Stolen machine identities just became the top way hackers break into companies. Just weeks after this data dropped, tech leaders shared free code to help fix the massive blind spot.

The big picture:

The gap between what bosses believe and what is true keeps growing.

A SpyCloud poll of 750 security chiefs shows that stolen non-human identities (NHIs) are now the main way attackers get in [1]. These include service accounts, application programming interface (API) keys, and artificial intelligence (AI) agents. I have been watching this shift, and the blind spot shocks me. Most firms (95%) say they see their machine identities. Yet only 36% actually track them [1].

Rule-making lags behind tech use. About 91% of companies run AI agents with deep access, but just 56% have strict rules for them [1]. My read: firms still treat safety as a paper document, while the live systems ignore it.

By the numbers

  • 31% vs 17% — NHI entry point: stolen machine identities are nearly twice as likely as phishing to let hackers in [1].
  • 95% vs 36% — Tracking gap: firms that think they track machine identities versus those that really do [1].
  • 91% vs 56% — Rule lag: firms running AI agents with deep access versus those with strict rules for them [1].
  • 3 — Open control backers: OpenAI, Red Hat, and a top chipmaker are building OpenClaw Enterprise as free software for always-on agents [2].
You Think You're Governing Your AI Agents. The Data Says… Figures as stated in this article's own numbers section (verified figures, %) NHI entry point 31% ([1]) Tracking gap 95% ([1]) Rule lag 91% ([1])

What I’d watch:

The builders closest to this problem are voting with code. Red Hat calls OpenClaw Enterprise a major shift for agents. They frame it as a tool to run agents across teams [2]. Kevin Lin leads this work at OpenAI. He notes that companies want the same safety from agents that they expect from normal software [2].

What I’d watch next:

  • The live replacement: engineers are moving rules into the active systems with scoped access and instant cut-offs. I want to see if this live layer closes the 95-to-36 tracking gap [1][2].
  • The RBAC shift: role-based access control (RBAC) checks human logins, but agents keep acting long after that. I am curious how many firms will wire new tokens together to manage this live access [4].
  • The rule hammer: 94% of groups work where AI laws apply, but only 29% are ready for the European Union (EU) AI Act [3]. I expect this new software to become the exact proof that auditors demand.

The catch

I could be wrong that this software fixes the debate. Free code is still early tech. Open software does not mean safe systems. Better tools fail to fix the blame gap if nobody owns the identities. A control plane only keeps a company safe if a human turns it on and runs it. That 95-to-36 tracking gap is a belief problem. Belief rarely changes just because the tools get better.

At a glance

  • The Big Shift: Non-human identities (NHIs) are now the main way hackers breach firms, showing a huge gap in tracking. Meanwhile, tech giants just launched OpenClaw Enterprise to move agent rules from static paper to live systems.
  • Why It Matters: Enterprise AI rules are moving out of paper documents and into the live tech stack. With 94% of firms facing AI laws and only 29% ready for the European Union (EU) AI Act, active checks are now a must.
  • What I’d Watch: whether these live systems actually force firms to track their agents.
  • Control plane: the software layer that actively limits what an agent can do in real time.
  • Non-human identity (NHI): the keys or accounts that let software act inside a system.
  • RBAC (role-based access control): an older model that grants access based on a human’s job at login, which fails when agents act on their own.
  • The Catch: open tools do not fix broken trust. System upgrades cannot solve the safety gap if no one actively owns and tracks the machine identities.

Related reading

Sources

[1] SpyCloud — 2026 Identity Threat Report (https://spycloud.com/newsroom/spycloud-2026-identity-threat-report-finds-non-human-identities) [2] Red Hat — “Why Red Hat is building an open foundation for enterprise agents with OpenClaw Enterprise” (https://www.redhat.com/en/blog/why-red-hat-building-open-foundation-enterprise-agents-openclaw-enterprise) [3] Cloud Security Alliance — “Enterprise Reality: Why Organizations Aren’t as Prepared for AI Governance as They Think They Are” (https://cloudsecurityalliance.org/blog/2026/09/16/enterprise-reality-why-organizations-aren-t-as-prepared-for-ai-governance-as-they-think-they-are) [4] Cloud Security Alliance — “Shadow AI Does Not Read Your Org Chart: Rethinking Identity Governance for Autonomous Agents” (https://cloudsecurityalliance.org/blog/2026/09/08/shadow-ai-does-not-read-your-org-chart-rethinking-identity-governance-for-autonomous-agents)