The machine identity problem just got a $1 billion price tag attached to it.
The Summary
- Palo Alto Networks and NTT DATA announced a $1B joint sales target through 2029 to secure AI agent deployments across enterprises
- Palo Alto estimates enterprises now run 80+ machine accounts for every human employee, and most security teams can't even inventory them
- The partnership pairs Palo Alto's security platforms with NTT DATA's managed services to solve the credential sprawl problem agents create
The Signal
Every AI agent you deploy is a potential security hole. Not because the model is malicious, but because it needs keys to the kingdom just to do its job. An agent processing insurance claims needs database access. A customer service bot needs CRM credentials. A code review agent needs repository permissions. Multiply that across hundreds or thousands of agents, and you have a credential management nightmare that makes the human IAM problem look quaint.
Palo Alto Networks pegged the ratio at 80 machine identities per human employee in February. That was before this year's agent deployment surge. Most enterprises cannot produce a complete inventory of these accounts, which means they cannot answer basic questions like "what systems can our agents access" or "which credentials would an attacker inherit if they compromised an agent."
"Most security teams cannot produce a full list of machine accounts, so they cannot say who or what has access to their most sensitive systems."
The $1 billion figure is a combined sales target, not committed revenue. Split across three years and two companies, it signals market sizing more than deal flow. But the number itself matters less than what it represents: two major enterprise infrastructure players betting that agent security becomes a mandatory line item as companies scale from pilot AI projects to production deployments.
NTT DATA brings 190,000 consultants and existing enterprise relationships. Palo Alto brings the security stack. The joint offering bundles risk assessment, secure deployment frameworks, and ongoing credential management into a managed service package. The target customers are banks, hospitals, and other regulated industries where an agent with excessive permissions could trigger compliance violations or worse.
Key dynamics in play:
- Agent credential sprawl growing faster than security tooling to manage it
- Regulated industries facing auditor questions about AI access controls they don't have answers for
- Security budgets shifting from preventing human breaches to managing machine identity at scale
This alliance extends Palo Alto's April Frontier AI Alliance, which already included NTT DATA plus four other partners. The new agreement adds financial targets and deepens the services integration. Neither company would specify current joint revenue or detail the "joint investments" mentioned in the announcement, citing Palo Alto's September earnings blackout.
The Implication
If you are deploying agents in production, audit what they can access today. Not tomorrow. Most security teams are managing agent credentials the same way they handled service accounts in 2015: poorly, manually, and with no systematic review process. The companies that figure out machine identity management this year will have a structural advantage. The ones that don't will be explaining breaches to regulators.
Watch for similar managed security partnerships targeting the agent deployment wave. The $1 billion target is a signal that agent security is becoming its own services category, not just a feature add-on.