A new report from CyberArk, a company in Palo Alto Networks, shows that AI and machine identities are rapidly changing the attack surface for businesses in EMEA. At the same time, the number of identity-related breaches is increasing and many organizations still lack automated security processes to manage the growing risks.
Study from CyberArk shows that AI and machine identities are rapidly increasing the complexity and risks in corporate IT environments.
CyberArk presents new research showing that 80 percent of organizations in EMEA have experienced at least three successful identity-related breaches in the past 12 months. The report Identity Security Landscape Report 2026 shows how attack surfaces and risks grow with the rise of AI-powered and autonomous identities.
Massive increase in machine identities
The study shows that there are now 110 machine identities for every human identity in EMEA, up from 83 a year ago, a 36 percent increase. The growth is driven primarily by AI identities, which are expected to grow faster than both human and traditional machine identities.
Meanwhile, organizations in EMEA expect a sharp increase in the number of identities over the next 12 months, with 87 percent expecting more AI identities, while 84 percent see an increase in machine identities and 64 percent expect more human identities.
The main factors behind the development are AI and large language models, machine identities such as IoT devices and bots, and increased use of cloud applications.
As digital expansion, rather than headcount increases, has become the primary driver of identity growth, organizations need to rethink how they manage risk, increasing the need for visibility, control, and governance.
Identity-related threats are becoming increasingly common
According to the report, identity-related threats have become a constant operational reality for businesses in EMEA, with 91 percent of organizations reporting having experienced at least one identity-related breach.
At the same time, security managers state that the complexity of identities is now developing faster than organizations' ability to control and manage the risks.
EMEA is also described as the region least prepared for the upcoming shortening of certificate lifecycles. A full 75 percent of organizations still lack full automation of renewals and monitoring of certificate environments. The estimated economic impact for an organization in EMEA is estimated at €213,262.
AI agents gain access to sensitive data
The report also shows that on average, nearly two out of five AI agents and machine identities have access to organizations' data, including sensitive information such as financial data and business-critical systems.
Meanwhile, only a minority of organizations use behavioral monitoring and automatic credential revocation for autonomous and generative AI agents.
Additionally, 82 percent of EMEA respondents believe that fragmented identity systems and tools make it more difficult for organizations to detect and manage identity-related threats.
“Traditional security checks are no longer enough”
“The explosion of machine identities is fundamentally changing the attack surface for enterprises. As AI-powered identities continue to proliferate, organizations are facing a reality where identity complexity is rapidly outpacing the capabilities of traditional security controls,”, says Renske Galema.
She continues:
“The fact that 91 percent of organizations in EMEA have experienced an identity breach shows that security leaders must move beyond manual processes as AI agents gain access to increasingly sensitive data. To mitigate risk, organizations need to implement end-to-end automation and unified governance.”.
Need for uniform identity security
As machine and AI identities become increasingly prevalent in enterprise environments, organizations need to move from fragmented and manual control to a more unified and automated approach to identity security.
According to the report, managing the 110:1 ratio between machine identities and human identities requires a platform-based strategy that makes it possible to combine innovation with high security for people, machines and AI agents.
Read more about the report via CyberArk
Notice: For those of you who have previously followed CyberArk continues its journey now under the name Idira™.








