Identity · CA
Half of Enterprises Have No Owner for Their AI Agent Identities
A new CSA whitepaper on the "non-human identity governance vacuum" puts numbers to a problem most agentic AI security writing only gestures at: enterprises are creating machine identities faster than they can govern them. The paper reports that 47% of non-human identities have gone unchanged for over a year, 51% of organizations have no clear ownership of AI identity, and 16% aren't even tracking new AI credential creation.
That last figure is the one worth sitting with. It's not that companies are tracking credentials poorly — a meaningful slice aren't tracking them at all. An agent can spin up, get issued a key or token, and never appear in any inventory that a security team reviews. Combined with the 47% stat on stale identities, the picture is of credentials that are both invisible on creation and neglected indefinitely afterward — the exact conditions under which dormant, over-privileged accounts become the easiest lever for an attacker to pull.
The whitepaper frames this as governance debt accumulating at the same pace as agentic AI adoption, and it isn't speculative about the cost: it points to exploitation of these exact failures already showing up in the 2026 Verizon Data Breach Investigations Report and in incidents referred to as Moltbook and OpenClaw. In other words, this isn't a future risk being modeled hypothetically — it's a pattern already showing up in breach data.
The paper connects the diagnosis to CSA's existing MAESTRO threat-modeling framework, mapping identity governance as a cross-cutting concern that touches how agent frameworks issue credentials, how deployment infrastructure manages workload identities, how security controls enforce access policies, and how credentials get governed across multi-agent ecosystems. That's consistent with where the rest of the field has been heading: less about inventing new crypto primitives for agent identity, more about admitting that most organizations don't have a working answer to "who owns this agent's credential, and did anyone notice it hasn't rotated in a year."
The uncomfortable implication is that the identity and attestation layers being built — DIDs, verifiable credentials, signed receipts — assume a baseline of operational hygiene that, per this data, roughly half of enterprises don't have. A cryptographically verifiable agent identity doesn't help much if nobody in the organization is assigned to watch it.