Skip to main content

SpyCloud Identity Threat Report Finds 36% Monitor AI and Non-Human Identity Exposures

5th article in the last 90 days, one of 11 articles referencing SpyCloud. Previous coverage: Netskope and ecosystem expand AI guardrails, zero trust - Week of June 22, 2026 (Jun 2026).

Companies mentioned

Best suited for

Seniority
Director
Job function
Chief Information Security Officer
Persona
Security Operations Practitioner
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Operational Expansion
Industry
Information Technology / Software & Services / Cybersecurity / Identity & Access Management (Workforce IAM/SSO/MFA)

Our classification, not the publisher's statement. Best suited for, not only for.

SpyCloud released its 2026 Identity Threat Report based on a survey of 750 cybersecurity leaders and practitioners, addressing how organizations monitor and govern identity exposures tied to AI and non-human identities.

The report said 95% of organizations believe they have visibility into AI- and non-human identity exposures, but only 36% monitor them. It also reported that 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events.

SpyCloud’s survey highlighted non-human identities, including AI agents, service accounts, API keys, and authentication tokens, as a common entry path for attackers. It reported compromised non-human identities at 31% versus phishing and social engineering at 17%, and it cited non-human identity-related misuse as 42% of reported identity-based event types. It also described service accounts not being off-boarded, rotating credentials, or failing MFA as reasons such exposures can remain usable for months.

In the report’s additional findings, SpyCloud said nearly all organizations (91%) use AI tools or agents with access to internal systems, applications, or data, while 56% have formal governance and ownership for resulting privileges. It also introduced an Identity Threat Protection Maturity Model with four maturity tiers—Reactive, Building, Operational, and Optimized—covering visibility, monitoring, governance, automation, and remediation. “That asymmetry is what attackers are exploiting,” said Trevor Hilligoss, SpyCloud's Chief Intelligence Officer. “Every one of these identities is a standing invitation that renews itself until someone notices.”

Press release, provided by Globe Newswire on behalf of SpyCloud. Read the original.