As agentic AI proliferates, fragmented identity tools are creating a governance vacuum legacy security architectures were never built to close
Identity has overtaken malware as the number one attack vector in enterprise environments, and across Asia Pacific (APAC), the scale of the challenge has fundamentally changed. Machine identities now outnumber human workers 111:1 on corporate networks, driven by the rapid adoption of autonomous AI agents. Yet most organizations continue to secure their environments as though people are still the primary identity to protect.
At an interactive media session today, Palo Alto Networks drew on findings from the 2026 Identity Security Landscape Report, based on a global study of 2,930 cybersecurity decision-makers, to expose the widening gap between the scale of today’s identity environments and the architectures built to govern them.
Key APAC Findings
- The 111:1 ratio. Machine identities now vastly outnumber humans in APAC enterprise environments, driven by the proliferation of autonomous AI agents across business operations. 100% of APAC organizations have adopted AI agents, with the vast majority expecting their AI agent and machine identity footprints to grow further over the next 12 months.
- The breach reality. Nine in ten organizations have experienced a successful identity-related breach in the last 12 months.
- The certificate renewal risk. 97% of APAC organizations anticipate financial impact if certificate renewal is not fully automated, with the mean annual cost quantified at USD 305,161.
- The governance blind spot. 98% of human identities in APAC hold access permissions beyond what their roles require, while 98% of APAC organizations report experiencing identity silos, with the adoption of AI tools outside of formal identity and security governance cited as the top contributor. The cost is measurable: fragmented identity tools add an average of 13 hours of delay per incident response.
“Nine in ten organizations already experienced a successful identity-related breach this year, and machine identities are growing at close to a 40% compound annual rate, driven largely by the rise of AI. The findings from this year’s report is clear that most organisations aren’t effectively preventing identity-related breaches,” said Jeffrey Kok, Senior Director, Idira Domain Consulting at Palo Alto Networks. “What’s most concerning is fragmentation, which is significantly slowing organizations down: disconnected systems are adding hours of delay to every incident response, while attackers only need about an hour to breach. Attackers no longer need to break in; they simply log in using a stolen human or AI identity, and the only way to close that gap is a platform that can discover, control and govern every identity with the right level of security control. “
What This Means for ASEAN
The APAC findings carry sharp relevance for ASEAN, where enterprise AI adoption is accelerating rapidly, and the identity attack surface is expanding in step. As a prime example, Singapore’s numbers illustrate both the scale of the challenge and the urgency of the response.
In Singapore, machine identities already outnumber humans 107:1 on average, with 85% of organizations expecting both their AI agent and machine identity populations to grow further over the next 12 months. The drivers of this growth are telling: machine identity proliferation (51%), expanding third-party relationships including partners and service providers (43%), and LLM adoption (41%).
Siddharth Deshpande, Director of Industry Solutions at Palo Alto Networks JAPAC, added: “CISOs across Southeast Asia have two key priorities: Securing AI By Design and Fighting AI With AI. Identity security transformation is an opportunity to increase alignment between the business and security/risk teams. Breaking down traditional identity silos, eliminating standing privileges, and extending dynamic privilege controls across every human, machine, and agentic identity are critical to driving this transformation.”
What Needs to Change
Addressing the identity security gap requires organizations to rethink governance from the ground up, starting with three foundational shifts:
- Bring the Agentic Workforce into the Light. Discover and centrally manage AI agents across SaaS, cloud, and developer environments. Give agents access only for the duration of a specific task, and maintain a clear audit trail of what each agent did and on whose behalf.
- Implement Just-in-Time and Time-Bound Enforcement. Eliminate standing access across every access path. Grant permissions only when needed, revoke them automatically when the task is done, and log every action taken.
- Platformization and Automation of the Identity Lifecycle. Automating identity discovery, access governance, and real-time enforcement across human and non-human identities is the only way to respond at machine speed.
