Opens in a new tab
vmblog logo 2024 wht (updated)

2026: The year of machine identity overload

Share: 

David Marshall | Published: January 2, 2026

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Pierre Mouallem, CISO, Delinea

Even though enterprises have spent the last few years ramping up their AI transformation, few are aware of or even ready to face its most immediate consequence: the surge of AI-related machine identities that now outnumber human users across the organization. From service accounts to workloads and IoT devices, these identities are multiplying faster than security teams can track, and the result is a rapidly expanding attack surface. What leaders assumed would accelerate innovation is instead creating an identity landscape they can’t see or control, and attackers are taking note.

These machine identities, proliferated through employee experimentation, operate with excessive privileges and frequently without clear ownership. Every new AI tool, script, or integration has the ability to silently generate another credential, token, or access pathway. This is how employee shadow AI use evolves into a security problem, not because AI tools are inherently dangerous, but because each spawns an unmanaged identity. So, it’s no surprise that 56% of organizations are reporting shadow AI incidents every month.

The overload of machine identities is not a failure of innovation, but a failure of how identity is governed once AI enters the system. With the modern enterprise losing visibility over who and what has access to their systems and threat actors looking to exploit any gap in security, it’s becoming more important than ever for companies to ensure the right identity security practices are in place to safeguard their systems.

The implementation dilemma

CISOs now face a turning point. While slowing down AI adoption is not realistic, the governance gap it has created is widening fast. Employees need clear guidance on safe AI practices to limit machine identity proliferation, so that security teams don’t have to waste time chasing every rouge identity that – left unmonitored – could open their systems to exploitation.

Security leaders who once hesitated to let vendors auto-enable AI features may soon find themselves embracing them, as AI capabilities can discover identities faster than security teams can manually identify them. If AI adoption and subsequent identity growth continues at its current pace, AI security tools will become essential to monitor them. However, leaders must approach these new tools with caution, as every new AI agent will become a new identity with privileges that must be tightly managed.

Threat actors have taken notice of machine identity sprawl and are using it to their advantage. Shadow AI tools often have access to hard-coded API keys, service tokens, and privileged credentials that are rarely updated or monitored. These unmanaged or forgotten accounts become easy entry points into organizations’ systems once discovered, allowing attackers to move without triggering security alarms. Shadow AI therefore turns weak governance into a direct accelerant for breaches.

The growing synthetic identity threat

Synthetic identities are dangerous because they don’t rely on compromised accounts at all. These digital personas utilize AI generated attributes and authentic personal content to impersonate users. What was initially a financial fraud tactic has evolved into a cross-domain threat vector, intensifying the risks of machine identities. As weak AI governance allows for unchecked hidden identity growth, synthetic identities will be easier to slip through existing and overwhelmed security controls.

Attackers can now impersonate employees, contractors, vendors, or partners with AI, appearing entirely legitimate on paper and online. These synthetic identities have realistic digital footprints with polished social media accounts, cloned resumes, and even doctored HR documentation. They can get past traditional verification checks and gain a foothold in an organization, establishing trust, and navigating through systems long before raising suspicion. Deepfake voice and video content help fraudulent identities defeat biometric and visual checks, which were once considered fool-proof.

The rise of synthetic identities shows that identity can no longer be checked once but must be continually proven. Their implications raise concerns far beyond the authentication process – they challenge digital trust itself. Security teams will be forced to rethink what it means to verify identity in an AI-driven world. Static credentials and one-time checks will no longer be sufficient when identities can be manufactured. Moving forward, organizations will need to implement cryptographic identity proofs, continuous behavioral validation, and high-assurance verification mechanisms to confirm who, or what, is operating inside their environments.

Enterprises are being attacked from all sides as gaps in AI governance create uncontrolled machine identities internally and enable synthetic identities to be engineered externally at scale. Identity security has become the deciding factor in whether AI delivers competitive advantage or systemic risk. Organizations that implement disciplined AI policies and forward-thinking identity protocols will be well equipped to innovate securely. Those that don’t will spend the year reacting to breaches born from identities they never knew existed.

##

ABOUT THE AUTHOR

Pierre Mouallem, CISO, Delinea

Pierre Mouallem 

Pierre is a seasoned leader with over 20 years of experience in cybersecurity and technology. He has a wealth of experience successfully building, scaling and maturing best-in-class enterprise-wide security programs. He brings expertise engaging with customers on their top of mind security concerns. Most recently Pierre served as Deputy CISO at SailPoint. Previously, Pierre has held various leadership roles at organizations such as Lenovo and Oracle where he built highly rated Cybersecurity and Product Security Programs. Throughout his career, Pierre has served as leader, architect, engineer, researcher, and instructor, which has provided him with a unique perspective on the role of cybersecurity and how it can be used to facilitate and drive growth.