Malaysia’s AI Rollout Is Outpacing Identity Security, ManageEngine Warns
- Olivia Johnson

- 40 minutes ago
- 13 min read
ManageEngine has issued a stark warning through a Google News report: Malaysia is deploying AI agents faster than enterprises can secure their digital identities.
The concern is not simply that companies are adopting unfamiliar software. Every agent, automated workflow, and machine integration needs credentials that grant access to data and business systems. Those credentials can remain active long after a project ends.
Malaysia has already built national frameworks around cybersecurity, privacy, and responsible AI. The conflict now sits between that policy progress and everyday enterprise access management. Organizations can follow high-level governance principles while still giving an AI agent permanent administrative privileges.
That gap makes this more than another story about AI adoption. It raises a practical question for every Malaysian enterprise: who, or what, is currently authorized to act inside its network?
What ManageEngine’s Warning Actually Changes
The warning shifts enterprise AI governance from a model-risk discussion to an identity-control problem.
The original identity security report was published by Tech Wire Asia on August 3, 2026. It focused on a weakness that is easy to miss during rapid AI deployment.
An AI agent does not enter a company network as an abstract algorithm. It normally receives a service account, token, certificate, API key, or another machine credential. That identity determines which applications, records, and actions the agent can reach.
ManageEngine’s Jay Reddy told the publication that developers often treat autonomous agents like conventional application integrations. Teams may assign standing administrative permissions or broadly privileged service accounts to avoid integration delays.
That shortcut can keep a pilot moving. It also creates persistent access that does not reflect the agent’s changing task, risk level, or operating context.
An autonomous agent differs from a static integration because it can plan steps, call several tools, and respond to changing inputs. A credential designed for one predictable connection can become dangerous when attached to software that takes varied actions.
ManageEngine identity security research places this problem within a much larger change. Non-human identities include service accounts, certificates, bots, workloads, application secrets, and AI agents. They are becoming the dominant identity category in many enterprise environments.
ManageEngine says machine identities commonly exceed human users by more than 100 to one in surveyed organizations. Some sectors are approaching a ratio of 500 to one.
These figures come from ManageEngine’s survey rather than a Malaysia-only census. They should not be interpreted as a measured ratio across every Malaysian company.
The broader finding remains important. An enterprise with several thousand employees can still have hundreds of thousands of machine credentials spread across cloud services, internal applications, and automation platforms.
ManageEngine also found that only 12% of surveyed organizations had comprehensive, automated lifecycle management for machine identities. The remaining 88% relied on manual or improvised processes that struggle at machine scale.
Lifecycle management covers the creation, modification, monitoring, and retirement of an identity. It should remove access when an application is decommissioned, an agent changes roles, or a credential is no longer needed.
Without that process, an abandoned pilot can leave behind an orphaned account. The application may disappear from the project dashboard while its access token remains valid.
The problem extends beyond forgotten credentials. An active AI agent can inherit more access than its task requires, especially when deployment teams prioritize speed.
Least privilege means granting only the access required for a defined function. It becomes harder when an agent must complete several steps across email, document storage, customer records, and internal databases.
A Google News headline about “identity security” can therefore sound narrower than the underlying issue. The warning touches procurement, software development, data governance, cloud architecture, and incident response.
The immediate change is conceptual. Enterprises must stop treating AI agents only as products to approve and start treating them as identities to govern.
Why Google News Is Surfacing the Risk Now
Malaysia’s national AI ambitions are moving into an operational phase, while many identity programs still reflect a human-centered security model.
Malaysia is not approaching AI without a policy framework. The country released its National Guidelines on AI Governance and Ethics on September 20, 2024.
The guidelines establish seven principles covering fairness, reliability, privacy, security, transparency, accountability, inclusion, and human benefit. They apply across the lifecycle of AI systems.
Malaysia’s National AI Office describes those guidelines as voluntary. Its newer AI governance resources are intended to help organizations translate principles into working practices.
The government is also developing the National AI Action Plan 2026–2030 under its AI Nation 2030 direction. The plan is expected to address adoption, infrastructure, talent, governance, and industry participation.
This creates momentum for both public and private organizations. Boards want useful deployments, departments want productivity gains, and technical teams face pressure to move pilots into production.
Yet policy-level AI governance and operational identity governance solve different parts of the problem.
An ethics framework can require accountability, privacy, and safety. It does not automatically discover an undocumented API key or revoke an agent’s access after a pilot ends.
Malaysia’s National AI Office acknowledges this distinction indirectly. Its guidance covers deployment, monitoring, and decommissioning, not only model development.
That lifecycle view is essential. An agent can meet an organization’s initial approval criteria and later become risky because its permissions, connected tools, or operating instructions change.
Malaysia also has binding cybersecurity rules in specific areas. The Cyber Security Act was gazetted on June 26, 2024, and entered into operation on August 26, 2024.
The law establishes duties around National Critical Information Infrastructure, known as NCII. It also addresses cyber incidents, sector responsibilities, and licensing for certain cybersecurity service providers.
The Act strengthens Malaysia’s national cybersecurity structure. However, it does not eliminate the need for each enterprise to maintain accurate internal inventories and access controls.
Privacy obligations are tightening as well. Malaysia’s PDPA amendments introduced changes that include breach notification and data-protection responsibilities.
Those rules increase the consequences of weak credential governance. An agent with excessive access can turn one compromised token into exposure across several data systems.
The resulting pressure falls first on chief information security officers, identity teams, cloud administrators, and application owners. They must support faster deployment without losing visibility.
It also reaches boards. Senior leaders cannot oversee AI risk if the organization cannot list its agents, their owners, their credentials, and their permitted actions.
Malaysia’s current policy direction encourages responsible adoption, but much of its dedicated AI guidance remains non-binding. Enterprises still carry the responsibility for translating broad principles into technical controls.
That is why the story is appearing now. AI adoption has advanced beyond isolated demonstrations, while the security architecture underneath many deployments has not advanced at the same pace.
ManageEngine AI governance commentary frames AI as both a source of identity growth and a potential aid for security teams. That dual role complicates the response.
Organizations want AI to detect risky behavior, review access, and reduce manual work. At the same time, every defensive AI component can introduce more credentials and integrations that require governance.
This cycle can produce security tooling that expands the very identity estate it is supposed to control. Consolidation and automation become necessary, but they also require careful implementation.
The real pressure is therefore not to slow every AI project. It is to make identity controls operate at the speed and scale of those projects.
AI Agents Versus Human-Centered Identity Security
Malaysia’s core enterprise conflict is AI deployment speed versus an identity architecture built around employees and predictable applications.
Traditional identity and access management starts with recognizable human events. A person joins a company, changes roles, requests access, and eventually leaves.
Those events can trigger workflows involving human resources, managers, and IT administrators. Ownership is usually visible, even when execution is imperfect.
Machine identities do not follow that pattern. A developer can create multiple service accounts during one project, while cloud platforms generate credentials through automated infrastructure processes.
AI agents add another layer. One agent may receive access to a language model, internal documents, a ticketing system, customer records, and communication tools.
Its role can also change without a formal transfer. New instructions or integrations can expand its effective authority even when its original account stays unchanged.
This is why a simple list of user accounts is no longer enough. Security teams need to understand relationships between agents, credentials, tools, data, owners, and actual behavior.
ManageEngine’s Identity Security Outlook 2026 found a significant perception gap. According to its survey findings, 80% of senior leaders believed dormant machine accounts were being tracked.
Barely half of practitioners confirmed that confidence. The difference suggests executives can believe a control exists even when frontline teams see incomplete coverage.
The same study found that nine in ten surveyed organizations were piloting or using AI in identity and access management. Only 7% reported organization-wide deployment.
That gap matters because limited pilots do not prove that AI-assisted security works across legacy directories, cloud platforms, and thousands of machine accounts.
Executive expectations also exceeded operational confidence. ManageEngine reported that 68% of C-suite respondents were optimistic about AI for identity-risk modeling and analytics.
Only 27% of managers considered that use practical. The survey does not prove either group correct, but it exposes a deployment problem that budget approval alone cannot solve.
ManageEngine identity security research also points toward platform consolidation. More than 80% of surveyed security leaders were consolidating fragmented identity tools into unified platforms.
Consolidation can reduce blind spots when separate systems manage workforce access, privileged accounts, cloud entitlements, certificates, and application secrets. It can also provide a shared policy layer.
However, buying a unified platform does not automatically create an accurate identity inventory. Organizations still need to identify owners, define acceptable behavior, and connect every relevant environment.
This is the main opponent in the story: fast AI deployment versus human-centered identity operations.
The conflict is not ManageEngine versus another vendor. Microsoft, CyberArk, Okta, SailPoint, and cloud providers all address parts of the expanding identity problem through different products.
Their approaches vary, but the industry direction is similar. Identity programs are extending from employee authentication toward workload access, machine credentials, and continuous authorization.
Continuous authorization means access decisions can be reassessed as context changes. A system might consider the requested action, data sensitivity, credential behavior, and current risk.
That is more suitable for autonomous software than a permanent permission assigned once. An agent processing invoices at noon does not necessarily need the same access while idle at midnight.
Short-lived credentials offer another response. They expire quickly and can limit the value of a stolen secret.
Just-in-time access grants higher privileges only when a specific task requires them. It reduces the standing access available to attackers or malfunctioning agents.
These controls are not new. The challenge is applying them consistently to rapidly created AI workflows without turning security review into an unusable bottleneck.
A real-world enterprise agent may summarize internal documents, draft an answer, and update a customer system. Each action can cross a different security boundary.
If the agent receives one broad service account, investigators may struggle to determine which action came from the agent, a developer, or another application sharing that identity.
Dedicated identities and detailed logs improve attribution. They also increase the total number of identities that teams must manage.
This tradeoff explains why manual identity processes collapse at scale. Better accountability creates more objects to track, while fewer shared accounts can mean many more individual credentials.
Enterprises need automation, but automation must follow verified policy. Otherwise, it can reproduce excessive permissions faster than a human administrator ever could.
What the ManageEngine AI Governance Claim Does Not Prove
The warning identifies a credible structural risk, but it does not establish that Malaysian enterprises share one uniform security failure.
The most eye-catching figure is the possible 500-to-one ratio between non-human and human identities. Readers should handle it carefully.
ManageEngine says some surveyed sectors approach that ratio. The company does not claim that every Malaysian organization has measured the same level.
The Tech Wire Asia article applies global identity findings to Malaysia’s adoption context. It adds an informed regional interview, but it is not a nationwide audit of Malaysian credentials.
This distinction matters because industries have very different technology estates. A cloud provider, bank, manufacturer, hospital, and small retailer will not create machine identities at the same rate.
Definitions can also change the count. Some studies include certificates, keys, workloads, bots, service accounts, and application identities as separate objects.
Others focus on accounts that can authenticate directly. Comparing ratios without matching definitions can exaggerate apparent differences.
ManageEngine also sells identity and security products. Its research can still offer useful evidence, but its commercial position should remain visible.
The strongest conclusions come from findings that align with observable architecture. AI agents need credentials, permanent privileges increase exposure, and abandoned accounts create risk.
The weaker conclusion would be that a particular ratio describes Malaysia as a whole. Available evidence does not support that claim.
ManageEngine AI governance recommendations also favor consolidation. A unified platform can reduce fragmentation, yet centralization introduces its own concentration risk.
If one identity control plane is misconfigured or compromised, the impact can spread widely. Organizations need resilience, separation of duties, and independent logging around centralized systems.
AI-assisted identity analytics presents another uncertainty. An algorithm can flag unusual access patterns, but it can also produce false positives or miss behavior that resembles legitimate automation.
Security teams must understand which decisions are advisory and which trigger automatic enforcement. Blocking a critical agent based on a weak signal can interrupt operations.
Conversely, allowing an AI system to approve access without human review can recreate the same over-privileging problem under a new label.
There is also a governance boundary between an AI agent and the model supporting it. The agent’s tools and credentials determine what it can do, while the model influences how it chooses actions.
A company might perform model testing but neglect credential scope. Another might restrict permissions while failing to monitor unsafe instructions or manipulated inputs.
Prompt injection illustrates that overlap. It occurs when malicious content attempts to redirect an AI system’s behavior through instructions hidden in data it processes.
An agent with read-only access may expose information after prompt injection. An over-privileged agent may also change records, send messages, or invoke administrative tools.
Identity governance cannot prevent every prompt attack. It can limit the damage by narrowing what the compromised agent is authorized to do.
This makes least privilege a containment measure, not proof of complete AI safety. Model evaluation, data controls, monitoring, and incident response remain necessary.
Malaysia’s voluntary AI guidance has similar limits. It gives boards and teams a common vocabulary, but organizations must convert that vocabulary into enforceable technical policy.
The country’s cybersecurity and privacy laws create firmer obligations in their respective scopes. Yet compliance after a breach is not a substitute for preventing unnecessary access.
Enterprises should also resist a false choice between rapid adoption and strict control. A lengthy manual approval for every agent can push employees toward unsanctioned tools.
Shadow AI refers to AI services used without formal organizational approval. It can move data beyond approved systems and create identities security teams never see.
A workable program must make safe deployment easier to discover and use. Standard credential patterns, approved connectors, automated expiration, and clear ownership can reduce friction.
This is where knowledge practices also matter. Teams need accessible records of who approved an agent, which systems it can reach, and why those permissions remain necessary.
A searchable technical knowledge base can support reviews, although documentation alone cannot enforce access policy.
The skeptical reading does not invalidate ManageEngine’s warning. It narrows the claim to what the evidence supports.
Malaysia has a plausible and growing machine-identity risk. The available sources do not establish one nationwide exposure rate or prove that platform consolidation alone will solve it.
The Three Signals to Watch After This Google News Report
The next stage will be measured through identity inventories, enforceable access lifecycles, and evidence that boards can see the same risks as practitioners.
The first signal is whether Malaysian organizations begin reporting complete inventories of AI agents and non-human identities.
An inventory should connect each identity to an owner, business purpose, environment, credential type, accessible data, and expiration policy. Counting accounts without those relationships offers limited protection.
This signal would strengthen ManageEngine’s warning if companies discover large numbers of orphaned or shared credentials during reviews. It would weaken the most severe interpretation if inventories show tight ownership and limited privileges.
The process should include agents created by central technology teams and those assembled within individual departments. Low-code tools can let business users deploy automation without traditional software-release controls.
Boards do not need a list of every token. They need reliable measures showing how many agent identities exist, how many lack owners, and how many retain standing privileges.
The second signal is the adoption of automated, enforceable identity lifecycles for AI agents.
Organizations should be able to issue short-lived credentials, restrict tools, review behavior, and revoke access when a workflow changes. Decommissioning must remove associated secrets and service accounts.
The key word is enforceable. A policy document that says agents should use least privilege does not prevent an administrator from issuing a permanent, broadly scoped token.
Evidence of automated expiration and just-in-time privilege would strengthen the case that security architecture is catching up. Continued dependence on manual spreadsheets would support ManageEngine’s concern.
This signal also tests vendor claims. Identity platforms should demonstrate coverage across cloud services, internal directories, certificates, application secrets, and agent frameworks.
A dashboard showing only workforce users will not answer the machine-identity problem. Neither will an AI assistant that recommends changes but cannot safely implement or verify them.
Enterprises should measure both prevention and recovery. They need to know how quickly they can disable one agent, rotate related credentials, and reconstruct its recent actions.
The third signal is whether Malaysia turns national AI principles into more specific accountability requirements.
The National AI Office says Malaysia does not yet have a dedicated AI law. It also notes that an AI Governance Bill is being explored.
Future policy could clarify responsibilities for AI deployers, risk assessment, documentation, security testing, and ongoing monitoring. Sector regulators may also issue requirements before a general law arrives.
New rules would strengthen the article’s central judgment if they explicitly address agent identity, access, and decommissioning. General ethical language without operational requirements would leave the enterprise gap largely unchanged.
Regulatory development should not be measured only by whether Parliament passes a single AI statute. Privacy enforcement, NCII obligations, procurement rules, and sector guidance can all shape identity practice.
Financial services and critical infrastructure operators are likely to face the closest scrutiny. Their agents can interact with sensitive records and operational systems where excessive permissions carry higher consequences.
The boardroom response deserves equal attention. Malaysia’s National AI Office has published voluntary guidance intended to help directors oversee AI adoption.
Boards should ask whether the organization can stop an agent immediately, not only whether it approved the original business case. They should also ask who reviews access after the agent’s function changes.
Those questions connect high-level accountability with technical evidence. They also expose the gap between executive confidence and practitioner visibility found in ManageEngine’s survey.
For developers, the lesson is direct. Credentials are part of an agent’s architecture, not a deployment detail to revisit after launch.
For enterprise buyers, identity coverage should be evaluated alongside model accuracy and workflow features. A useful agent with untraceable authority creates an operational liability.
For knowledge workers, the issue affects which documents and systems an assistant can reach. Convenience grows when tools connect broadly, but so does the impact of a mistaken or manipulated action.
The Google News framing will fade as another headline replaces it. The underlying identity problem will persist because every new automated action creates an authorization decision.
Malaysia has already established a policy direction built around responsible AI, cybersecurity, and privacy. Its next test is whether organizations can make those principles visible in credentials, logs, and revocation controls.
ManageEngine’s warning should therefore be judged by operational evidence over the coming months. Are enterprises finding abandoned agent accounts? Are they replacing standing privileges? Can they prove who owns each machine identity?
Those answers will show whether Malaysia’s security architecture is catching up with its AI ambitions.
Before approving the next agent deployment, ask one concrete question: if this system behaves unexpectedly tonight, can your organization identify its credentials and remove every permission before morning?


