Product1 publisher2 min readPublished
Palo Alto Networks finds 37% of organizations can revoke an AI agent's credentials
Palo Alto Networks surveyed the identity market it sells into. It found that almost every organization has deployed AI agents and that most cannot switch one off. Now it is selling the maturity model to close the gap.
The Product Desk · Product desk

What happened
- Palo Alto Networks counts 109 machine identities for every human in the enterprise this year, up from 82 to 1 last year, in its 2026 Identity Security Landscape report.
- The same report says 99% of organizations have adopted AI agents.
- 40% of those agents already have access to organizational data.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint The vault that most teams standardized on rotates on a schedule measured in hours, so it cannot contain an agent compromise that ends inside the hour. A different control answers the question on the incident call.
- exposure Most organizations would walk into an incident review for an agent they can neither stop nor evidence, and the person who shipped the agent is the one who answers for both.
- decision Any team about to promote an agent pilot to production now has a gate to set: name the owning human and the revoke path before the agent gets read access to company data.
- contradiction The survey that sizes the gap and the maturity model that closes it come from the same vendor. No sample size or definition of adoption is disclosed, so buyers are pricing a problem measured by the seller.
Revoking a credential is the crudest off switch there is, and it is the one Palo Alto Networks asked about. Its report also puts immutable audit logging of agent activity at 30% [5]. Read the two findings from the other side and 63% of organizations cannot cut an agent's credentials on demand, while 70% cannot produce a tamper-proof record of what the agent did before anyone thought to ask [2][3].
The timing is where the vault stops helping. Unit 42's incident response report puts the path from initial access to exfiltration at 25 minutes for AI-assisted attacks [6], and Palo Alto Networks says the fastest rotation policies measure in hours [8]. At an hourly rotation, the attack finishes with 35 minutes to spare before the credential changes [4].
The two survey numbers most likely to end up on a slide together do not share a denominator. The 40% is a share of agents with data access; the 37% is a share of organizations that say they can revoke [6]. Nothing in the post says how many organizations answered, who they were, or what counted as adopting an AI agent [15]. That last omission decides how much the adoption figure means, because one sanctioned pilot in one business unit puts a whole company inside it.
What the post describes is agents running on static API keys handed out of a vault, and it says AI agents need cryptographic identity instead [13]. Growth will not relieve the pressure. 77% of organizations expect machine identities per human to keep climbing [7], and the ratio already grew about 33% in a year [1].
The thing to fix by Monday is three fields per agent in production: the named human who owns it, the credential it authenticates with, and the time from a decision to kill it to the moment it stops making calls. Measure that last one end to end. Anything slower than half an hour outlasts the intrusion Unit 42 timed [6].
Palo Alto Networks sells the long version of this as a five-level maturity index, opened at its Impact 2026 conference in Austin, and the post concedes that most enterprises will not sit at a single level [9][10]. The level-one KPI is the percentage of secrets inventoried across cloud, on-premises, CI/CD and SaaS environments, with the vendor's own Idira Discovery and Context named as the tool for surfacing the unmanaged ones [11][14]. On that first metric the post writes: "If you can't answer this with a number, you're still at level 1." [12]
What to watch
- Whether the 2026 Identity Security Landscape Report publishes its sample size and its definition of AI agent adoption.
- Whether any agent platform ships a per-agent revoke that someone outside engineering can trigger, and how long it takes end to end.
- Whether Unit 42's next incident response report moves the access-to-exfiltration window in either direction.