According to JumpCloud's Q3 2026 State of IT report published on August 6, non-human identities such as AI agents now outnumber actual employees at the majority of enterprises. This rapid growth is creating severe security vulnerabilities, as most organizations have yet to implement any formal governance for this virtual workforce.
Background & Root Causes
The rapid proliferation of AI applications has driven development teams to autonomously deploy AI agents to automate workflows across platforms, from Salesforce to Jira. JumpCloud's report, which surveyed 800 IT leaders in the US and UK, reveals that non-human identities outnumber physical users in 83% of organizations, yet only 21% have established dedicated governance controls for them.
This reality has given rise to 'Shadow AI'—AI agents operating silently in production environments without official records or clear ownership. When these agents outlive their original purpose but continue running in the background, they become 'Zombie Agents,' accumulating indefinite system access privileges and posing a direct threat to corporate cybersecurity.
Technical Analysis & Technology
To address this challenge, Agentic Identity and Access Management (Agentic IAM) is proposed to integrate AI agents directly into corporate directories as formal employee identities. From a technical standpoint, the security architecture requires the complete elimination of static credentials, such as hardcoded API keys in environment variables, which have long been a critical vulnerability.
Instead, the new security framework advocates for the use of just-in-time (JIT) credentials and establishing human-in-the-loop approval workflows before agents can access sensitive data. Additionally, credential shielding is recommended to prevent AI models from directly exposing credentials for SSH servers or databases.
Expert Insights & Perspectives
Greg Keller, Chief Technology Officer and Co-founder of JumpCloud, noted that managing people, devices, and AI agents through a unified control plane is core to achieving secure workflows at scale. Many independent security experts agree that without the ability to reconstruct the audit trail of AI agent behaviors, enterprises are essentially deploying new technology based on luck.
The report also highlights a strong correlation between IT infrastructure consolidation and the safe adoption of AI. Specifically, organizations operating within a unified IT environment are five times more likely to deploy AI agents into critical workflows compared to those with fragmented systems.
Impact & Future Outlook
Establishing a comprehensive governance framework for non-human identities not only mitigates security risks but also provides a solid foundation for enterprises to confidently scale their AI initiatives. For markets like Vietnam, where digital transformation is accelerating rapidly, gaining early awareness of 'Shadow AI' risks and building AI agent management protocols from the outset is crucial to safely leading global technology trends.