Forecasts that the machine identity security market could surpass $26.97 billion by 2035 reflect how quickly non-human identities are becoming a board-level security concern. Certificates, keys, tokens, workloads and AI agents now operate across nearly every enterprise system. Their scale makes manual management impractical and unmanaged access a material risk.
The market growth is being driven by a widening machine identity attack surface. Cloud workloads start and stop dynamically, APIs connect services across organisational boundaries and AI agents add decision-making capability to automated processes. Each identity may hold credentials that remain active long after its original purpose has changed.
This creates a visibility problem before it becomes a control problem. Organisations cannot apply least privilege to identities they cannot discover. Effective NHI security programmes need inventories that connect a machine identity to its owner, workload, environment, credentials, permissions and recent activity. Without this context, security teams tend to rotate secrets reactively or respond to incidents one system at a time.
Certificate and key management remain important, but modern machine identity management increasingly includes behaviour and intent. A credential used from an unexpected workload, an agent requesting an unusual tool or a service account accessing data outside its normal pattern can all indicate risk. Combining lifecycle data with runtime telemetry allows policies to respond to changing conditions.
AI agents make this urgency more visible. Unlike a static service, an agent can interpret natural-language instructions and chain multiple actions. Its identity must therefore be bound to a defined purpose, constrained tools and an accountable owner. Agentic Identity controls can limit where an agent operates, what it can change and how long its authority remains valid.
Market expansion also suggests that organisations are moving toward consolidated platforms. Security teams want fewer disconnected inventories and more consistent policy across cloud, application, certificate and AI environments. Integration with existing IAM, security operations and secrets systems will be critical because machine identities rarely stay within one product boundary.
For CISOs, the forecast is less about a single market number than about the cost of unmanaged automation. Investment in discovery, governance, credential protection and runtime enforcement can turn machine identity from an invisible dependency into a measurable security control.