91% of Active Production Systems Are Non-Human: AI and Automated Identities Dominate
Non-human identities account for 91% of active entities in production environments, according to the 2026 Identity Intelligence Report.
Key Findings from the 2026 Identity Intelligence Report
The 2026 Identity Intelligence Report highlights the growing dominance of non-human identities in production environments, with 91% of active entities being machine-based. This includes service accounts, execution roles, managed identities, and vendor credentials, which operate continuously to execute critical tasks such as backups, automated scans, and deployment pipelines.
The Rise of Non-Human Identities
Machine-based identities are integral to modern cloud operations, running tasks at specific times, such as backup processes at 2 AM, automated scans an hour later, and deployment pipelines assuming roles at 4 AM. Logging agents also maintain uninterrupted activity throughout the night, relying on machine-issued credentials.
Challenges in Detecting Malicious Activity
Attackers exploit non-human identities by leveraging stolen credentials to mimic legitimate machine behavior, making detection difficult. For example, the Miasma breach in June 2026 involved malicious packages infiltrating Red Hat’s trusted channels through compromised credentials and legitimate publishing workflows. Similar incidents, like the LiteLLM project’s compromise, demonstrate the vulnerability of machine identities.
“Non-human identities generate 3% of activity through Delete and terminate commands, alongside privileged create-and-modify operations,” according to the report.
The Vulnerability of Machine Identities
Machine identities constitute 90% of active identities in production environments, yet defenders struggle to distinguish legitimate activity from malicious actions. While 99% of human interactions involve read-only operations, non-human identities often execute destructive commands. A compromised service account can act at machine speed, amplifying the impact of anomalies.
Third-Party Credentials and Destructive Behavior
Third-party credentials represent 4% of the identity population, with top vendor identities spanning multiple regions and services. One security vendor observed 40% of its interactions involving destructive actions, while the rest were read-only. Time-based anomaly detection is effective only during weekends when traffic drops below 5% across all identity types.
The Need for Advanced Identity Verification
The report emphasizes the need for advanced identity verification beyond traditional tools. While identity providers confirm authentication and cloud posture tools validate configurations, neither can assess the legitimacy of specific identity behavior. This gap highlights the complexity of securing environments where machines outnumber humans.
Broader Cybersecurity Trends
The findings align with trends in cybersecurity, including increased reliance on automated workflows and challenges in managing privileged access. As non-human identities proliferate, organizations must adopt strategies to monitor and secure these entities, ensuring they do not become vectors for exploitation.
Conclusion
The 2026 Identity Intelligence Report underscores the critical need for robust security measures to protect non-human identities, which now dominate production environments. With attackers increasingly targeting machine-based credentials, organizations must prioritize advanced verification methods to mitigate risks and safeguard their infrastructure.
