TL;DR: AI agent identity volumes could outpace human users by 25:1 as businesses move from traditional identities to short-lived, high-density agent workloads, according to C1.ai. The real issue is not count alone but the collapse of manual governance models when identities become ephemeral, numerous, and increasingly autonomous.
NHIMG editorial — based on content published by C1.ai: The Inevitable AI Wave: Modeling the AI Agent Explosion
By the numbers:
- AI identities will soon outnumber human users 25:1.
- A 1,000-person company could suddenly be managing hundreds of thousands or even millions of AI agent identities annually.
Questions worth separating out
Q: How should security teams govern AI agents that use multiple identity layers?
A: Security teams should inventory every identity layer an agent can use, including static credentials, session identities, embedded tool identities, and any delegated relationships between agents.
Q: Why do AI agents make non-human identity governance harder?
A: AI agents make governance harder because they can request tools, act autonomously, and change behaviour across sessions while still relying on machine credentials.
Q: What breaks when organisations treat agent identities like service accounts?
A: What breaks is accountability.
Practitioner guidance
- Inventory agent identities by business function Map every known AI agent to an owning team, application, and access scope before deployment expands further.
- Design for short-lived credentials and expiry Issue credentials only for the duration of the task, and require automatic teardown when the agent completes its work.
- Bind approval and accountability to the workflow owner Make one business owner responsible for each agent-driven workflow, including periodic validation of scope, logs, and revocation paths.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- The article’s reasoning model for comparing servers, VMs, containers, serverless, and AI agents across identity density.
- The specific examples of how a 1,000-person organisation can accumulate hundreds of thousands or millions of agent identities.
- The source’s own framing of ephemeral-by-default access and why short-lived credentials become essential.
- The call to action around AI-native IDP design and density-driven identity planning.
👉 Read C1.ai's analysis of the AI agent identity explosion →
AI agent identity sprawl: what happens when density explodes?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI agent density is now an identity governance problem, not an application feature problem. Once every business workflow can spawn agents, the number of identities becomes operationally meaningful in its own right. The article’s 25:1 projection is less important than the direction of travel: governance demand grows faster than human staffing models can absorb. Practitioners should treat agent population growth as a control design input, not a deployment side effect.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: How do organisations keep AI agent sprawl under control?
A: Organisations need a clear inventory, a named owner for each workflow, and automatic expiry for each agent credential. They also need telemetry that shows when agents are accessing data or invoking tools outside their expected scope. Without those controls, sprawl becomes a governance problem rather than an automation gain.
👉 Read our full editorial: Modeling the AI agent explosion and its identity governance burden