Only 1% of organisations have fully adopted Just‑in‑Time (JiT) privileged access, leaving them exposed to a surge in AI identities that are creating major blind spots in visibility and control, new research from CyberArk warns.
The 2025 State of Machine Identity Security Report – a survey of 500 professionals working across privileged access management and identity – found a significant gap between firms’ confidence in their access controls and their day-to-day practices as AI rapidly expands identity attack surfaces.
For example, although three-quarters (76%) of organisations said their privileged access management (PAM) strategies are ready for AI, cloud and hybrid environments, 91% report that at least half of their privileged access is always-on, providing unrestricted, persistent access to sensitive systems.
CyberArk found that these “always-on” access assumptions are heightening the risks of “shadow privilege”, unmanaged, unknown or unnecessary privileged accounts and secrets that accumulate silently over time.
More than half of firms (54%) admit they uncover unmanaged privileged accounts and secrets every week, a problem made worse for the 63% of organisations that say their employees routinely bypass existing controls to move faster.
While the vast majority of businesses (88%) agreed that tool sprawl and fragmentation have introduced blind spots to identity management, the explosion in AI identities has added a significant new layer of risk.
Despite a third of firms (33%) reporting they still don’t have clear AI policies around access, 45% have charged ahead and are providing AI agents with the same privileged access controls as human identities.
Recommended reading
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
- Identity Fraud Set to Explode in 2026, Warn Security Pros
- Report: More Than 50% of Fraud Is Now Driven by AI
“Dynamic, evolving environments mean the nature of privileged access, and how to secure it, has fundamentally changed,” said Matt Cohen, CEO of CyberArk.Â
“With only one per cent of organisations having fully implemented a Just-in-Time access model, it’s clear that industry-wide modernisation is overdue.Â
“As AI agents and non-human identities take on increasingly sensitive tasks, applying the right privilege controls to each identity, and governing every privileged action, is now essential.”Â
To reduce risk while supporting innovation, CyberArk recommends organisations focus on evolving how privileged access is applied by adopting automated and orchestrated Just-in-Time access for high-risk or sensitive actions, consolidating identity platforms to improve visibility, and applying privilege controls across human, machine and AI identities, based on context and risk.





