By Patricia Titus Machine identities now vastly outnumber and outrank human ones in most enterprises, yet almost none of them are governed. Machine identities, including APIs, service accounts, tokens, and now AI agents, have quietly become the most powerful actors in the enterprise. Research estimates organisations now manage more than 100 machine identities for every human on. Most security programs still aren’t built to govern them. Patricia Titus, Field CISO at Abnormal AI, argues this isn’t a tooling gap. It’s a governance failure. For years, identity security has been built around people. Logins, MFA, lifecycle reviews, least privilege, all designed to answer one question: does this person have the right access? But now, that question no longer covers most of what’s really operating inside the enterprise. Machine identities, APIs, service accounts, tokens, and most recently AI agents, have overtaken human ones by a wide margin. Palo Alto Networks 2026 Identity Security Landscape report, based on a survey of nearly 3,000 cybersecurity decision-makers, puts the ratio at 109 machine identities for every human one, up from 82:1 just a year earlier. Of those 109, roughly 79 are AI agents. AI agents alone now make up almost three-quarters of the machine identity population, not API keys and service accounts. The scale is only part of the story, however the bigger issue is authority. A CFO can approve a payment, while an API can approve millions. An employee might access one database, but an AI agent can rapidly sweep dozens. These identities don’t log in, so there’s no login to flag. They don’t trigger MFA, so there’s nothing to challenge. When one is compromised, an attacker doesn’t break in. They execute quietly, programmatically, and at scale, often without tripping a single alert built for human behaviour. Why identity programs weren’t built for this