Gridware Logo

79% of teams unprepared to secure AI identities

By Ahmed Khanji Updated 29 January 2026 2 min read

in 𝕏
79% of teams unprepared to secure AI identities

Cloud Security Alliance released a survey this week on non-human identities and AI security. The facts CSA present in this survey shows how difficult it has become for teams to keep visibility and ownership aligned with AI growth.

Confidence is already strained

79% of respondents rated their confidence in preventing attacks that use non-human identities as low or moderate.

Teams know these identities exist. But they also know how difficult it is to see them clearly once they sit across cloud platforms, pipelines, integrations and internal systems.

This includes service accounts, tokens, bots, workload identities and any AI agents that sit outside traditional user access models.

Policy and ownership unclear

78% of organisations reported that they do not have documented and formally adopted policies for creating or removing AI identities.

That tracks with how these identities tend to appear. They accumulate gradually as automation is introduced and systems are connected. They’re rarely onboarded through a single process with a clear owner.

The survey also found that 39% of respondents cited governance as their main issue around AI systems and identity. 51% said unclear ownership or excessive access were their most significant pain points.

When responsibility isn’t clearly assigned, identities keep their access longer than intended and gain more than they should.

Legacy IAM is under pressure

92% of respondents said they are not confident that their existing IAM solutions can manage the risks associated with AI and non-human identities.

Most IAM programmes were designed around employees and contractors. Machine identities often sit between teams and systems. They span cloud services, development pipelines, data platforms and third party tools.

As AI driven workflows increase the volume and pace of identity creation, those gaps become harder to ignore.

Response speed is lagging far behind access growth

More than 16% of organisations said they do not track when new AI related identities are created. When credentials are exposed, remediation often takes time. Nearly ¼ reported taking more than 24 hours to rotate or revoke a credential after a potential exposure. 30% reported taking more than a day to triage a high severity credential leak.

What organisations are dealing with now

Non-human identities are already a large access surface in many environments. AI increases how quickly they appear. But governance, ownership and lifecycle controls are still catching up.

The number of these identities will continue to grow as AI systems connect to more internal and external services. What matters is whether controls evolve at the same pace.

If you’re seeing more machine identities than you can comfortably keep track of, Gridware’s Identity and Access Management team can help you work through it.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.