top of page

The 45 Billion Identity Problem Nobody Is Talking About

  • Jul 14
  • 5 min read

TBDCyber | Agentic AI Security Series



Every CISO has a handle on their human identity estate. You know roughly how many employees, contractors, and privileged accounts you have. You have a joiner-mover-leaver process. You run access certifications. You have someone who owns IAM.


Here is the number that process was not designed for: 45 billion.


That is the projected volume of non-human and agentic identities by the end of 2026, according to data published by the World Economic Forum citing Okta research. It surpasses the global human workforce by a factor of twelve. And the organizations responsible for governing that identity population, yours included, almost certainly are operating without a strategy for doing so.


The Invisible Workforce You Already Have


Before we get to autonomous agents, consider what is already operating in your environment. Service accounts running background processes. API keys embedded in codebases by developers who left two years ago. Machine certificates authenticating cloud workloads. RPA bots executing finance processes overnight. OAuth tokens connecting SaaS platforms to each other without a human in the loop.


In advanced enterprises, non-human identities already outnumber human employees at a ratio of 80:1. Most organizations have no formal governance process for them.


Research from Entro Security Labs finds that 94% of organizations lack full visibility into their service accounts. Forty percent of cloud non-human identities have no defined owner. Ninety-seven percent carry excessive privileges. And 91% of former employees' tokens remain active after they leave the organization.


Read that last one again. The person is gone. Their non-human identity estate largely is not.


This is the inheritance that agentic AI is being deployed on top of. Before the first autonomous agent was provisioned, most organizations were already managing a vast, largely invisible, heavily overprivileged population of non-human identities with inadequate tooling and no coherent lifecycle process.


Why Agentic AI Changes the Equation


The non-human identity problem is not new. Security professionals have been pointing at service account sprawl and credential exposure for years. What makes agentic AI different is not scale alone.


Traditional non-human identities are deterministic. A service account does what it was scripted to do. An RPA bot follows its workflow. The same input produces the same output. You can model their behavior, set a baseline, and detect deviations. Their access scope is defined at provisioning and stays there.


Agentic AI systems are not deterministic. They reason. They plan. They select tools dynamically based on context. The same instruction can produce different action sequences depending on what the agent encounters along the way. They can spawn sub-identities, chain tools in ways their creators did not anticipate, and operate across multiple systems simultaneously at machine speed.


80% of organizations report that their AI agents have already taken unintended actions. That figure, from Dimensional Research on behalf of SailPoint, should sit uncomfortably with every security leader who has signed off on an agentic AI deployment without specifically updating their governance posture.


The Proliferation Is Already Underway


The 45 billion figure is an aggregate projection. What matters for security leaders is understanding where that population is coming from because it is not arriving from a single, visible, governable source.


Developer-deployed agents are the familiar variant: technical teams spin up agents via OpenAI, Anthropic, or Azure AI APIs, provision long-lived keys embedded in codebases, and build workflows that persist long after the project has moved on. The identity has no owner, no expiry date, and no decommissioning plan.


Citizen developer agents are the faster-growing and less visible variant. No-code platforms (e.g., Microsoft Copilot Studio, Power Automate, Salesforce Flow, ServiceNow AI, Zapier) have placed agent creation capabilities directly in the hands of non-technical staff. The finance analyst who built a Power Automate workflow to extract and summarize ERP data has created a non-human identity that carries their full access rights and will continue exercising them indefinitely. The security team was not consulted. The identity does not appear in any NHI discovery scan. There is no separate agent identifier in the audit trail.


Vendor-embedded agents arrive with SaaS renewals. Salesforce Agentforce, Workday AI, ServiceNow AI Agents, and Microsoft 365 Copilot are not optional add-ons. They are core product features now embedded in platforms most enterprises have already licensed. The agents that come with them operate under vendor-controlled logic, authenticate using credentials that may not appear in the organization's central identity directory, and access some of the most sensitive data in the environment.

None of these three populations is captured by traditional NHI discovery tooling. Most organizations have meaningful visibility into only a fraction of their actual agent population.


The Governance Vacuum


Gartner forecasts that 33% of enterprise applications will include agentic AI capabilities by 2028. Accenture's State of Cybersecurity Resilience research finds that 90% of organizations currently lack a comprehensive strategy for managing autonomous systems.

That gap between the pace of deployment and the maturity of governance is the defining security challenge of the next several years.


The practical implication is straightforward. An organization that does not know what non-human identities exist in its environment, who owns them, what access they hold, and what lifecycle they are subject to cannot govern them. That was true before agentic AI. It becomes materially more serious as autonomous agents proliferate through every layer of the enterprise.


The inventory problem has a new dimension in the agentic era: traditional discovery tools were designed to find service accounts and API keys. They were not designed to find citizen developer workflow agents, vendor-embedded platform agents, or personal AI tool integrations. Closing the gap requires discovery approaches that extend beyond the identity directory and the secrets vault to the platforms, productivity tools, and SaaS integrations where ungoverned agents are already proliferating.


What Security Leaders Should Do Now


The 45-billion-identity horizon is not an abstract future concern. The conditions that create it are present in your environment today. Three immediate actions are worth prioritizing.


Extend your NHI inventory scope. If your current NHI discovery program covers service accounts and API keys but not citizen developer platform agents or vendor-embedded AI capabilities, you have a material gap. Identify which platforms in your environment enable agent creation, including those your business users have been using for 12 months, and determine whether those agents are visible to your governance program.


Ask the ownership question for every active agent. Who is the designated owner of this agent? What business purpose does it serve? What is its authorized scope? What is the decommissioning trigger? For agents that cannot answer these questions, the default governance posture is unacceptable exposure.


Update your offboarding process explicitly for agents. When a staff member leaves, your current process almost certainly does not identify and address agents who operate under their credentials or were created during that staff member's tenure. It should.


***

Ungoverned agentic AI identities are arriving in your environment incrementally, through developer projects, business workflows, and SaaS renewals, largely without announcement. The organizations that govern it effectively will be the ones that start asking the right questions now, rather than the ones still building their strategy when the next significant agentic AI incident lands.


This is the first article in TBDCyber's Agentic AI Security series. For the full research behind the numbers in this piece, including the complete governance gap analysis, read our whitepaper on agentic AI identity governance.


The next article examines why the governance problem cannot be solved by applying existing IAM frameworks more rigorously, and why that is a structural issue, not a maturity gap.


TBDCyber advises security leaders on identity governance, agentic AI security, and emerging threat architectures. To discuss what this means for your organization, contact us.

 

Comments


bottom of page