The ratio of human to non-human identities in modern enterprises has reached a staggering 1:82.1 For every employee, contractor, or partner, there are now dozens (if not hundreds) of machine identities, service accounts, API keys, and autonomous AI agents operating across production environments.
This shift has made identity the new security control plane. With the rapid growth of SaaS, multi-cloud, APIs, and machine-to-machine communication, identities now span employees, contractors, OT/IoT devices, service accounts, and AI models. Managing this diverse array has become one of the most complex challenges in cybersecurity.
According to IBM X-Force 2026, identity-related incidents have been one of the most common attack vectors for three consecutive years.2 AI agents represent a growing share of identity-related findings now. The IBM Cost of a Data Breach Report 2025 found that compromised credentials remain among the top three initial attack vectors.3 Understanding these patterns helps organizations prioritize where governance controls deliver the most value.
The problem: Identity programs were never designed for autonomous identities
Most identity programs were designed for human users navigating structured workflows. That assumption no longer holds. Fragmented identity systems, unmonitored privileges, and inconsistent security controls create gaps that AI agents can inadvertently widen — making unified governance increasingly important.
The exposure falls into three critical categories:
- Privilege Accumulation: Agents continuously acquire privileges without respecting access request flows. Most AI agents already have more access than equivalent human roles. Combined with toxic entitlement combinations, weak credentials, and dormant accounts, the privilege landscape has become a primary attack surface. IBM research indicates that identity incidents involving AI agents can take longer to detect and resolve, underscoring the value of continuous monitoring.3
- No Forensic Foundation: Existing logging, alerting, and policy controls cannot track what an agent is authorized to do. Agent registries are missing or incomplete, agent-to-agent communication goes unlogged, and unmanaged AI tools may operate without visibility from existing security controls.
- Compliance Exposure: Organizations lack inventory and access review processes for AI agents. NIS2, DORA, and the EU AI Act all mandate AI agent governance, yet few organizations can pass a compliance review.
The statistics reinforce the urgency:
- 97% of AI breaches lacked proper access controls.3
- 63% of breached organisations lacked operational AI governance controls.3
- Only 24% of GenAI projects are being secured.4
Addressing these challenges requires moving from periodic snapshots to continuous posture management, and that’s precisely what IBM, Saviynt, and AWS have built together through Identity Watch.
Recommendations for IAM leaders
The path forward does not require a new identity security program. It requires aligning governance discipline to address a new class of identity.
- Count ungoverned agents before the next board review. That number alone will reframe the governance conversation.
- Extend IGA to non-human identities. ISPM is a scope extension, not a new program.
- Replace snapshots with a live Posture Index from IBM. Quarterly certification is retrospective; a live score answers the board question today.
- Deliver executive committee-ready reporting with metrics that demonstrate risk reduction, ROI, and improved security posture.
Identity Watch incorporates this governance discipline.
A three-layer architecture built for the AI agent era
Identity Watch brings together AWS infrastructure, the Saviynt identity security platform, and IBM's assessment methodology into a single offering designed to complement existing controls.
Trusted infrastructure by AWS
Identity Watch runs on AWS, which maintains ISO 27001, SOC 2 Type II, FedRAMP High, and HIPAA certifications for its infrastructure services.
Continuous governance by Saviynt
Saviynt ISPM is the platform that underpins Identity Watch, providing posture management and governance controls across all identity types — human, external, non-human, and AI agents. It's the engine that powers the assessment, surfacing risk and control gaps across the environment.
Intelligent insights by IBM
IBM brings the assessment capabilities that power Identity Watch, evaluating risk across every identity in the environment and translating findings into prioritized, actionable plans. Security teams get a clear view of what to fix first and how to reduce exposure — without waiting on a lengthy deployment.
AI adoption at scale requires three things working together: trusted infrastructure, continuous identity governance, and detection that respects governance policy. Without all three, risk compounds faster than it can be tracked.
Identity Watch: Transforming data into actionable insights
Identity Watch is an assessment-driven solution that transforms collected data into actionable insights through advanced anomaly detection and posture analytics. It identifies misconfigurations, excessive entitlements, and risky combinations across cloud, SaaS, and on-premises environments — surfacing blind spots before they affect your security posture. Unlike IAM tools which govern access, or PAM which protects privileged accounts, Identity Watch focuses on ongoing posture assessment to ensure identities remain aligned with compliance frameworks and least privilege principles.
The assessment uncovers critical identity risks including:
- Dormant accounts — inactive identities that elevate breach risk through unused, exploitable credentials.
- Terminated users with active access — former employees or decommissioned agents retaining live entitlements.
- Toxic entitlement combinations — privilege pairings that enable lateral movement and escalation.
- Weak, shared, or orphaned credentials — susceptible to brute-force and credential-stuffing attacks.
- Active users with inactive managers — identities operating without oversight due to broken approval chains.
- Outliers and anomalous access patterns — identities deviating from peer group baselines.
- Unauthorized protocols and access routes — including public VPNs and unmonitored service-account interactions.
- Revocation effectiveness — measuring whether access removal processes operate within acceptable SLAs.
The five strategic benefits of Identity Watch
- Comprehensive Visibility & Threat Detection — Full-spectrum insight into every human and machine identity across cloud, SaaS, and on-premises, with detection of dormant accounts, MFA/PAM bypass attempts, and orphaned credentials.
- Actionable, Rapid Insights — Prioritized risk findings and scoring within hours of deployment, paired with clear remediation guidance.
- Contextual Risk Analysis & Activity Mapping — Understand how service accounts, users, and AI agents interact with critical systems, exposing unauthorized protocols and unusual access routes.
- Resiliency & Closing Security Gaps — Strengthen identity systems to minimize operational disruption, expose shadow assets and unauthorized AI, and reinforce business continuity.
- Seamless Integration & Regulatory Alignment — Integrate IGA, PAM, Access Management, and Directories with SIEM, SOAR, and EDR platforms to elevate threat detection and compliance posture.
Identity Watch then delivers technical and business-focused reports tailored to each audience — from SecOps teams requiring remediation guidance to board-level stakeholders requiring evidence of governance posture. These are board-ready findings, not just technical reports.
The imperative is now
Only 21 percent of organizations have mature agentic AI governance today. The organizations that close that gap in 2026 will be able to move faster, demonstrate compliance more confidently, and maintain operational resilience across their AI programs, while enhancing their security. Organizations that establish governance early will deploy AI faster than those that defer.
AI agent governance is no longer optional — it's foundational. Organizations that build governance into their AI programs from the start position themselves to move faster and maintain compliance as they scale.
Read more about our solution here.
Get in touch for a rapid Identity Watch assessment. Get prioritized identity risk findings — including your ungoverned AI agents — within hours, not quarters.
Citations:
- Saviynt Press Release, 10/15/2026
- X-Force Threat Intelligence Index 2026
- IBM Cost of a Data Breach Report 2025
- IMB and AWS Joint Report, Securing generative AI: What matters now