Skip to main content Announcement: Now accepting design beta partners · Read more

The Blog · August 5, 2026

Entering the Agentic Era

Agent growth, enterprise adoption, and exploits by non-human-identity agents, 2025 to 2030. Each series is drawn against its own 2030 endpoint.
Agent growth, enterprise adoption, and exploits by non-human-identity agents, 2025 to 2030. Each series is drawn against its own 2030 endpoint.

Demis Hassabis, 2024 Nobel Laureate in Chemistry and CEO of Google DeepMind, said it in three words: we are "just getting going." The numbers agree with him.

The number to hold onto

IDC counts roughly 28.6 million AI agents in production in 2025. By 2030, their projection is 2.2 billion. That is 77x growth, a 138% compound annual rate, sustained for five years. Nothing else in enterprise infrastructure is compounding at that pace.

For scale: 2.2 billion agents is hundreds of agents for every large enterprise on earth, each one opening network connections on its own, calling model providers, calling tools, and calling other agents. No human clicks first.

Three curves, one story

The chart above puts three trend lines on one axis, each normalized to its own 2030 endpoint, each anchored to published research.

Agent growth (IDC, 2026). The green line looks flat until 2028 and then goes vertical. That is what 138% CAGR feels like from the inside: two quiet years, then a wall. 28.6M in 2025, 68M in 2026, 162M in 2027, 386M in 2028, 919M in 2029, 2.2B in 2030.

Enterprise adoption (Gartner, 2025). Under 5% of enterprises ran agents in production in 2025. Gartner expects 40% in 2026, and the curve points toward roughly 90% by 2030. Adoption is not waiting for the security story to mature.

Exploits by NHI agents (CSA, 2025; Sophos, 2026). The share of incidents involving non-human identities was about 20% in 2025 and 41% in 2026, tracking toward roughly 80% of exploits by 2030. Attackers have noticed that agents hold credentials, act at machine speed, and rarely have an owner watching.

The uncomfortable part is how closely the red line tracks the blue one. Attacks are not lagging adoption. They are riding it.

The gap nobody declared

The Cloud Security Alliance found that 82% of enterprises have unknown AI agents running in their infrastructure. Machine identities already outnumber humans roughly 80 to 1, and most organizations have no identity controls for them at all.

That is the agentic era's real opening condition: not 2.2 billion well-governed agents, but 2.2 billion agents arriving faster than anyone can inventory them, on networks that reason about IP addresses and flows, not agents.

AI applications are a network of agents, not IP addresses. The controls that protected the last era read packets and still cannot tell you which agent sent them.

What we are building for it

Maya is the network layer for the agent era: per-agent identity derived from the wire, payload-blind, inside your VPC, with zero agent code change. Every agent named, every A2A conversation attributed, every deviation detected, and enforcement in under a second when an agent does something it never declared.

The era is just getting going. The time to learn who your agents are is before the green line goes vertical.

Start a conversation if you want to see your own fleet the way Maya sees it.

Newsletter

Get the white papers, free.

Subscribe and we'll send you our white papers on agentic network security, plus every new article as it publishes. No noise, unsubscribe anytime.

All posts