MCKINSEY TECH TRENDS 2026
The Identity Check That Keeps AI-Speed Hackers Out of Your Business

McKinsey says bots and AI agents now outnumber people in company systems about 100 to one. Here is a six-question check to control who and what can act in yours.

18 min read

Ask a business owner who has access to their systems and they will usually count people: staff, a bookkeeper, maybe an IT contractor. That count is now badly out of date. Every automation, integration, bot and AI agent that logs in and acts on its own is also a user, and most businesses have far more of those than they think.

McKinsey’s Technology Trends Outlook 2026 describes a security landscape that AI has changed on both sides. Attackers use it to find and exploit weaknesses faster than ever, and companies are deploying AI agents that need access to do their jobs. The report’s message is that security is no longer only about keeping outsiders out. It is about knowing, at every moment, who or what is acting inside your systems and whether it should be. This article turns that into a simple identity check any growing business can run.

~100:1
software identities, such as bots and agents, to human users in many organizations
3 in 4+
vulnerabilities classified as zero day, meaning an exploit exists by the time the flaw is disclosed
+49%
more active ransomware and extortion groups in a single year

All figures: McKinsey & Company, Technology Trends Outlook 2026, Cybersecurity and trustworthy systems chapter, including third-party sources the report cites (Palo Alto Networks, Zero Day Clock and IBM’s 2026 X-Force Threat Intelligence Index).

THE 60-SECOND VERSION
  • AI has collapsed the gap between a weakness being found and being exploited, according to McKinsey. Waiting for the next patch is no longer a plan.
  • Machines now vastly outnumber people as users of company systems, and every AI agent you deploy adds another.
  • The report says leading security teams are moving from guarding the perimeter to checking every user, device and agent continuously.
  • VIVISION’s view: for a growing business, the highest-return first step is an identity check. Know every account that can act in your systems, human or not, and give each one an owner and a limit.

Pictogram: one human user next to a grid of 100 software identities such as bots and AI agents, showing that software identities outnumber human users by roughly 100 to one in many organizations
Palo Alto Networks data as cited in McKinsey’s Technology Trends Outlook 2026. The ratio is approximate. Chart redrawn by VIVISION.

McKinsey reports that in many organizations, software identities such as bots or agents that can access systems and act automatically now outnumber human users by roughly 100 to one. The report adds that security teams can no longer treat identity as a human-only issue, and that companies are replacing fixed role-based permissions with unified identity governance, password-free sign-in and access rules that take context into account.

01 / THE WINDOW HAS CLOSED

You no longer get weeks to patch

For years, businesses had a buffer. McKinsey notes that organizations historically had weeks or months between a software weakness being identified and attackers actively exploiting it. That buffer has shrunk dramatically, the report says, because AI helps attackers find weaknesses, build exploits and launch attacks much faster.

HOW IT USED TO WORK

A flaw is found, a patch comes out, and you have weeks or months to install it.

Security means a strong wall around the network. Whoever is inside is trusted.

HOW IT WORKS NOW

By the time most flaws are made public, an exploit already exists.

Nothing is trusted by default. Every user, device and agent is checked continuously, even inside the network. McKinsey calls this principle zero trust.

Gauge chart: more than three-quarters of cybersecurity vulnerabilities are classified as zero day, meaning an exploit already exists when the flaw is publicly disclosed
Zero Day Clock data as cited in McKinsey’s Technology Trends Outlook 2026. Chart redrawn by VIVISION.

The report also cites IBM’s 2026 X-Force Threat Intelligence Index: exploitation of public-facing applications, such as websites, customer portals and online booking systems, rose 44 percent in a single year, which McKinsey says directly fueled a 49 percent rise in the number of active ransomware and extortion groups.

Arrow chart indexed to the prior year: exploitation of public-facing applications up 44 percent and active ransomware and extortion groups up 49 percent in one year
IBM X-Force Threat Intelligence Index 2026 as cited by McKinsey. Indexing to 100 is VIVISION’s presentation. Chart redrawn by VIVISION.
VIVISION insight. Smaller firms often assume they are too small to be a target. The numbers above describe attacks that are cheaper and faster to run at scale, which makes that assumption weaker every year. You cannot outrun AI-assisted attackers on patch speed alone. What you can control is how far an attacker gets once they find a way in, and that comes down to which accounts exist and what each one is allowed to do.

02 / THE NEW USERS OF YOUR SYSTEMS

When an agent acts, can you say who allowed it?

As companies deploy AI agents and automated workflows, McKinsey says spotting unusual activity is no longer enough. Those workflows need to be auditable, which the report frames as three questions every business should be able to answer:

1
Who authorized this action?
2
Did the agent stay within the job it was given?
3
How was permission passed from one system to the next?

The report also notes a real test in which an autonomous AI agent chained dozens of separate steps to turn one low-severity flaw into full unauthorized access to files. Scanners that look at one weakness at a time are not built to catch that kind of path. The practical lesson: a small gap plus a powerful account is how minor issues become major incidents.

“Trust belongs in the value case, not just the risk register.”

Roger Roberts, partner, McKinsey, in Technology Trends Outlook 2026.

03 / THE 10-MINUTE IDENTITY CHECK

Score your business in six questions

This is VIVISION’s self-assessment, built on the identity and zero-trust shift McKinsey describes. Give yourself 2 points for “yes”, 1 for “partly” and 0 for “no” or “not sure”.

# Question Why it matters
1 Do you have one list of every account that can log in to your systems, including bots, integrations and AI tools? You cannot protect accounts you do not know exist.
2 Does every non-human account have a named person who owns it? Ownerless accounts are rarely reviewed or switched off.
3 Does each account have only the access its job needs? Limits how far one small gap can spread.
4 Is multi-factor or password-free sign-in on for every human account? A password alone is the weakest lock on the door.
5 Can you see a log of what your AI tools and automations actually did last week? This is the auditability McKinsey says agentic workflows now need.
6 When someone leaves or a tool is dropped, is its access removed within a day? Old keys that still work are an open door.
0 to 5
Exposed. Start with question 1 this week.
6 to 9
Foundations in place, gaps around bots and AI tools.
10 to 12
Ready to scale AI agents with confidence.
VIVISION insight. In the businesses we work with, question 2 is where scores drop fastest. Integrations and AI tools get connected by whoever needed them that week, with an admin-level key, and then everyone forgets about them. Giving every non-human account an owner costs almost nothing and makes every other control on this list work.

04 / WHAT ELSE IS ON THE RADAR

Two things to note, not panic about

QUANTUM-SAFE ENCRYPTION

McKinsey says the risk of “harvest now, decrypt later”, where attackers store encrypted data today to crack with future quantum computers, has become an active planning priority. It matters most for firms that hold long-lived sensitive data, such as health, financial or legal records. VIVISION’s view: if that is you, ask your key vendors about their quantum-safe plans this year.

VENDOR CONSOLIDATION

The report describes a market consolidating around platforms that bundle identity, cloud security and automated threat detection, and flags the risk of depending on a few dominant vendors. VIVISION’s view: fewer tools is usually better for a small team, but know how you would leave before you sign.

YOUR MONDAY CHECKLIST
☐  Export the user list from your email, finance and customer systems. Mark every account that is not a person.
☐  Put a name next to each non-human account. Anything nobody claims gets switched off after a week’s notice.
☐  Find any integration or AI tool with admin rights and reduce it to what the job needs.
☐  Turn on multi-factor sign-in wherever it is still optional.
☐  List your public-facing apps (website, portals, booking and payment pages) and confirm who keeps each one updated.

Quick answers

We use cloud software for everything. Isn’t security the vendor’s job?

Partly. Vendors secure their platform, but you decide who and what gets access to your account and what each can do. That is exactly the identity layer McKinsey says has become central. VIVISION’s view: it is the part most small businesses leave unmanaged.

Should we slow down our AI rollout until security catches up?

Not necessarily. McKinsey frames trust as something that increases the value of technology, because people use systems more fully when they trust them. VIVISION’s view: build the identity check into each AI rollout from day one, so security becomes the reason you can scale, not the reason you stop.

Is there a skills shortage we should worry about?

McKinsey’s talent data for this trend shows a relatively strong supply of people with cybersecurity skills, and the sharpest gaps in AI and in continuous integration and delivery. Job postings rose 6 percent from 2024 to 2025, the first yearly increase since the postpandemic pullback. VIVISION’s view: for most growing firms the gap is not a security expert, it is someone who owns access decisions.

How mature is this market?

McKinsey rates adoption at 4, “scaling in progress”, and reports $77.5 billion of equity investment in 2025 and roughly $63.0 billion by mid-2026, still below the 2022 level. The tools exist. The work is in setting them up well for your business.

WHAT WE DO FOR CLIENTS FACING THIS

VIVISION runs an identity and AI access review. We build the full list of accounts that can act in your systems, human and non-human, give each one an owner, cut access down to what each job needs, and set up a simple log so you can answer “who allowed this?” for every automated action.

If you are about to roll out AI agents, we design the access rules first, so the rollout does not add a hundred new doors nobody is watching.

Scored under 10 on the identity check?

Send us your score. We will tell you the first three fixes worth making.

Talk to VIVISION

Source: McKinsey & Company, “Technology Trends Outlook 2026” (Sixth edition, September 2026), Cybersecurity and trustworthy systems chapter. All statistics are McKinsey’s, including third-party sources the report cites (among them Palo Alto Networks, Zero Day Clock, IBM and XBOW). Charts were redrawn by VIVISION from the published figures. The “VIVISION insight” sections, the identity check and its scoring, the Monday checklist, the quick-answer opinions and “what we do for clients” are VIVISION’s own views and are not McKinsey’s.

Copyright in the original report belongs to McKinsey & Company. Cover photo: chris panas on Unsplash.