# What the report measured SpyCloud surveyed 750 cybersecurity leaders and practitioners at organizations with 500 or more employees across North America and several European markets. The company published findings in its 2026 Identity Threat Report that focus on identity‑based risk, especially non‑human identities (NHIs): AI agents, service accounts, API keys and authentication tokens that connect to internal systems.
# Main finding: machine identities lead Respondents ranked compromised non‑human identities as the most common attacker entry point into enterprises. Thirty‑one percent named NHIs as the primary route, compared with 17% for phishing and social engineering. SpyCloud also reported NHI misuse as the most frequently observed identity event at 42%.
# Visibility vs monitoring gap Most organizations overestimate protection. While 95% said they have adequate visibility into AI and machine identity exposures, only 36% actively monitor those identities. SpyCloud highlights that many of the routine controls applied to human accounts — offboarding, forced credential rotation, multifactor prompts — don't apply to service accounts and similar machine identities, allowing exposed credentials to remain usable for months.
# AI governance shortfall The survey found broad adoption of AI agents with internal access: 91% of respondents run AI tools or agents that connect to systems, applications or data. Despite that, only 56% reported formal ownership and rules governing what those tools are permitted to access. Another 41% operate with partial ownership or informal arrangements, leaving privileged machine connections outside standard oversight.
# Session tokens and supply chain risks
# Maturity model and controls that matter
# Practical implications for security teams
- Treat machine identities as high‑risk assets: service accounts, tokens and API keys can provide persistent access unless explicitly managed.
- Close the visibility‑monitoring gap: claiming visibility is not the same as having active monitoring and alerting for NHIs.
- Assign ownership and governance for AI tools that have internal privileges, and formalize rules for what those agents may access.
- Prioritize detection of stolen session data and require vendors to prove exposures are remediated.
- Consider the maturity model as a checklist: improve monitoring, automate remediation, and track governance to reduce incidents.
# Bottom line