IBM's 2026 Cost of a Data Breach report found that 13% of organizations had suffered a breach of an AI model or application. Of those, 97% reported having no proper AI access controls in place.
Almost every organization breached through its AI estate had failed to extend to its AI systems the control discipline the identity industry has spent decades building.
It is tempting to read those organizations as careless. More likely, the architecture most enterprises now call an Identity Fabric has simply never been tested by an actor that behaves like an AI agent. Agents are the first identity population your fabric was not designed for, and they will find every seam in it.
This post makes three arguments: that "non-human identity" has stopped being a single governable category, that agentic AI separates designed fabrics from accreted ones, and that identity is necessary but not where this gets decided.
"Non-human identity" stopped being one thing
The term did real work. It marked off a population that behaved nothing like human users: cloud workloads, ephemeral containers, service accounts, IoT devices, machine-to-machine traffic. Then AI agents arrived, and the population split.
The exact multiple varies by source. KuppingerCole Analysts puts machine identities at more than 50 for every human; Palo Alto Networks' 2026 Identity Security Landscape report puts it at 109 to 1, up from 82 to 1 a year earlier, and attributes the increase to AI agents rather than to growth in the older population of service accounts and workloads. Other published estimates range from 17:1 to 144:1 depending on how much of the estate gets counted, but none of them puts the older, non-agent population anywhere near a majority of the total.
Palo Alto's own breakdown makes the point directly: of the 109 machine identities per human, 79 are AI agents. That is the figure worth sitting with. Treat it with some care, since a census counting everything marketed as an agent will overstate how much of the population is genuinely autonomous, but even a conservative reading puts AI agents at most of the non-human estate already.
The useful cut runs along autonomy, not humanity. As Alexei Balaganski argues in From Identity to Access, dependent identities such as workloads and devices act only as extensions of the system that owns them. Autonomous identities act on their own behalf within a delegated mandate, which puts them closer to a privileged human than to a workload.
The two classes fail differently. Dependent identities fail through scale and credential sprawl. Autonomous identities fail through missing accountability and unbounded blast radius. A governance model tuned for the first leaves the second largely uncovered.
Agentic AI separates designed fabrics from accreted ones
Most organizations that say they have an Identity Fabric have not built one. They have accreted one: an IGA platform here, a PAM tool there, three IdPs from three acquisitions, a secrets manager the platform team bought quietly, and integrations that hold as long as nothing moves fast.
That arrangement survives human users because humans are slow. A person authenticates once, works at human speed, and generates access requests a review board can plausibly inspect.
Agents remove the cushion. A single high-level task spawns dozens of sub-actions across multiple systems at machine speed, and agents delegate to further agents as they go. Every seam becomes a place where accountability is lost, faster than anyone notices.
This is where the Identity Fabric earns its keep or fails to. A fabric is a deliberate capability model with governance attached, not a diagram drawn after the fact to explain what procurement happened to buy.
Two sessions at Identity Fabric Impact Day 2026 in Cologne address this question directly. Matthias Jarka of WACKER opens with "Steering Identity as a Fabric," on how WACKER structures, evolves and actively governs its IAM: the operative word is actively. Marco Venuti, Field CTO at SGNL, follows with the orchestration toolbox and the adoption patterns separating organizations that have moved from integration to orchestration from those still wiring point to point.
Identity is necessary, not sufficient
Knowing who or what is acting solves very little of the security problem on its own, because the risk lives in what the actor is permitted to do. Balaganski's conclusion is that access, not identity, is the control point, and that enforcement belongs at the resource: the API, the service, the database where the action lands. Authorization at a gateway is coarse, and authorization left to an agent's own instructions is not authorization at all.
Three consequences follow.
- An API key is a secret, not an identity. Conflating entity, identity, account, credential and access is the most consequential mistake in the current vocabulary, and it is baked into many products that operate at one layer while carrying the name of another.
- Every account traces to an accountable owner. Attestation proves only that the thing presenting a credential is the thing that was enrolled. It never proves the enrollment should have happened.
- Pre-scripted access does not hold. Autonomous actors combine permissions in unplanned sequences and pursue intermediate steps nobody wrote down, which forces continuous evaluation, in context, at the moment of action.
Anmol Singh, Director and Global Head of IAM at Olympus Corporation, takes this on with a session on evolving the fabric for autonomous identities through delegation, governance and runtime authorization. Jonathan Neal, SVP and Field CTO at Saviynt, pushes further with "From Identity Fabric to AI Control Plane." Both are the right argument to be having; neither has a settled answer yet.
What to build, rather than what to buy
The vendor market is moving faster than the control problem is understood. My own advisory note, Navigating the Agentic AI Security Landscape, maps six categories across prevent, observe, detect/respond and govern, split into three procurement tracks with different buyers and budgets. Buying from the wrong track is a common and expensive error.
Architecture before procurement
In From AI Agents to Trusted Digital Workers, Martin Kuppinger sets out four pillars for governing agent identities: registration and lifecycle management, multi-tier authorization, governance and oversight, and auditability with provenance. The paper sequences them across three horizons, separating what enterprises can do now from what waits on standards that have not stabilized yet.
None of the four requires a new product category to begin. Registering agents as first-class identities with named owners is a lifecycle exercise your IGA platform can already model, badly at first. Establishing that every agent action resolves to an accountable human takes a policy decision, not a product. Both are unglamorous, and both are prerequisites for whatever the runtime authorization vendors sell you next year. Ownership is the harder gap: governance that belongs to no named team defaults to the platform teams shipping the agents, the one group with no incentive to constrain them.
Which is why Matthias Reinwarth closes the day with "The Fabric Is Not the Deliverable: What You Build on Monday." The fabric is the means. The governed access is the outcome.
The takeaway
The non-human category has split, and autonomous identities need a governance model closer to privileged human access than to infrastructure. And identity is the prerequisite, not the control point: enforcement has to reach the resource.
Identity Fabric Impact Day 2026 takes place on September 9 at the Hilton Cologne. It is a single day built for the people who own this problem rather than describe it. Register here, and come prepared to argue.