As autonomous AI agent adoption accelerates, identity has overtaken malware as the primary attack vector in enterprise environments across the Asia Pacific (APAC) region. Machine identities now outnumber human workers 111:1 on corporate networks, yet most organizations continue to focus security strategies primarily on human identities.
At a media session today, Palo Alto Networks presented key findings from its 2026 Identity Security Landscape Report, based on a global survey of 2,930 cybersecurity decision-makers, highlighting the growing gap between enterprise identity environments and current governance architectures.
Key findings for the APAC region include:
- 111:1 Machine-to-Human Ratio: Driven by AI agent adoption across operations, 100% of APAC organizations have deployed AI agents, with most expecting machine identities to increase over the next 12 months.
- Prevalence of Breaches: 90% of organizations in APAC experienced a successful identity-related breach in the past 12 months.
- Certificate Renewal Risks: 97% of APAC organizations anticipate financial impacts if digital certificate renewal is not automated, with costs averaging USD 305,161 annually.
- Governance Blind Spots: 98% of human identities hold access permissions exceeding their job roles, and 98% of organizations report identity silos—primarily caused by unmanaged AI adoption. Disconnected identity tools add an average of 13 hours to incident response times.
Jeffrey Kok, Senior Director of Idira Domain Consulting at Palo Alto Networks, noted that machine identities are growing at nearly a 40% compound annual rate. He stated that fragmented systems slow down organizational response times to hours, whereas attackers need about an hour to gain breach access using stolen human or AI credentials. He emphasized the necessity of a single platform to discover, control, and govern all identities.
In ASEAN, enterprise AI adoption is similarly expanding the identity attack surface. In Singapore, machine identities outnumber humans 107:1, with 85% of organizations expecting further growth over the next 12 months. Key growth drivers include machine identity expansion (51%), third-party partner relationships (43%), and LLM adoption (41%).
Siddharth Deshpande, Director of Industry Solutions at Palo Alto Networks JAPAC, stated that CISOs in Southeast Asia are focused on Securing AI By Design and Fighting AI With AI. He highlighted the need to eliminate identity silos, remove standing privileges, and implement dynamic privilege controls across human, machine, and agentic identities.
To address the identity security gap, the report recommends three foundational changes:
- Centralized AI Agent Visibility: Discover and manage AI agents across SaaS, cloud, and developer environments with task-specific, time-bound access and complete audit logs.
- Just-In-Time Access Enforcement: Eliminate standing access permissions across all pathways, granting access only when required and revoking it upon task completion.
- Lifecycle Automation and Platformization: Automate identity discovery, access governance, and real-time enforcement across both human and non-human identities to match threat response speeds.
LG launches Robotics Business Center to drive Physical AI
MHESI-NXPO-AIS Academy-IRIS launches ‘TARI’ to assess national AI readiness


