SANS 2026 Survey: 92% of Organizations Aren't Rotating Machine Credentials -- And AI Agents Are Making It Worse
Dr. Abeer Alshammari · Published 7/29/2026
Executive View
SANS's 2026 State of Identity Threats and Defenses survey of 500+ security professionals found non-human identities -- service accounts, API keys, bots, workload identities -- are now growing faster than any other identity category, with 76% of organizations reporting growth. 92% fail to rotate machine credentials on a 90-day cycle, and 5% of security leaders do not know whether agentic AI is running in their own environment. Decision required: inventory and credential-rotation policy for non-human identities should be treated as a standing governance gap, not a future project.
SANS Institute's 2026 State of Identity Threats and Defenses survey, based on responses from more than 500 security professionals globally.
What happened
SANS published its 2026 State of Identity Threats and Defenses survey, finding that non-human identities -- service accounts, API keys, automation bots, and workload identities -- are now the fastest-growing identity category in the organizations surveyed, with 76% reporting growth. The survey specifically flags agentic AI as an accelerant: 74% of organizations are already using AI agents or automations that require credentials, yet 5% of security leaders reported not knowing whether agentic AI is even running in their environment.
Why it matters
The most striking finding is a credential hygiene gap: 92% of organizations fail to rotate machine credentials on a 90-day cycle, creating what the survey terms a "forever access" problem -- long-lived, rarely-rotated credentials are exactly what an attacker wants to find. This is compounded by a detection-versus-containment gap: 68% of organizations detect identity attacks within 24 hours, but only 55% actually contain them within that same window.
Who is affected
Effectively every organization operating cloud infrastructure, CI/CD pipelines, SaaS integrations, or any form of automation -- which is to say, nearly all organizations, since non-human identities now outnumber human identities in most modern environments by a wide margin.
Technical impact
85% of surveyed organizations have identity security tools deployed, yet 55% were still compromised in the past 12 months -- a tool-deployment paradox suggesting that having identity security tooling is not the same as having effective non-human identity governance. The gap tends to sit in inventory (not knowing what NHIs exist), rotation (not cycling credentials that do exist), and ownership (not knowing who is accountable for a given service account or API key).
Governance impact
Non-human identity governance needs to be treated as its own risk domain with its own inventory, ownership, and rotation policy -- not folded into general "identity and access management" as an afterthought behind human user accounts. Agentic AI adoption is accelerating NHI growth faster than most governance programs are adapting to track it.
What security teams should do
- Build or refresh a complete inventory of service accounts, API keys, bot accounts, and workload identities -- treat "we don't fully know" as the finding, not a footnote
- Establish a credential rotation policy specifically for machine identities, separate from human password policy, and measure actual compliance against it
- Assign explicit ownership for every non-human identity; an unowned service account is an unmonitored one
- Specifically confirm whether any agentic AI is operating in your environment with standing credentials, and whether its access scope has been reviewed
What executives should know
Non-human identities already outnumber human ones in most environments, and identity security tooling alone has not closed the gap -- 55% of organizations with tools deployed were still compromised. This is a governance and ownership problem as much as a technology problem.
The decision this data points to is ownership, not tooling: who owns the inventory of every non-human identity in your environment, and who is accountable when a credential goes unrotated for a year. If that owner doesn't exist today, the 92% statistic in this survey is very likely describing your organization too.
GCC organizations scaling cloud adoption and, increasingly, agentic AI pilots are building non-human identity sprawl at the same pace as anywhere else. This is a directly applicable finding, not a US-specific one -- NHI governance gaps are a global pattern this survey happens to quantify.
Sources
SANS Institute 2026 State of Identity Threats and Defenses survey; Intelligent CISO coverage; AuthMind survey insights report.