McKinsey says bots and AI agents now outnumber people in company systems about 100 to one. Here is a six-question check to control who and what can act in yours.
Ask a business owner who has access to their systems and they will usually count people: staff, a bookkeeper, maybe an IT contractor. That count is now badly out of date. Every automation, integration, bot and AI agent that logs in and acts on its own is also a user, and most businesses have far more of those than they think.
McKinsey’s Technology Trends Outlook 2026 describes a security landscape that AI has changed on both sides. Attackers use it to find and exploit weaknesses faster than ever, and companies are deploying AI agents that need access to do their jobs. The report’s message is that security is no longer only about keeping outsiders out. It is about knowing, at every moment, who or what is acting inside your systems and whether it should be. This article turns that into a simple identity check any growing business can run.
All figures: McKinsey & Company, Technology Trends Outlook 2026, Cybersecurity and trustworthy systems chapter, including third-party sources the report cites (Palo Alto Networks, Zero Day Clock and IBM’s 2026 X-Force Threat Intelligence Index).
- AI has collapsed the gap between a weakness being found and being exploited, according to McKinsey. Waiting for the next patch is no longer a plan.
- Machines now vastly outnumber people as users of company systems, and every AI agent you deploy adds another.
- The report says leading security teams are moving from guarding the perimeter to checking every user, device and agent continuously.
- VIVISION’s view: for a growing business, the highest-return first step is an identity check. Know every account that can act in your systems, human or not, and give each one an owner and a limit.

McKinsey reports that in many organizations, software identities such as bots or agents that can access systems and act automatically now outnumber human users by roughly 100 to one. The report adds that security teams can no longer treat identity as a human-only issue, and that companies are replacing fixed role-based permissions with unified identity governance, password-free sign-in and access rules that take context into account.
You no longer get weeks to patch
For years, businesses had a buffer. McKinsey notes that organizations historically had weeks or months between a software weakness being identified and attackers actively exploiting it. That buffer has shrunk dramatically, the report says, because AI helps attackers find weaknesses, build exploits and launch attacks much faster.
A flaw is found, a patch comes out, and you have weeks or months to install it.
Security means a strong wall around the network. Whoever is inside is trusted.
By the time most flaws are made public, an exploit already exists.
Nothing is trusted by default. Every user, device and agent is checked continuously, even inside the network. McKinsey calls this principle zero trust.

The report also cites IBM’s 2026 X-Force Threat Intelligence Index: exploitation of public-facing applications, such as websites, customer portals and online booking systems, rose 44 percent in a single year, which McKinsey says directly fueled a 49 percent rise in the number of active ransomware and extortion groups.

When an agent acts, can you say who allowed it?
As companies deploy AI agents and automated workflows, McKinsey says spotting unusual activity is no longer enough. Those workflows need to be auditable, which the report frames as three questions every business should be able to answer:
The report also notes a real test in which an autonomous AI agent chained dozens of separate steps to turn one low-severity flaw into full unauthorized access to files. Scanners that look at one weakness at a time are not built to catch that kind of path. The practical lesson: a small gap plus a powerful account is how minor issues become major incidents.
“Trust belongs in the value case, not just the risk register.”
Roger Roberts, partner, McKinsey, in Technology Trends Outlook 2026.
Score your business in six questions
This is VIVISION’s self-assessment, built on the identity and zero-trust shift McKinsey describes. Give yourself 2 points for “yes”, 1 for “partly” and 0 for “no” or “not sure”.
| # | Question | Why it matters |
|---|---|---|
| 1 | Do you have one list of every account that can log in to your systems, including bots, integrations and AI tools? | You cannot protect accounts you do not know exist. |
| 2 | Does every non-human account have a named person who owns it? | Ownerless accounts are rarely reviewed or switched off. |
| 3 | Does each account have only the access its job needs? | Limits how far one small gap can spread. |
| 4 | Is multi-factor or password-free sign-in on for every human account? | A password alone is the weakest lock on the door. |
| 5 | Can you see a log of what your AI tools and automations actually did last week? | This is the auditability McKinsey says agentic workflows now need. |
| 6 | When someone leaves or a tool is dropped, is its access removed within a day? | Old keys that still work are an open door. |
Two things to note, not panic about
McKinsey says the risk of “harvest now, decrypt later”, where attackers store encrypted data today to crack with future quantum computers, has become an active planning priority. It matters most for firms that hold long-lived sensitive data, such as health, financial or legal records. VIVISION’s view: if that is you, ask your key vendors about their quantum-safe plans this year.
The report describes a market consolidating around platforms that bundle identity, cloud security and automated threat detection, and flags the risk of depending on a few dominant vendors. VIVISION’s view: fewer tools is usually better for a small team, but know how you would leave before you sign.
Quick answers
We use cloud software for everything. Isn’t security the vendor’s job?
Partly. Vendors secure their platform, but you decide who and what gets access to your account and what each can do. That is exactly the identity layer McKinsey says has become central. VIVISION’s view: it is the part most small businesses leave unmanaged.
Should we slow down our AI rollout until security catches up?
Not necessarily. McKinsey frames trust as something that increases the value of technology, because people use systems more fully when they trust them. VIVISION’s view: build the identity check into each AI rollout from day one, so security becomes the reason you can scale, not the reason you stop.
Is there a skills shortage we should worry about?
McKinsey’s talent data for this trend shows a relatively strong supply of people with cybersecurity skills, and the sharpest gaps in AI and in continuous integration and delivery. Job postings rose 6 percent from 2024 to 2025, the first yearly increase since the postpandemic pullback. VIVISION’s view: for most growing firms the gap is not a security expert, it is someone who owns access decisions.
How mature is this market?
McKinsey rates adoption at 4, “scaling in progress”, and reports $77.5 billion of equity investment in 2025 and roughly $63.0 billion by mid-2026, still below the 2022 level. The tools exist. The work is in setting them up well for your business.
VIVISION runs an identity and AI access review. We build the full list of accounts that can act in your systems, human and non-human, give each one an owner, cut access down to what each job needs, and set up a simple log so you can answer “who allowed this?” for every automated action.
If you are about to roll out AI agents, we design the access rules first, so the rollout does not add a hundred new doors nobody is watching.
Scored under 10 on the identity check?
Send us your score. We will tell you the first three fixes worth making.
Source: McKinsey & Company, “Technology Trends Outlook 2026” (Sixth edition, September 2026), Cybersecurity and trustworthy systems chapter. All statistics are McKinsey’s, including third-party sources the report cites (among them Palo Alto Networks, Zero Day Clock, IBM and XBOW). Charts were redrawn by VIVISION from the published figures. The “VIVISION insight” sections, the identity check and its scoring, the Monday checklist, the quick-answer opinions and “what we do for clients” are VIVISION’s own views and are not McKinsey’s.
Copyright in the original report belongs to McKinsey & Company. Cover photo: chris panas on Unsplash.