Forecasts that place the machine identity security market above $26.97 billion by 2035 reflect a structural change in enterprise computing. Certificates, workload credentials, service accounts, API keys and AI agents now form a large population of non-human identities that require governance. Their growth is changing security from a people-centric access problem into a machine identity management discipline.

The problem

The market expansion is being driven by cloud migration, microservices, automation and the adoption of AI agents. Each layer creates identities that may be ephemeral, distributed across providers and difficult to associate with a human owner. Traditional IAM controls were designed around joiner, mover and leaver events; they are less effective when workloads are created and destroyed continuously.

What security teams should prioritise

A modern NHI security programme must discover machine identities across cloud accounts, code repositories, CI/CD pipelines and runtime environments. Discovery is only the first step. Organisations also need ownership, purpose, privilege, expiry and dependency data so that an apparently unused credential can be assessed before it is removed.

Certificate and secret lifecycle automation is another major market driver. Manual renewal creates outages, while untracked keys create exposure. Policy-based issuance, rotation and revocation can reduce both risks, provided the automation itself is protected and its actions are observable.

The rise of Agentic Identity adds a behavioural dimension. Security teams need to evaluate not just whether a machine identity is valid, but whether its activity is consistent with the workload it represents. Investment decisions should therefore prioritise shared inventory, least privilege, runtime context and integrations with incident response rather than isolated credential tooling.