Cloud Security Alliance released a survey this week on non-human identities and AI security. The facts CSA present in this survey shows how difficult it has become for teams to keep visibility and ownership aligned with AI growth.
Confidence is already strained

79% of respondents rated their confidence in preventing attacks that use non-human identities as low or moderate.
Teams know these identities exist. But they also know how difficult it is to see them clearly once they sit across cloud platforms, pipelines, integrations and internal systems.
This includes service accounts, tokens, bots, workload identities and any AI agents that sit outside traditional user access models.
Policy and ownership unclear

78% of organisations reported that they do not have documented and formally adopted policies for creating or removing AI identities.
That tracks with how these identities tend to appear. They accumulate gradually as automation is introduced and systems are connected. They’re rarely onboarded through a single process with a clear owner.
The survey also found that 39% of respondents cited governance as their main issue around AI systems and identity. 51% said unclear ownership or excessive access were their most significant pain points.
When responsibility isn’t clearly assigned, identities keep their access longer than intended and gain more than they should.
Legacy IAM is under pressure
92% of respondents said they are not confident that their existing IAM solutions can manage the risks associated with AI and non-human identities.
Most IAM programmes were designed around employees and contractors. Machine identities often sit between teams and systems. They span cloud services, development pipelines, data platforms and third party tools.
As AI driven workflows increase the volume and pace of identity creation, those gaps become harder to ignore.
Response speed is lagging far behind access growth
More than 16% of organisations said they do not track when new AI related identities are created. When credentials are exposed, remediation often takes time. Nearly ¼ reported taking more than 24 hours to rotate or revoke a credential after a potential exposure. 30% reported taking more than a day to triage a high severity credential leak.
What organisations are dealing with now
Non-human identities are already a large access surface in many environments. AI increases how quickly they appear. But governance, ownership and lifecycle controls are still catching up.
The number of these identities will continue to grow as AI systems connect to more internal and external services. What matters is whether controls evolve at the same pace.
If you’re seeing more machine identities than you can comfortably keep track of, Gridware’s Identity and Access Management team can help you work through it.



