Machine identities now outnumber humans 80 to 1 — and nobody's watching what they cost
On July 30, 2026, Okta agreed to pay roughly $200 million for a startup that does one narrow thing: track which AI agents and machine identities in an enterprise still need to exist. The reason that's worth $200M: the average enterprise now runs more than 80 machine identities for every human employee, and over 16% of organizations don't even track when a new one gets created — let alone when it should be deleted.
A $200 million bet on a governance gap
Okta's target, Permiso Security, detects and mitigates threats across human, non-human, and agentic identities in multi-cloud environments. The deal, structured as an almost all-cash transaction valued at just under $200 million, is expected to close in Okta's fiscal Q3 2027. Okta isn't buying market share with this deal — it's buying a category that barely existed three years ago: knowing which AI agents are still alive, what they can access, and why they were created in the first place.
The ratio nobody budgeted for
KPMG's Cybersecurity Considerations 2026 report puts the average enterprise's non-human-identity-to-human ratio at more than 80 to 1, with machine identities jumping from roughly 50,000 in 2021 to 250,000 in 2025 — a five-year expansion that outpaced every identity governance process built for a world of human employees and a handful of service accounts. Palo Alto Networks' 2026 Identity Security Landscape report puts some enterprises even higher, at 109 machine identities for every human identity.
Why an orphaned agent is a budget line, not just a security hole
AI agents acquire permissions dynamically at runtime, spawn sub-agents, invoke external APIs, and chain together actions across dozens of systems — which is exactly why a compromised or forgotten one is dangerous. But the same properties make an orphaned agent a live cost problem, not just a security one: an agent nobody remembers creating doesn't stop calling the model API when the project that spawned it ends. It just becomes spend with no owner, invisible until someone reconciles a bill against a headcount that hasn't changed.
A 2026 Cloud Security Alliance analysis found more than 16% of organizations don't track the creation of AI-related identities at all. That's the same blind spot showing up twice — once as a security gap, once as a cost attribution gap — because it's the same missing inventory underneath both.
The breach cost is already priced; the phantom-spend cost usually isn't
Sophos's State of Identity Security 2026 survey found 71% of organizations suffered at least one identity-related breach in the past year, at a mean recovery cost of $1.64 million, with weak non-human-identity management cited as a contributing factor. Security teams have started pricing this risk explicitly enough to justify a $200M acquisition. FinOps and platform teams mostly haven't made the equivalent connection yet: every ungoverned agent identity sitting in that 80-to-1 ratio is also a credential that can keep drawing against an API budget indefinitely, with no expiration tied to the project it was built for.
What to check before adding another agent
- Do you have a single inventory of every API key and agent identity, or does each team spin up and track its own?
- Is there an offboarding step when a project or experiment ends, or do keys simply go stale until someone notices a strange line on an invoice?
- Can you attribute API spend to a named, still-active agent — or does "agent-something" show up as an unowned, unexplained line?
The bottom line
A $200 million acquisition is a strong signal that machine identity sprawl has crossed from theoretical risk to board-level priority — but it's being priced almost entirely as a security problem. The same 80-to-1 ratio that keeps security teams up at night is quietly running up an API bill nobody's watching, one orphaned agent at a time. The fix for both starts in the same place: an inventory that knows which agents are still supposed to exist.
Know which agent is spending, not just which agent exists.
AIntOps connects to OpenAI, Anthropic, and Gemini in under a minute and attributes every API call to the exact key, feature, and agent that generated it — so an orphaned identity shows up as an unowned cost the moment it starts spending, not a mystery line three weeks later. Join the beta and get Pro free for 3 months.
Try AIntOps Free →No credit card required · Setup in 30 seconds · Free up to $500/mo AI spend