Grady Summers, CEO at Netwrix.gettyA 19th-century astronomy problem and new data on AI governance are pointing at the same thing.Astronomers weren't looking for a planet when they discovered Neptune. They were trying to figure out why its twin ice giant kept drifting off the path Newton's equations predicted, and it turned out Neptune was the answer. Its gravity had been pulling the other planet off its expected course. I kept coming back to that story while working through my company's 2026 Data & Identity Security Report. We surveyed 2,317 security and IT leaders globally in early 2026. Organizations where AI has significantly increased the number of identities in their environment reported a 43% breach rate over the past 12 months. Where AI hasn't meaningfully changed the identity footprint, the rate was 11%, and that fourfold gap was the cleanest signal in the survey.My first assumption was a maturity story. The most aggressive AI adopters might simply be the companies most willing to throw caution to the wind, perhaps laggards on identity fundamentals whose AI push exposed what was already broken. The data refused to cooperate: The organizations leaning hardest into AI are measurably ahead on the fundamentals that have anchored identity security for a decade. They were less likely to lack a continuous data inventory (46% versus 60% of everyone else), reported stronger governance of nonhuman identities (25% weak versus 44%) and had better visibility into shadow AI inside their own walls (13% blind versus 25%). As we noted in the report: "They invested in the playbook. They got breached anyway."That's the same kind of drift the astronomers were staring at. The model says organizations doing those things should be breached less, and the fastest AI adopters are measurably off the predicted path. A discrepancy that sharp usually means something the model never accounted for is pulling on the results. Taking The Discrepancy SeriouslyThere's a stronger objection to rule out before trusting the number. Maybe the 11% figure understates reality, because organizations that haven't adopted AI often lack the visibility to detect breaches at all. We tested that directly: Inside the cohort reporting no growth in agentic identities, organizations with strong visibility reported a 6.6% breach rate, those with weak visibility reported 11.4% and another 32% couldn't answer the question at all. So undercounting is clearly present, and even if the weak-visibility group is missing breaches at two or three times the rate they admit, the gap with aggressive AI adopters stays several-fold wide and the finding holds.Built For A Different LoadHere's my read on what that something is. Point-in-time inventories, periodic access reviews and human-paced provisioning workflows were built for an identity surface that grows at the pace of hiring. AI agents, co-pilots and integrations grow at the pace of deployment, and every one of them is a new identity asking for access to your data.An agent can be created this afternoon, inherit access and permissions immediately, and still be running months after the business problem it solved has disappeared, with nothing prompting anyone to ask whether it should exist. That growing population of identities is the unseen planet in this story: 41% of organizations run agentic AI in production today, while only 19% say they fully govern the nonhuman identities in their environment.Attackers widen the mismatch because AI works for both sides. Adversaries now iterate reconnaissance and attack methods at machine speed and can move from initial access to meaningful impact in minutes. Meanwhile, just 23.5% of organizations can respond to identity threats automatically in real time, and 62.9% still need one to three days. Remediation measured in days against an adversary operating in minutes isn't a strategy. It amounts to accepting the breach in advance.Where The Exposure ConcentratesThe risk doesn't fall evenly: Mid-market organizations of 500 to 999 employees reported a 40% breach rate, the highest of any size band. These are companies carrying enterprise-grade data with small-team resources, and they told us where they're stuck: 32% cite budget as their primary barrier and 28% cite skills. They know what to do but can't staff it at the scale AI demands.I've come to see this as an operating model challenge more than a compliance initiative. Organizations have spent years building separate programs for data security, identity governance and privileged access, each with its own owner and review cycle. Attackers don't respect those boundaries, and neither does AI. For leaders deciding where to start, three questions do most of the work:• Do we have a continuous inventory of every identity, human and machine, and what each one can touch?• Are we granting standing access, or access that expires when the task does?• And do the people responsible for identity, data and AI governance actually see the same picture?The fundamentals behind those questions haven’t stopped mattering, but they’ve moved from sufficient to necessary. In our data, the breach rate climbs another 14 points when organizations tolerate widespread overprovisioning, and another seven when standing privileged access is the norm. Least privilege and just-in-time access remain the cleanest ROI in security spending, though they're now table stakes rather than the finish line. Back To NeptuneBoards increasingly ask management about the ROI they're seeing from AI, and it's a fair question. The one I'd put alongside it is whether governance can adapt as quickly as AI changes the business, because for many organizations in our data, AI has already inherited more than anyone is watching.The 43% figure implicates the exact organizations moving the way every board is asking companies to move, mine included. The astronomers who found Neptune were the ones willing to take the discrepancy seriously instead of explaining it away, and Newton's equations came through the episode intact. We gave the 43% figure the same treatment. It survived, and that's usually the point where I stop arguing with the data and start acting on it.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Why Early AI Adopters Are Getting Breached More Often
AI agents, co-pilots and integrations grow at the pace of deployment, and every one of them is a new identity asking for access to your data.
AI-heavy organizations report 43% breach rates versus 11% for non-adopters, despite strong identity governance practices. Agentic identities scale at deployment pace, faster than traditional point-in-time provisioning; only 23.5% of organizations detect threats in real time.








