Semperis has published the results of a multi-industry global study of 1,100 organizations with the aim of understanding AI’s effect on the attack surface of identity systems such as Active Directory, Entra ID, and Okta.
The study shows that AI is ‘quietly redrawing’ the boundaries of global identity attack surfaces and organizations are giving AI agents the keys to critical systems faster than they are putting guardrails around those new identities.
The ‘State of Identity Security in the AI Era’ study found that 74% of organizations in the US, UK, France, Germany, Spain, Italy, Singapore, and Australia believe that AI will increase attacks on identity infrastructure.
Globally, only 65% of organizations say that AI identities are fully registered, authenticated, and authorized in a formal system, and 6% admit they do not track them at all. In organizations that do track AI identities, 57% use the same system as for human identities, while 43% authenticate and authorize them using a separate system.
AI is being placed close to sensitive identity infrastructure, and too few organizations are prepared for the potential consequences. More than a quarter of surveyed organizations (29%) already use AI agents to manage security-related help desk tickets including password resets and VPN access. Another 65% intend to do so within the next year. In parallel, 92% of respondents say that some % of their workforce has AI installed on local machines where it can access SSH and encryption keys, yet globally only 32% are very confident they could regain control if AI exposes admin credentials. In the US, 53% of companies expressed confidence in regaining control; in France, the number is 12%.
al, especially when identity is within the blast radius. On paper, organizations have plans and backups; in practice, identity failures turn technical incidents into prolonged business crises, exposing a dangerous gap between perceived resilience and reality…
Chris Inglis, the first US National Cyber Director and Semperis Strategic Advisor
How can organizations govern AI identities?
Current best practices include:
- Treat agents explicitly as non-human identities (NHIs) in the identity fabric.
- Enforce least-privilege, just-enough, and just-in-time access for agents as rigorously as for humans.
- Segregate agent and human trust boundaries where appropriate.
- Use User and Entity Behaviour Analytics (UEBA)-style analytics to detect ‘zombie’ or anomalous agent behaviour.
- Ensure that your organization can quickly recover identity systems to a trustworthy state if they are breached.
Methodology
The survey was conducted by Censuswide in early 2026. Censuswide surveyed 1,100 organizations across the US, UK, France, Germany, Italy, Spain, Australia, and Singapore.






