← All Articles Radar Editorial
Security Blog

AI Agents Now Outnumber Human Employees 45 to 1, and Most Companies Can't Tell Them Apart in Logs

By AI SaaS Radar Team · Aug 2026 · 5 min read

A 2026 Cloud Security Alliance analysis puts a number on something security teams have been describing anecdotally for a while: AI agent service accounts, API keys, and OAuth tokens are proliferating inside companies largely without anyone tracking the total. Across organizations broadly, AI agents now outnumber human identities 45 to 1. In cloud-native environments specifically, that ratio climbs to 144 to 1.

The identity count isn't the most concerning number in the CSA whitepaper. It's this one: 68% of organizations say they cannot reliably distinguish AI agent activity from human activity in their own logs. When an incident happens, most security teams looking at their own audit trail can't tell whether a given action was a person or an agent acting on that person's behalf, which makes root-causing any breach involving agent credentials substantially harder.

Only 15% of organizations feel confident they could actually prevent an attack based on a compromised non-human identity, a service account, API key, or OAuth token belonging to an agent rather than a person. Given that these identities already outnumber human ones by double digits, and by triple digits in cloud-native setups, that confidence gap is the practical risk, not the raw count of agents in use.

The starting point for closing that gap is inventory: knowing how many non-human identities exist, what each one can actually reach, and whether any of them have gone stale. Most organizations, per CSA's numbers, don't have that visibility yet, which means the 45-to-1 ratio is likely to keep climbing faster than the controls around it.

Stay ahead of the AI SaaS market

Sourced, dated analysis on security, funding, and benchmarks. Straight to your inbox.

No spam. Unsubscribe anytime.