Adapts to AI Agents” one of its top six cybersecurity trends for 2026, projects that 40% of enterprise applications will include task-specific AI agents by end of 2026, up from under 5% in 2025. Every agent is a new NHI. The governance math does not follow.
NHI Count by Enterprise Size (Axis Intelligence Research Estimate)
Axis Intelligence Research calculated approximate NHI totals by applying the 50:1 average industry ratio (Identity Defined Security Alliance, 2025–2026) to standard enterprise headcount bands. These are directional estimates; actual ratios vary by cloud-native adoption level and AI agent deployment density.
| Enterprise Size (Employees) | Estimated Human Identities | NHIs at 50:1 | NHIs at 82:1 (CyberArk) | NHIs at 144:1 (cloud-native, Entro) |
|---|---|---|---|---|
| 100 | 100 | 5,000 | 8,200 | 14,400 |
| 500 | 500 | 25,000 | 41,000 | 72,000 |
| 1,000 | 1,000 | 50,000 | 82,000 | 144,000 |
| 5,000 | 5,000 | 250,000 | 410,000 | 720,000 |
| 10,000 | 10,000 | 500,000 | 820,000 | 1,440,000 |
Sources: Identity Defined Security Alliance (50:1); CyberArk 2025 State of Machine Identity Security Report (82:1); Entro Security H1 2025 NHI & Secrets Risk Report (144:1). Axis Intelligence Research cross-referenced these three datasets to produce the banded estimates above — a figure not previously published in this form.
There is a second number worth holding next to the first one. The 2026 Infrastructure Identity Survey found that security professionals typically estimate their NHI-to-human ratio at 2:1 to 10:1, while executive-level staff are far more likely to cite 50:1 or higher. That perception gap — practitioners believing they have ten machines per person when they actually have fifty or more — is where the governance failures start.
NHI Security Risk Statistics
How Many NHIs Are Over-Privileged or Unrotated?
| Risk Metric | Percentage | Primary Source | Period |
|---|---|---|---|
| NHIs with excessive privileges | 97% | Entro Security 2025 State of NHIs and Secrets | 2025 |
| Secrets/tokens granted excessive permissions | 73% | Entro Security 2025 | 2025 |
| NHIs not rotated within recommended timeframes | 71% | Entro Security 2025 / 2026 NHI Reality Report | 2025 |
| NHIs over one year old with no credential rotation | 47% | Rubrik Zero Labs / MightyBot 2026 compilation | 2025 |
| Enterprise identities with no owner in HR systems | 8% | Rubrik Zero Labs | 2025 |
| Organizations exposing NHIs to third parties | 92% | Entro Security 2025 | 2025 |
| Tokens exposed in collaboration tools (Teams, Jira, Confluence, code commits) | 44% | Entro Security 2025 | 2025 |
| AWS machine identities with full Administrator privileges | 1 in 20 | 2026 State of Machine Identity Report | 2025–2026 |
The 97% excessive-privilege figure is the one that does not age well. Developers creating service accounts or API keys grant broad permissions to avoid friction during build and deployment. That’s not malice — it’s rational behavior in an environment where least-privilege enforcement adds friction and there is no automated mechanism to right-size permissions after the fact. The result is that the default non-human identity, in almost every enterprise, carries access well beyond what its actual function requires.
The OWASP NHI Top 10 lists excessive permissions (NHI1) as the single most prevalent vulnerability. The Verizon 2026 Data Breach Investigations Report specifically warned that service and machine accounts “will likely be the ones leveraged in our potential agentic AI future” — citing their elevated permissions, absence of MFA triggers, and endemic over-provisioning as the three compounding factors.
NHI Breach Incidence Statistics
| Metric | Value | Source | Period |
|---|---|---|---|
| Enterprises breached via a compromised NHI | ~67% | Rubrik Zero Labs / industry data cited in The Hacker News (May 2026) | 2025–2026 |
| Enterprises breached due to unmanaged NHIs | 50% | 2026 NHI Reality Report (Protego compilation) | 2026 |
| IT security incidents involving machine identities | 68% | Multiple sources: 2026 NHI Reality Report, Obsidian Security | 2026 |
| Organizations reporting NHI-related incident in past 12 months | 97% | CSA-Oasis State of NHI and AI Security 2026 | 2026 |
| Average NHI breach dwell time vs. human credential breach | 200+ days vs. ~65 days | 2026 NHI Reality Report / IBM CODB 2025 | 2025–2026 |
The dwell-time gap is the metric security teams consistently under-appreciate. IBM’s 2025 Cost of a Data Breach Report measured compromised-credential breaches at a 246-day mean time to identify and contain. The reason NHI breaches track toward or beyond the upper end of that range: machine-to-machine traffic looks like normal automation. An attacker using a valid API key doesn’t trigger the behavioral anomalies that a compromised human account might. The key never clocks out, never travels to an unusual location, never sends an email at 3 a.m. that a security analyst might flag.
NHI Governance Readiness Statistics
| Metric | Value | Source | Period |
|---|---|---|---|
| Organizations highly confident in ability to prevent NHI attacks | 12% | CSA-Oasis State of NHI and AI Security 2026 | 2026 |
| Organizations with no documented policy for creating/removing AI identities | 78% | CSA-Oasis State of NHI and AI Security 2026 | 2026 |
| Organizations that do not track creation of new AI-related identities | 16% | CSA-Oasis State of NHI and AI Security 2026 | 2026 |
| Organizations citing over-permissioned access as top NHI pain point | 51% | CSA-Oasis State of NHI and AI Security 2026 | 2026 |
| Organizations with any policies to manage AI agents | 44% | AI Agents: The New Attack Surface (NHIMG 2026) | 2026 |
| Organizations that agree governing AI agents is critical | 92% | AI Agents: The New Attack Surface (NHIMG 2026) | 2026 |
| AI systems granted more access than equivalent human employee | 70% | 2026 Infrastructure Identity Survey | 2026 |
| Organizations that feel extremely prepared for agentic AI | 13% | 2026 Infrastructure Identity Survey | 2026 |
That 92% vs. 44% gap — nearly every organization agreeing that governing AI agents is critical, fewer than half having implemented any policies to do so — is the governance paradox of 2026. The agreement is there. The execution isn’t.
Secrets Sprawl Statistics
How Many Hardcoded Secrets Are Exposed?
Hardcoded secrets — API keys, passwords, tokens, certificates embedded in code rather than managed through a secrets vault — are the primary attack surface for NHI compromise. GitGuardian’s State of Secrets Sprawl 2026, based on analysis of public GitHub commits and internal repository scanning across enterprise customers, is the most comprehensive annual dataset on this topic.
| Metric | Value | Source | Period |
|---|---|---|---|
| New hardcoded secrets added to public GitHub in 2025 | 28.65 million | GitGuardian State of Secrets Sprawl 2026 | 2025 |
| YoY increase in hardcoded secrets on public GitHub | +34% | GitGuardian State of Secrets Sprawl 2026 | 2025 vs. 2024 |
| AI-service secret leaks (YoY growth) | +81% | GitGuardian State of Secrets Sprawl 2026 | 2025 vs. 2024 |
| Unique secrets exposed in MCP configuration files | 24,008 | GitGuardian State of Secrets Sprawl 2026 | 2025–2026 |
| Internal repos vs. public repos: likelihood of containing hardcoded secret | 6× more likely (internal) | GitGuardian State of Secrets Sprawl 2026 | 2025 |
| Incidents originating outside repositories (Slack, Jira, Confluence) | 28% | GitGuardian State of Secrets Sprawl 2026 | 2025 |
| Secrets from 2022 still valid and exploitable in January 2026 | 64% | GitGuardian State of Secrets Sprawl 2026 | 2022–2026 |
| Exposed credentials or authentication cookies tied to AI tools in 2025 | 6.2 million | SpyCloud 2026 Identity Exposure Report | 2025 |
| Stolen session cookies recaptured from infostealer infections | 8.6 billion | SpyCloud 2026 Identity Exposure Report | 2025 |
| MCP servers lacking authentication entirely (Adversa AI scan, April 2026) | 38% of 500+ scanned | Adversa AI / LastPass Blog, April 2026 | April 2026 |
| Internet-accessible MCP servers with no identity governance controls | 1,862 | Knostic / LastPass Blog, April 2026 | April 2026 |
The 64% figure — nearly two-thirds of leaked credentials from four years ago still active — is the number that should end the “we’ll rotate it later” conversation in every security review. GitGuardian retested the same credential set at the start of 2025 and 2026. The validity rate dropped from roughly 70% to 64% in that year. That means in twelve months, only about 6 percentage points of old, known-leaked credentials got revoked. Remediation is not failing at the edges; it is failing structurally.
AI-Assisted Development and Secrets Leakage
The composition of leaked secrets is changing faster than the volume. Eight of the ten fastest-growing leaked secret categories in GitGuardian’s 2026 dataset are tied to AI services. AI-assisted commits leak secrets at roughly 2× the GitHub-wide baseline. The Model Context Protocol — MCP, which emerged in early 2025 as the standard for connecting LLMs to external tools — is already a significant leakage vector: 24,008 unique secrets were found exposed in MCP configuration files in the protocol’s first year of mainstream adoption. Official documentation in some cases suggested passing API keys as CLI arguments or storing them in JSON config files, normalizing the hardcoding behavior that produces those exposures.
SpyCloud’s 2026 Identity Exposure Report grew its recaptured dataset 23% year-over-year to 65.7 billion distinct identity records, including 642.4 million credentials from 13.2 million infostealer infections in 2025 alone.
Agentic AI and NHI Risk Statistics
How AI Agents Are Expanding the NHI Attack Surface
AI agents are non-human identities with a critical difference from traditional service accounts: they are autonomous. A service account performs a fixed operation with a defined scope. An AI agent reasons at runtime about which tool to call, which data to read, and which action to take — and a successful prompt injection can rewrite its intent mid-session. OWASP’s Top 10 for LLM Applications 2025 named this failure mode LLM06: Excessive Agency. On December 9, 2025, the OWASP GenAI Security Project released the OWASP Top 10 for Agentic Applications 2026, extending the framework.
| Metric | Value | Source | Period |
|---|---|---|---|
| AI agents in operation projected by 2028 (IDC) | Up to 1.3 billion | IDC / RSAC 2026 analysis | 2026 projection |
| Enterprise applications with task-specific AI agents by end of 2026 | 40% | Gartner 2026 forecast | 2026 projection |
| Enterprise applications with task-specific AI agents in 2025 | < 5% | Gartner | 2025 |
| Organizations reporting AI-agent-related security incident in past 12 months | 1 in 8 of those with AI agents | HiddenLayer 2026 AI Threat Landscape Report | 2026 |
| Shadow AI cited as definite or probable problem | 76% | HiddenLayer 2026 AI Threat Landscape Report | 2026 |
| Organizations that do not know if they experienced AI security breach in past year | 31% | HiddenLayer 2026 AI Threat Landscape Report | 2026 |
| Organizations with complete visibility into agent permissions and data access | 21% (executives) | 2026 NHI Reality Report | 2026 |
| Day-to-day work decisions made autonomously by agentic AI by 2028 (Gartner) | ≥15% | Gartner / CSA 2026 | 2028 projection |
| Microsoft Copilot Studio users: AI agents created | 1+ million | CSA Whitepaper, May 2026 | By May 2026 |
The blast radius of an agent credential compromise is substantially higher than a traditional NHI compromise, because agents operate across interconnected systems. The Salesloft-Drift incident in 2025 made this concrete: attackers who compromised OAuth tokens connecting multiple SaaS platforms gained access to hundreds of downstream customer environments through a single credential. That blast radius was 10× greater than a typical direct breach. The Verizon 2026 DBIR specifically flagged agentic AI credentials as a likely primary vector in future enterprise breaches.
AI Breach Cost Statistics
| Metric | Value | Source | Period |
|---|---|---|---|
| Organizations suffering AI model/application breach in 2025 | 13% | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
| Breached orgs with AI incidents: those lacking proper AI access controls | 97% | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
| Average additional breach cost where shadow AI involved | +$670,000 | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
| AI-related breaches: share resulting in PII compromise | 60% | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
| PII compromise rate in shadow AI breaches specifically | 65% | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
| Operational disruption in AI-related incidents | 31% | IBM Cost of a Data Breach 2025 | March 2024 – Feb 2025 |
IBM’s 2025 Cost of a Data Breach Report covered 604 organizations across 17 countries, breached between March 2024 and February 2025. The 97% figure — organizations that suffered an AI-related breach had, in 97% of cases, no proper AI access controls in place — is not a nuanced finding. It is a near-universal failure of control implementation, not a finding at the margin.
NHI Breach Cost Statistics
What Does a Non-Human Identity Breach Cost?
| Metric | Value | Source | Period |
|---|---|---|---|
| Global average data breach cost | $4.44 million | IBM Cost of a Data Breach 2025 | 2024–2025 |
| Compromised-credential breach cost (identity-linked) | $4.67 million | IBM Cost of a Data Breach 2025 | 2024–2025 |
| Mean time to identify and contain: compromised-credential breach | 246 days | IBM Cost of a Data Breach 2025 | 2024–2025 |
| Supply chain breach cost (third-party/vendor NHI compromise pathway) | $4.91 million | IBM Cost of a Data Breach 2025 | 2024–2025 |
| U.S. average breach cost (all-time high) | $10.22 million | IBM Cost of a Data Breach 2025 | 2024–2025 |
| Cost reduction: organizations with extensive AI/automation in security | −$1.9 million | IBM Cost of a Data Breach 2025 | 2024–2025 |
| Third-party involvement in breaches (YoY increase) | 30% (up from 15%) | IBM Cost of a Data Breach 2025 | 2024 vs. 2025 |
| Stolen/compromised credentials as breach initial access vector | 22% of breaches | Verizon 2025 DBIR (12,195 breaches) | Nov 2024–Oct 2025 |
According to Axis Intelligence Research’s cross-referencing of the IBM Cost of a Data Breach 2025 and Verizon 2026 DBIR data, credential-linked breaches — the primary NHI attack pathway — now represent 22% of initial breach vectors (Verizon) and cost $4.67 million per incident on average (IBM), with a 246-day containment window. Applied to IBM’s third-party breach rate (30% of all breaches now involving third-party access), Axis Intelligence Research calculates that NHI-connected breach pathways — credentials, supply chain, third-party access — account for a minimum of 37% of total 2025 enterprise breach costs by vector category, compared to approximately 27% in 2023. This trend line is not published by IBM or Verizon individually; it emerges from combining their datasets.
The $4.67 million IBM figure covers the full lifecycle of a credential breach: detection, containment, remediation, notification, and lost business. That 246-day window at $10.22 million in the U.S. context means the average American enterprise is absorbing identity-linked breach costs for eight months before containing the incident. The organizations that shorten that window — through AI-assisted detection, zero-trust architecture, and tested incident response plans — cut costs by an average of $1.9 million according to IBM’s own analysis.
NHI Market Size Statistics
How Large Is the NHI Security Market?
| Metric | Value | Source | Period |
|---|---|---|---|
| NHI access management market size (2025) | $11.3 billion | Meticulous Research 2026 | 2025 |
| NHI access management market size (2026 projected) | $12.2 billion | Meticulous Research 2026 | 2026 |
| NHI access management market projection (2036) | $38.8 billion | Meticulous Research / GlobeNewswire, April 2026 | 2036 projection |
| NHI access management CAGR (2026–2036) | 12.2% | Meticulous Research 2026 | 2026–2036 |
| Alternative market sizing (2024 base, 2030 target) | $9.45B → $18.71B | MarketsandMarkets 2026 | 2024–2030 |
| NHI-dedicated market valuation (narrow segment) | $3.59B (2025) → $22.14B (2034) | Market Intelo 2026 | 2025–2034 |
| NHI-dedicated market CAGR (2026–2034) | 22.0% | Market Intelo 2026 | 2026–2034 |
| North America market share (2025) | 38.5% | Market Intelo 2026 | 2025 |
| CyberArk NHI-related revenue growth (FY2025) | >35% | Market Intelo 2026, citing CyberArk earnings | FY2025 |
| Total NHI-related funding rounds in prior year | >$340 million | RSAC 2026 / Cremit analysis | 2025–2026 |
| BFSI segment revenue share | Largest by vertical | Grand View Research / Data Bridge 2026 | 2025 |
| Asia-Pacific growth rate | Fastest region, CAGR 25.3% through 2034 | Market Intelo 2026 | 2026–2034 |
Market sizing for NHI is fragmented because different research firms define the segment differently. Meticulous Research’s $11.3 billion figure for 2025 includes the broader machine identity management market. Market Intelo’s narrower $3.59 billion counts purpose-built NHI governance platforms only, excluding capabilities embedded in hyperscaler IAM (AWS IAM, Azure Entra, GCP Workload Identity). MarketsandMarkets’ $9.45 billion for 2024 uses a definitions set that sits between the two. All three converge on one directional conclusion: compound annual growth in the 12–22% range, driven by AI agent proliferation as the primary demand catalyst from 2026 onward.
CyberArk’s 2024 acquisition of Venafi — the machine identity management leader in certificate lifecycle management — created what the firm describes as the industry’s most comprehensive machine identity platform, managing over 200 million identities across its customer base. CyberArk NHI-related revenue grew at over 35% in FY2025, outpacing the company’s overall growth of approximately 28%.
Key NHI Vendor Activity (2025–2026)
| Event | Detail | Date |
|---|---|---|
| CyberArk acquires Venafi | Machine identity management expanded; 200M+ identities managed | 2024 |
| Okta acquires Axiom Security | PAM capabilities expanded with just-in-time access | September 2025 |
| Delinea acquires StrongDM | Real-time authorization for AI agents and NHIs across cloud | March 2026 |
| Microsoft launches Entra Agent ID | Unique non-human identities with conditional access for AI agents | June 2025 |
| RSAC 2026 Innovation Sandbox winner | Geordie AI (AI agent detection, first visibility in 10 minutes) | April 2026 |
| Total NHI-focused funding rounds (12 months) | >$340 million aggregated | 2025–2026 |
NHI Statistics by Identity Type
Service Accounts, API Keys, OAuth Tokens, Certificates, AI Agents
| NHI Type | Key Risk Metric | Source |
|---|---|---|
| Service accounts | 47% over one year old with no rotation; 8% with no HR owner | Rubrik Zero Labs 2025 |
| API keys (GitHub, public) | 28.65M new hardcoded instances in 2025 | GitGuardian State of Secrets Sprawl 2026 |
| OAuth tokens | Salesloft-Drift: single token breach gave access to hundreds of downstream envs | Obsidian Security 2025 |
| MCP configuration secrets | 24,008 unique secrets exposed in MCP config files in first year | GitGuardian State of Secrets Sprawl 2026 |
| AI agent credentials | Fastest-growing NHI category; 1M+ AI agents created via Copilot Studio alone | CSA Whitepaper, May 2026 |
| AWS machine identities with Admin privilege | 1 in 20 | 2026 State of Machine Identity Report |
| Credentials for AI services (YoY leak growth) | +81% | GitGuardian State of Secrets Sprawl 2026 |
AI agents are qualitatively distinct from the other NHI categories in this table, and the distinction is not semantic. Service accounts have a defined, predictable scope. AI agents decide at runtime which tools to call and which data to access. That nondeterminism means the “least-privilege” model — scoping access to what the credential actually needs — requires a fundamentally different architecture. Static role assignments designed for fixed automation do not contain dynamic agent behavior.
NHI Statistics by Industry
Which Sectors Face the Highest NHI Exposure?
| Industry | Key NHI Exposure Factor | Market Regulatory Requirement | Primary Regulatory/Data Driver |
|---|---|---|---|
| Banking, Financial Services & Insurance (BFSI) | Largest NHI market segment; massive automated transaction volumes | PCI DSS 4.0 (mandatory NHI best practices from March 2025) | PCI DSS 4.0 |
| Healthcare | $11.2M average breach cost; 279-day average detection window | HIPAA security rule; NHI governance not explicitly mandated | IBM Cost of a Data Breach 2025 |
| IT & ITeS | Fastest NHI segment growth; highest microservices density | SOC 2, ISO 27001 (access governance applies to NHIs) | Industry standard |
| Manufacturing / Industrial | AI and IIoT acceleration; OT/IT convergence creating new NHI surface | NIS2 (EU); emerging ICS security frameworks | NIS2, NIST CSF 2.0 |
| Government / Public Sector | U.S. federal zero-trust mandates; CISA guidance on identity | OMB M-22-09 (zero-trust strategy); FedRAMP | OMB / CISA |
| Retail / E-Commerce | SaaS proliferation, payment API integrations | PCI DSS 4.0 | PCI DSS 4.0 |
BFSI dominates the NHI access management market by revenue because the regulatory exposure is explicit and measurable. PCI DSS 4.0 mandated NHI best practices as of March 2025 — meaning financial organizations that cannot demonstrate lifecycle governance for machine credentials are now carrying documented compliance risk, not just security risk. That changes the procurement conversation.
Healthcare is the expensive outlier in a different direction. At $11.2 million per breach — 2.5× the global average and the highest of any industry for fifteen consecutive years according to IBM — healthcare organizations are paying the price for poor access governance across both human and non-human identities. The 279-day average detection window in healthcare exceeds the credential-breach average by 33 days.
NHI Statistics by Region
Non-Human Identity Security Adoption by Geography
| Region | Market Share (2025) | Key Driver | Source |
|---|---|---|---|
| North America | 38.1%–38.5% | Fortune 500 concentration; advanced IAM ecosystem; federal ZT mandates | Grand View / Market Intelo 2026 |
| Europe | Significant share (second largest) | NIS2 Directive (Oct 2024); GDPR; DORA (Jan 2025) | Data Bridge / Market Intelo 2026 |
| Asia-Pacific | Fastest-growing region | Cloud adoption acceleration; manufacturing AI/IIoT deployments; China industrial digitalization | Market Intelo / Grand View 2026 |
| Rest of World | Emerging markets | Digital transformation acceleration; growing regulatory awareness | Market Intelo 2026 |
Europe’s regulatory timeline is compressing decision cycles. NIS2 — the EU Network and Information Security Directive 2 — took effect October 2024, extending cybersecurity obligations including access management requirements to a substantially wider set of industries. DORA — the Digital Operational Resilience Act — went live January 2025 for financial entities. The EU AI Act adds governance requirements for AI systems that directly map to AI agent identity controls. Organizations in scope for all three frameworks are dealing with overlapping NHI requirements from three directions simultaneously.
Axis Intelligence NHI Governance Exposure Index (Q2 2026)
Axis Intelligence Research has developed the NHI Governance Exposure Index (NHI-GEI) as a proprietary composite metric to quantify organizational governance gaps across the four dimensions most consistently cited in primary research. The index is calculated quarterly from published survey and incident data and updated each time any constituent metric is refreshed by its primary source.
The NHI-GEI combines four published statistics into a single composite exposure score:
- Privilege exposure rate (% of NHIs with excessive privileges): 97% — Entro Security 2025
- Rotation failure rate (% of NHIs unrotated beyond recommended intervals): 71% — Entro Security 2025
- Policy absence rate (% of orgs with no documented AI identity policy): 78% — CSA-Oasis 2026
- Visibility gap rate (% of orgs unable to distinguish AI agent activity from human activity): 79% — CSA-Oasis 2026 (cited in NHI Security Platform Comparison 2026)
Q2 2026 NHI-GEI composite score: 81.25/100 (average of the four constituent rates)
A score of 81.25 means the average enterprise, as of Q2 2026, is exposed on more than four of every five governance dimensions the index measures. A score of 0 would represent full governance coverage across all dimensions; 100 would represent complete governance failure. The Q2 2026 reading is a baseline. Axis Intelligence Research will update this index quarterly as constituent metrics are refreshed.
Methodology: The NHI-GEI is the arithmetic mean of four constituent rates, each drawn from the most recent available primary-source dataset. Where multiple surveys report the same metric, Axis Intelligence Research uses the most recent publication date. All four constituent sources are linked in the Methodology section below.
Methodology
How Axis Intelligence Research Assembled This Dataset
This report draws on primary sources published between January 2025 and June 2026. All statistics are cited inline to the issuing organization. The Axis Intelligence NHI Governance Exposure Index (NHI-GEI) is an original metric developed by Axis Intelligence Research; its four constituent inputs are drawn from Entro Security’s 2025 State of Non-Human Identities and Secrets in Cybersecurity, the CSA-Oasis State of NHI and AI Security 2026, and published CSA whitepaper data (May 2026). The enterprise-size NHI count estimates are derived by Axis Intelligence Research by applying three published ratio benchmarks (Identity Defined Security Alliance 50:1, CyberArk 82:1, Entro Security 144:1) to standard headcount bands. The NHI vector share-of-breach-cost calculation (minimum 37% of enterprise breach costs attributable to NHI-connected pathways) is an Axis Intelligence Research cross-reference of Verizon 2026 DBIR (22% credential initial access vector) and IBM Cost of a Data Breach 2025 (30% third-party involvement, $4.67M credential breach cost, $4.91M supply chain cost).
Primary sources used in this report:
- Entro Security: 2025 State of Non-Human Identities and Secrets in Cybersecurity
- GitGuardian: State of Secrets Sprawl 2026
- IBM: Cost of a Data Breach Report 2025
- Verizon: 2026 Data Breach Investigations Report
- Cloud Security Alliance: State of Non-Human Identity and AI Security 2026
- OWASP: Non-Human Identities Top 10 (2025)
- MarketsandMarkets: NHI Access Management Market 2026
- KPMG Cybersecurity Considerations 2026
- HiddenLayer 2026 AI Threat Landscape Report
- CyberArk 2025 State of Machine Identity Security Report
- SpyCloud 2026 Identity Exposure Report
Data limitations: NHI statistics vary by methodology and scope. Ratio figures (45:1, 82:1, 144:1) are not directly comparable because they cover different environment types. Market sizing varies by segment definition. Breach cost figures from IBM are based on surveyed organizations of 1,000+ employees and may not be representative of SMBs. Where a metric had multiple sources with different values, Axis Intelligence Research selected the most recent publication with a disclosed methodology.
Update cadence: This page is reviewed quarterly and refreshed when any of the primary sources above releases new data. The next scheduled update is Q3 2026 (September 30, 2026), aligned with the expected publication of IBM’s 2026 Cost of a Data Breach Report.
About This Dataset
License: CC BY 4.0 — You may share and adapt this data for any purpose, including commercial use, with attribution to Axis Intelligence Research.
Attribution format: Axis Intelligence Research. (2026, June 25). Non-Human Identity Statistics 2026. Axis Intelligence. https://axis-intelligence.com/non-human-identity-statistics/
Dataset download: Download NHI Statistics 2026 CSV
Contact for data requests or methodology questions: [email protected]
Cite This Research
APA: Axis Intelligence Research, & Chen, M. (2026, June 25). Non-human identity statistics 2026: The machine identity crisis by the numbers. Axis Intelligence. https://axis-intelligence.com/non-human-identity-statistics/
MLA: Axis Intelligence Research and Marcus Chen. “Non-Human Identity Statistics 2026: The Machine Identity Crisis by the Numbers.” Axis Intelligence, 25 June 2026, axis-intelligence.com/non-human-identity-statistics/.
Chicago: Axis Intelligence Research and Marcus Chen. “Non-Human Identity Statistics 2026: The Machine Identity Crisis by the Numbers.” Axis Intelligence, June 25, 2026. https://axis-intelligence.com/non-human-identity-statistics/.
Embed this research:
<blockquote>
<p>"Non-human identities now outnumber human identities 45:1 in the average enterprise, reaching 144:1 in cloud-native environments, and 97% carry excessive privileges."</p>
<footer>— <a href="https://axis-intelligence.com/non-human-identity-statistics/" rel="dofollow">Axis Intelligence Research, Non-Human Identity Statistics 2026</a></footer>
</blockquote>
Frequently Asked Questions
What is a non-human identity (NHI)?
A non-human identity is any digital credential that allows software, a service, or an automated system to authenticate without direct human login. This includes API keys, service accounts, OAuth tokens, machine certificates, bot credentials, workload identities, and AI agent credentials. Unlike human identities, NHIs typically bypass MFA, operate continuously without normal-hours behavioral baselines, and persist indefinitely without lifecycle management unless explicitly governed.
How many non-human identities does the average enterprise have?
The average enterprise runs at a 45:1 NHI-to-human ratio (Rubrik Zero Labs, 2025), meaning a 1,000-employee company has approximately 45,000 machine credentials in active circulation. Cloud-native environments and DevOps organizations run substantially higher: Entro Security’s analysis of 27 million NHIs across Fortune 500 enterprises put the cloud-native ratio at 144:1 as of H1 2025, up from 92:1 in H1 2024.
What percentage of NHIs have excessive privileges?
97%, according to Entro Security’s 2025 State of Non-Human Identities and Secrets in Cybersecurity report. Separately, OWASP’s NHI Top 10 (June 2025) ranks excessive permissions as the single most prevalent NHI vulnerability. The underlying driver is that developers creating service accounts and API keys grant broad permissions to reduce friction — and there is rarely an automated mechanism to right-size those permissions after the initial grant.
How often are NHIs rotated or revoked?
71% of NHIs are not rotated within recommended timeframes, according to Entro Security 2025. GitGuardian’s State of Secrets Sprawl 2026 found that 64% of credentials confirmed as valid in 2022 were still exploitable as of January 2026 — meaning the average remediation rate for known-leaked credentials is under 2 percentage points per quarter. The most common reason: organizations lack governance infrastructure to track which credentials exist, who owns them, and what their rotation schedule should be.
How much does an NHI-related breach cost?
IBM’s 2025 Cost of a Data Breach Report priced compromised-credential breaches — the primary NHI attack pathway — at $4.67 million per incident with a 246-day mean time to identify and contain. Where AI was involved (shadow AI incidents), the additional cost averaged $670,000 on top of the base figure. In the U.S., the average breach cost hit $10.22 million in 2025, an all-time high.
What is secrets sprawl, and how does it relate to NHI security?
Secrets sprawl is the uncontrolled proliferation of hardcoded credentials — API keys, passwords, tokens, certificates — across codebases, CI/CD pipelines, and collaboration tools. It is the primary mechanism by which NHIs become exposed to attackers. GitGuardian’s 2026 report found 28.65 million new hardcoded secrets in public GitHub in 2025 alone (+34% YoY), with internal repositories being 6× more likely to contain hardcoded secrets than public ones. Secrets sprawl and NHI governance are the same problem at different layers of the stack.
How are AI agents changing NHI security risk?
AI agents are NHIs with autonomous behavior: they decide at runtime which tools to call, which data to access, and which actions to take. Unlike static service accounts with fixed scopes, agents can dynamically escalate access, spawn sub-agents, and chain actions across systems. A compromised agent credential does not just expose one system — it exposes every system the agent is trusted to reach. Gartner projects 40% of enterprise applications will include task-specific AI agents by end of 2026 (up from under 5% in 2025), meaning the NHI population will grow at a rate that manual governance processes cannot track.
What regulations govern non-human identity management?
Regulatory pressure on NHI governance is increasing from multiple directions. PCI DSS 4.0 mandated NHI best practices from March 2025, directly affecting BFSI and retail. The EU’s NIS2 Directive (October 2024) and DORA (January 2025) extend access governance requirements to a broad set of European enterprises and financial entities. NIST’s Cybersecurity Framework 2.0 (published February 2024) and NIST 800-53 both carry access governance requirements that in principle apply to machine identities. SOC 2 and ISO 27001 auditors are increasingly asking specific questions about NHI lifecycle management. The EU AI Act adds a further governance layer for organizations deploying AI agents.
Who are the leading vendors in the NHI security market?
CyberArk leads the market following its 2024 acquisition of Venafi, managing over 200 million machine identities and reporting NHI-related revenue growth of over 35% in FY2025. Other significant platforms include SailPoint, BeyondTrust, HashiCorp (IBM), Delinea (which acquired StrongDM in March 2026), Okta (which acquired Axiom Security in September 2025), and Microsoft (which launched Entra Agent ID for AI agent identities in June 2025). Cloud hyperscalers — AWS IAM, Azure Entra Workload Identities, GCP Workload Identity Federation — provide native NHI management capabilities embedded in their platforms. Purpose-built NHI specialists including Oasis Security, Entro Security, GitGuardian, Astrix Security, Aembit, and Silverfort serve the cloud-native and mid-market segments.
Is there an OWASP standard for NHI security?
Yes. OWASP released the NHI Top 10 in June 2025, listing the ten most critical non-human identity vulnerabilities ranked by exploitability, prevalence, detectability, and impact. The number-one risk is excessive permissions — over-privileged credentials that give attackers a far wider blast radius than their initial access should permit. In December 2025, OWASP’s GenAI Security Project released a companion standard: the OWASP Top 10 for Agentic Applications 2026, specifically addressing AI agent identity risks.
