Key takeaways

  • Breach data from 2025-2026 revealed that identity-chained attacks targeting non-human identities and AI agents have become the primary enterprise threat vector.
  • To prepare for 2027, security leaders must immediately audit non-human identities, extend access reviews to AI workflows, and stress-test SSO trust relationships.

At Oktane last year, BeyondID released The Identity Economy Report, our most comprehensive research to date on how identity gaps fuel cybercrime.

One year later, we have receipts that the predictions held.

Now, we're revisiting the data, reporting what we got right, what surprised us, and raising the stakes for what comes next.

What we got right: Validated identity risk predictions from 2025

Our 2025 research identified three fault lines that were quietly widening beneath enterprise security programs:

The confidence paradox has only deepened

We found that 85% of security leaders believed they could detect an identity-related breach within 24 hours, but fewer than 30% governed their non-human identities. That gap hasn't closed. The rapid adoption of AI agents in 2025 and 2026 has made it worse.

Orphaned identities became primary attack vectors

Back in 2025, we highlighted orphaned identities as a major risk. Recent incident trends have reinforced that assessment. Unmanaged service accounts and over-permissioned legacy integrations can serve as common lateral access routes.

SSO misconfigurations remained a durable, exploitable gap

We spent a significant portion of The Identity Economy Report on single sign-on (SSO) as a concentration risk. Organizations treat SSO as a security win, and attackers treat it as a master key. That dynamic hasn't changed, but the blast radius has grown.

Emerging threat patterns that surprised us

Three things emerged in 2025–2026 that we didn't fully anticipate in our original research:

The identity-chained attack became the dominant threat pattern

The new pattern is sequential. Adversaries compromise a human identity, use it to access a service account with broader permissions, and then pivot to an AI agent or automated workflow with system-level access. By the time security teams detect the anomaly, the damage is done.

AI adoption accelerated the compliance gap faster than anyone modeled

Security leaders were already struggling to govern non-human identities. Then the pace of AI agent deployment doubled, and then tripled. The compliance posture that seemed borderline acceptable in early 2025 now appears woefully inadequate in mid-2026.

The perimeter between “our agents” and “their agents” is already blurring

We anticipated that enterprises would struggle to govern their own AI agents. What we didn't fully model was the cross-organizational dimension: partners, vendors, and SaaS platforms deploying agents that interact with enterprise systems.

The 2027 identity threat landscape outlook

Based on our ongoing research and the patterns we're seeing in real enterprise deployments, here is what we believe will define the identity threat landscape in 2027:

  • Identity-chained attacks will become industrialized: Adversaries will commoditize and package the attack pattern described above into exploit kits targeting common enterprise identity configurations.
  • Regulatory accountability will arrive before many organizations are ready: The European Union AI Act enforcement, Securities and Exchange Commission cybersecurity disclosure requirements, and emerging US federal AI governance standards will collectively demand that organizations demonstrate auditable identity governance for autonomous systems.
  • The non-human identity ratio will flip: In many enterprise environments, non-human identities will outnumber human identities before the end of 2027.
  • Post-quantum migration timelines will compress: NIST has finalized its post-quantum cryptography standards, and governments have set compliance timelines. Private-sector pressure will follow. Identity infrastructure elements like certificates, tokens, and federation protocols will all need to resist quantum attacks.

How should security leaders prepare before 2027?

For security leaders who don't want to wait, here's where to start:

  • Audit your non-human identities now: Not next quarter. Now. You cannot govern what you haven't inventoried.
  • Extend access reviews to include AI agents and service accounts: If your access reviews only cover human identities, they are covering less than half of your actual attack surface.
  • Stress-test your SSO trust relationships: Review every application federated into your identity platform and ask whether the trust relationship is still warranted and appropriately scoped.
  • Deploy cross-identity detection rules: Build detection for lateral movement that starts at a human identity and pivots to a non-human one. Most security information and event management (SIEM) rules were written for human behavior patterns. Agents behave differently, and adversaries know it.

The identity economy is the operating reality of modern enterprise security. Identity is how attackers move. Identity governance is how you stop them.

See you at Oktane!

These materials are for general informational purposes only and do not constitute legal, privacy, security, compliance, or business advice.

The content may not reflect the most current security, legal and/or privacy developments. You are solely responsible for obtaining advice from your own legal and/or professional advisor and should not rely on these materials for compliance, implementation, or purchasing decisions.

Okta makes no representations or warranties regarding this content and is not liable for any loss or damages resulting from your implementation of these recommendations. Information on Okta’s contractual assurances to its customers may be found at okta.com/agreements.

Continue your identity journey