TL;DR: When AI significantly expanded the number of identities requiring access, reported breach rates reached 43% in the past year versus 11% where access patterns did not change, according to Cakewalk’s summary of Netwrix and ISACA research. The signal is not just adoption, but standing access that governance teams cannot revoke fast enough once AI systems are live.
NHIMG editorial — based on content published by Cakewalk: Where AI Expands Access, Breaches Run Four Times the Rate
By the numbers:
- Among organizations where AI significantly expanded the number of identities requiring access, breach rates reached 43% over the past twelve months, compared with 11% where AI had not materially changed access patterns.
- Only 19% of organizations say they fully govern their non-human identities, the service accounts and agent credentials that now act inside company systems.
- 56% of professionals did not know how long it would take to halt an AI system during a security incident.
Questions worth separating out
A: Security teams should treat AI agents, service accounts, and integrations as first-class identities from the moment they appear.
Q: Why do AI systems with standing access increase breach risk?
A: Standing access increases breach risk because the identity keeps its reach long after the original task or approval context has changed.
Q: What breaks when organisations cannot halt an AI system during an incident?
A: What breaks is containment.
Practitioner guidance
- Map AI-linked identities to standing access paths Inventory every service account, token, and agent credential that can be used by AI systems, then trace where standing permissions remain after deployment.
- Test revocation across the full access chain Measure how long it takes to remove AI access from applications, data sources, orchestration layers, and downstream integrations, then close the slowest handoff points.
- Reduce blast radius with task-scoped permissions Replace broad entitlements with narrower roles, constrained tool scopes, and time-bound access that matches the actual task window.
What's in the full report
Cakewalk's full article covers the operational detail this post intentionally leaves for the source:
- The full survey breakdown from Netwrix and ISACA, including respondent counts and the underlying question set.
- The article's direct comparison of breach rates, AI policy maturity, and revocation confidence across the two surveys.
- The source's original framing of how organisations are handling AI access expansion and shutdown uncertainty.
- The published citations and source notes for the two 2026 surveys used in the analysis.
👉 Read Cakewalk's analysis of how AI access is outpacing governance →
AI access and governance gaps: why breach rates are climbing?
Explore further
Standing AI access is now the central governance failure. The article shows that organisations are not failing because they lack policies, but because they are issuing access faster than they can constrain it. That pattern creates persistent entitlement exposure across non-human identities and AI-enabled workflows. The practitioner conclusion is clear: access governance must be measured by revocation speed and entitlement scope, not by policy count.
A few things that frame the scale:
- Only 19% of organizations say they fully govern their non-human identities, according to The State of Non-Human Identity Security.
- In the same research, 85% of organizations lack full visibility into third-party vendors connected via OAuth apps, which leaves delegated access outside clean lifecycle control.
A question worth separating out:
Q: Who is accountable when AI-related access outpaces governance?
A: Accountability sits with the owners of identity, data, and platform controls together, because AI-related access problems cross programme boundaries. IAM, IGA, PAM, and security leadership must share responsibility for visibility, revocation, and ownership. If one team can create access but no team can remove it quickly, the control model is incomplete.
👉 Read our full editorial: AI access is outpacing governance, and breach rates are rising