The Ultimate Guide to Machine identity
A curated Kiwi edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Machine identity.
What to know about Machine identity
Machine identity is the foundation of trust between the countless non-human actors now powering modern IT – from servers, containers, APIs and IoT devices to AI agents and automated workflows. This tag explores how cryptographic keys, certificates and credentials function as “digital passports” for machines, and why securing them is just as critical as protecting human usernames and passwords.
Stories here track the rapid growth of machine and AI identities, the shift to short-lived TLS certificates, and the mounting risks from exposed keys, code-signing abuse and long-lived credentials. You’ll find research on dark web certificate marketplaces, real-world outages caused by legacy PKI, and reports revealing how often machine identities are unmanaged, over-privileged or completely invisible to security teams.
The coverage highlights how vendors, standards bodies and enterprises are responding: from certificate lifecycle management and machine identity control planes to new tools for governing AI agents at runtime. It examines partnerships, product launches and market trends around PKI, HSMs, service mesh security, Kubernetes, cloud-native environments and identity-first security architectures where machines now outnumber humans.
For security leaders, architects and DevOps teams, this tag offers a concise way to stay ahead of emerging threats and best practices in machine identity management. Reading these articles will help you understand where your organisation is most exposed, how automation and policy can prevent outages and breaches, and why identity – human and machine – is fast becoming the ultimate control point in an AI-driven world.
Analyst Insights
Research and market analysis connected to Machine identity
Claroty adds five partners to microsegmentation alliance
BeyondTrust named leader in KuppingerCole PAM report
AI, regulation & quantum top Gartner cyber trends for 2026
DigiCert named IDC MarketScape leader in CLM market
BeyondTrust appoints Felix Gaehtgens as Vice President of Product Strategy
Expert Columns
Why runtime identity is emerging as the next cybersecurity imperative
Don't be fooled: The SaaS label that's misleading your security team
From 398 to 200 Days: Understanding the TLS Certificate Lifespan Reduction
Why digital identity is the new perimeter in a zero-trust world
The new rules of digital identity in ANZ: KYC & AML trends for 2026
2026: Resilience, the new foundation of cybersecurity
Automation vital as TLS certificate lifespans shrink
2026 Predictions: The year identity becomes the ultimate control point for an autonomous world
Interviews
Interviews and video coverage from the networkRecent Machine identity News
KnowBe4 adds Claude oversight to Agent Risk Manager
Security teams can now monitor Claude-based agents for prompt injection, data leaks and rogue tool access as autonomous AI use spreads.
BeyondTrust warns identity risks drive most attacks
Three out of four offensive security investigations traced back to identity or privilege, exposing access gaps across cloud, SaaS and AI systems.
Google Cloud adds group IAM auth to AlloyDB preview
Large enterprises can now manage AlloyDB permissions through Google Groups, reducing shared credentials and tightening audit trails in preview.
Google Cloud expands Gemini enterprise agent controls
Businesses can now run and monitor AI agents for up to seven days as Google Cloud adds tighter identity and governance controls.
Delinea launches runtime authorisation for AI agents
Businesses using AI agents can now approve or block individual commands in real time, reducing the risk of authorised access doing unauthorised things.
Snowflake launches AI gateway for secure agent access
Enterprises gain tighter control as Snowflake centralises AI agent access, logging and spending across multiple platforms and security tools.
ThreatDown adds shadow AI & identity tracking tools
Security teams face higher breach costs as ThreatDown expands visibility over unsanctioned AI tools and machine accounts in one console.
Keyfactor expands partner push for AI & PQC services
Partners will be able to sell higher-margin advisory and managed services as organisations brace for AI-driven identity sprawl and PQC risk.
ManageEngine automates TLS certificate post-deployment
Shorter TLS certificate lifespans are set to raise outage risk and admin burden, as teams face far more frequent renewals and installs.
Barracuda buys Evo Security to bolster MSP identity tools
The deal gives managed service providers a broader way to control identities across customer systems as attacks on credentials and privileges rise.
AppViewX launches agent identity security for enterprises
Private preview access is now available as security teams race to govern AI agents and harden identity controls for a post-quantum era.
Okta deepens Google Cloud tie-up on AI agent security
The tie-up adds tighter access checks as firms deploy AI agents and browser tools more widely, amid rising identity attacks.
Saviynt adds AI agent runtime controls & verification
The new controls could help enterprises stop AI agents from exporting data or changing records when their actions stray beyond approved intent.
SailPoint to buy Entro in AI identity security push
The move would deepen SailPoint's reach into fast-growing machine identity risks as firms race to control AI agents and cloud credentials.
NEC Australia & Exabeam expand security partnership
The tie-up aims to help Australian organisations spot suspicious activity sooner as AI-driven systems and human users blur traditional security boundaries.
Forrester finds agentic AI stuck in enterprise pilots
Most enterprises are still failing to turn agentic AI trials into usable gains, as weak governance and orchestration keep deployments in pilot mode.
Tetrate & Ory launch AI agent security partnership
Businesses deploying AI agents can now add live request checks and step-up approval, reducing the risk of unauthorised tool use.
Tetrate & Ory secure AI agents with runtime controls
Enterprises testing AI agents in production will get parameter-level policy checks and step-up approval for risky actions through a new Ory-Tetrate setup.
DigiCert warns on certificate sprawl & outage risk
Only 34% of organisations have a current view of their digital certificates, leaving most exposed to outages from expired credentials.
Ping Identity adds controls for AI agents in businesses
Businesses adopting AI agents face new security and accountability risks as Ping Identity extends access controls, auditability and governance.