Last updated on September 21st, 2026 at 08:13 am
In the recent past, identity security meant a strong employee password and IT’s ability to deprovision an account once the person left the firm. Clean, simple, human-shaped. The model has now failed – and the failure has occurred more quickly than some security teams would have reacted to.
AI agents changed the rules. They are no longer chatbots sitting idle behind a prompt window. In modern agentic systems, everything happens asynchronously: they invoke APIs, query databases, initiate cloud executions, spin up sub-agents, and complete a series of steps without a human in the loop at each point. A credential is required in every one of those acts. All the credentials are non-human identities (NHI).
The statistics tell a story that should not be comfortable for any security architect. Machine identities already exceed human identities by 45:1 to more than 100:1 in an enterprise environment – and in practice most organizations maintain less than half of them. With complex cloud deployments, SailPoint says the ratio is about 82:1. Meanwhile, one of the most frequently quoted statements from the NHI security community indicates that over 99 percent of agent and NHI credentials are currently uncontrolled.
The thesis on this is quite simple: to ensure the non-human identities that your AI agents will be based on, there will be no way to secure your AI agents. Full stop. The rest of this paper explains why, what the risk environment will look like in 2026, and what qualifies as a realistic answer.
Table of Contents
What Are Non-Human Identities in the Age of AI Agents?
We’ll start by clarifying what an NHI is before going further, as the term covers more than what people expect. A non-human identity is any computer-generated identity assigned to a system, service, or automated process instead of a human being. In practice, that includes:
- Rules that authenticate via third-party services: The applications are authenticated using API keys and OAuth tokens.
- Cloud accounts (AWS IAM roles, Azure Managed Identities, GCP service accounts).
- Workloads and encryption keys of workloads and containers.
- Bot accounts that perform within SaaS apps such as Slack, Salesforce, or Jira.
- IoT identities between sensors and edge elements with the central infrastructure.
- Pipeline credentials in CI/CD systems such as GitHub Actions or Jenkins.
- Identity of AI agents – the most recent and the quickest-growing type.
Now, the density and autonomy of NHI usage distinguish agentic AI from previous automation. It may take 10 or more individual NHIs for an AI agent, tasked with a moderately challenging task, to complete a full session: one to authenticate against a knowledge base, another to write to a CRM, another to invoke a notification service, another to call a financial API. Every connection creates a potential attack surface. Without security, each long-lived, over-privileged, or unmonitored credential is an open door.
I saw this firsthand when I reviewed a medium-sized SaaS setup that had adopted an agent-based customer support process. The agent was configured to use one service account with read and write access to all customer databases, since it seemed like a burden to create provisioned scopes credentials for every tool call at the time. It is the type of shortcut that works out well until something goes wrong.
Why NHIs Became the New Perimeter – And Why Legacy IAM Is Failing
Conventional identity and access control followed a basic cadence: someone logs into the system, works, and logs out. Visibility is associated with a role. Access is time-based, tied to a working day. Conduct is more or less foreseeable.
AI agents don’t beat to that rhythm. They are not only self-executing, but scale-to-order because they generate sub-agents as needed, recycle credentials, and then run like a machine, with no human supervision at each step. The assumptions built into legacy IAM systems don’t hold.
Identity as the Control Plane for AI Risk
Industry scholars and security researchers increasingly characterize NHI governance as the identity layer as the key control plane for AI risk. The framing is accurate. If an AI agent user is compromised, misconfigured, or over-privileged, an attacker doesn’t need to exploit the model; they only need to exploit what the model can do on its behalf.
The breakdown of legacy IAM in agentic environments has a couple of particular unsuspected outcome breakages:
- Lack of agent lifecycle concept: Identities are not created and released in large numbers; IAM systems were not developed to add and remove identities at the pace and frequency at which agents are developed and disposed of.
- Role-based access in Static permissions of a dynamic world: Role-based permissions apply in situations where job requirements are fixed. Roles are dynamic as agents move around, so fixed positions don’t suit them.
- Human approval gate is too slow: High-risk processes (those needing approval) can occur in milliseconds – quicker than most human inspection.
- Embedded credentials: Developers will routinely encode API keys and service account tokens in code and other configs without going through a vault or rotation policy.
According to the 2026 agentic AI and cybersecurity report of the World Economic Forum, one of the most pressing governance failures associated with the emergence of AI agents is cryptographic blind spots, i.e., credentials and certificates that no one knows exist. My experience reviewing enterprise deployments shows that the credentials available to the credentials teams are usually reasonably controlled. The issue is the ones that no one tells about.
Risk Landscape: Over-Privileged, Invisible, and Long-Lived Machine Identities
The OWASP Agentic AI Top 10 framework and OWASP NHI Top 10, published within the past 18 months, have crystallized the essential risk patterns. The following is what is constant in those frameworks and recent research of vendors:
Over-Privileged Tokens and Service Accounts
The permissions available to the agent are often excessive because scoping permissions is time-consuming and requires a detailed understanding of what the agent does. The outcome is service accounts that have extensive administrative privileges and remain idle between tasks, a boon to anyone who succeeds in compromising them.
Secret Exposure and Credential Sprawl
API keys and tokens often end up in source code, build logs, Slack messages, and spreadsheets. An unintended credential leak in its intended vault may go undetected for months or even years. Automated scanning tools often discover exposed secrets; however, reactive detection is not a good replacement for never leaking them.
Shared Credentials Across Agents
Multi-agent teams often use a single shared service account to minimize setup overhead. If one agent is compromised, all agents with that credential will be compromised. Shared credentials also cause a forensic investigation to be practically impossible – you cannot say that this performed an action or that agent when credentials are shared.
Long-Lived Credentials With No Expiry
The fundamental principle of a zero-trust network is short-lived tokens that automatically rotate. In practice, many production deployments still use credentials with no expiry date because rotation is too complicated to implement right now.
I’ve observed this in almost every cloud environment I’ve reviewed. Investigating credentials with a long shelf life is not merely a risk, but a muffled insurance that, over time, a compromise will become large-scale.
Cascading Failures and Lateral Movement Without a Human Attacker
The most disturbing pattern in the OWASP NHI Top 10 is the rogue agent pattern: a compromised agent credential allows lateral movement within cloud and SaaS environments, and high-volume automated activity hides the intrusion in logs meant to monitor human behavior. No phishing email. No man at a keyboard assaulting. Only a cog in the machine to do just what its credentials permit – in the wrong hands.
Important stat: In a multi-cloud setup with multiple complexities, a single AI agent might use 10 or more individual NHIs across SaaS, cloud, and internal setups. Without a complete map of those identities, responding to an incident becomes nearly impossible.
Three Pillars of Securing Non-Human Identities for AI Agents
Across research, vendor advice, and framework documentation, three pillars emerge as what organizations strive for when they try to get NHI security right. These are not optional extras, but the minimum base necessary.
Pillar 1 – Visibility and Inventory: You Cannot Protect What You Cannot See
The first, and most fundamental, step is knowing which HIs you have. This may sound obvious, but most organizations are completely blind. Shadow agents and AI automations used by separate groups without central management are typical. Accounts for forgotten services used long ago by degraded integrations are kept with fully valid credentials. The expiry of certificates goes unnoticed.
Cloud environments, SaaS platforms/frameworks, CI/CD pipelines, and agent frameworks are constantly scanned, and this is now expected. Discovery tooling such as Astrix, Aembit, and SailPoint has developed NHI-specific discovery tools that rely on machine learning to expose unmanaged credentials and flag abnormal access patterns. Its approach is to maintain a living inventory that updates automatically and assigns each NHI an explicit owner.
To build this foundation, the Discovery and Inventory: Gaining Visibility into AI Agents deep-dive details the tooling, processes, and governance models that enable continuous NHI visibility in production settings.
Pillar 2 – Least Privilege and Lifecycle Management
All AI agents must run with the least necessary permissions to perform their particular task, nothing more. Credentials must be time-limited and rotate like time-based cookies; do not serve a group of agents on a single cookie.
In practice, this means designing identities around agent roles rather than team or system needs; enforcing finite expiry on identities; requiring human approval or step-up controls for high-risk operations such as bulk data access or infrastructure modification; and automating rotation in the deployment pipeline from day one, not as a retrofit.
The guide Least Privilege for AI Agents further elaborates on setting permissions correctly, creating time-bound credentials, and deploying approval gates without creating a bottleneck to legitimate agent access.
Pillar 3 – Monitoring, Governance, and Identity Threat Detection
Least privilege and inventory make the situation much safer, although not risk-free. Monitoring closes the gap. Identity Threat Detection and Response (ITDR), with extensions to include machine identities, means baselining normal agent behavior, alerting on behavioral anomalies, and maintaining detailed audit trails that tie each instance of agent activity to a particular NHI and, where feasible, a human owner.
The challenge is volume. Agents create far more activity than people, and traditional SIEM tools were not meant to analyze and put into context the volume of activity they generate. New tooling, such as AI-aided anomaly detection, is starting to meet this requirement, but humans still must carefully craft the governance layer (ownership, review cadence, escalation policies).
A framework-based model for ongoing NHI governance (including alignment to NIST CSF, ISO 27001 controls, and OWASP NHI Top 10 remediation patterns)) can be found in the Governance for Agentic Identities deep-dive.
How NHI Security Fits Into Zero-Trust and AI Governance
Zero trust as an architecture is nothing novel; however, applying it to non-human identities remains in its infancy. The main zero-trust principles are a direct correspondence to the NHI issue:
- Explicit Verification: NHI requests need to be authenticated and authorized (network location, whether in a network or not). To a functioning extent, implicit trust in IP ranges or internal network status is inadequate.
- Least privilege access: As mentioned above, scope, time-bound, and rotate. Apply this to all credentials, not just the obvious ones.
- Breach assumption: This assumes credentials will be compromised so that Design NHI governance will take place. It aims to curb the blast radius, not completely eradicate any form of compromise.
Microsoft’s guidance on managing non-human identity positions NHIs as a zero-trust issue, suggesting a focus on centralized IAM integration, temporary credentials, and ongoing monitoring rather than the out-of-band approach most organizations currently use.
Regulations Are Catching Up
Laws are becoming clearer regarding machine identity hygiene. Both US Executive Order 14028 and NSM-10 contain different requirements for cryptographic inventory and automated key management involving non-human identities. The transparency and auditability of the EU AI Act include an implicit commitment to knowing and disclosing what AI actors are doing, but only to the extent they have a discernibly identifiable identity layer beneath them.
Another regulatory control point is post-quantum cryptography (PQC). Certificates and keys will require NIST-standardised post-quantum algorithms, not just the ones used by humans. Organizations that fail to maintain a real-time cryptographic inventory will struggle to prove compliance or even migrate in time.
My Take on the IAM + PAM Stack
I have worked with older versions of PAM platforms as well as newer NHI-specific tooling, and my fair evaluation is that they meet converging requirements. Privileged human accounts and high-value service accounts still need privileged accounts. NHI-specific platforms introduce discovery, agent-specific governance, and machine-speed automation that legacy PAM was not created to facilitate.
The IAM + PAM guide utilizing Non-Human Identities discusses the options and structures of the capabilities in a consistent stack, including tool selection, architectural patterns, and the organizational model that must be enforced to support it successfully.
Where to Go Deeper – My Recommended External Reading
Two external resources are specifically noteworthy to anyone developing or reviewing NHI security programs.
The World Economic Forum article on the identity of non-humans as the new cybersecurity frontier of agentic AI is an outstanding example of high-level framing of how agentic AI is driving NHI growth, the blind cryptography spaces are forming, and policy-level responses are already emerging. It targets a general audience and does not require a sophisticated technical background.
For a more technical audience, the OWASP NHI Top 10 can serve as a community-driven framework for establishing a reference baseline of NHI risk categories. It is worth reading alongside the Governance for Agentic Identities guide, as it provides a good basis for constructing a remediation roadmap.
Trust Booster Anchor Texts (for CMS Use)
The above anchor textings are to be used when referencing the external resources when trying to create the maximum context relevance:
- In the case of WEF: non-human identities the new cybersecurity frontier of agentic AI – enters weforum.org.
- OWASP NHI Top 10: OWASP NHI Top 10 risk framework – OWASP project page.
The Roadmap: Deep Dives Into Every Layer of NHI Security
This paper has outlined the three pillars and the problem strategically. One pillar, and the knowledge it’s built on, should be given a deep dive to be truly action-oriented. The individual child articles will fall under the following program:
NHI Fundamentals and Types
To introduce yourself to the subject or brief a non-technical stakeholder, the fundamentals article will cover each type of NHI, how each type is constructed, how it authenticates, and the governance required. It is the place where one enters before anything else.
Discovery and Inventory: Gaining Visibility into AI Agents
The major gap is continuous discovery, in which most programs have failed. The guide also covers tooling alternatives, scanning strategies in the cloud and SaaS systems, candidates for such shadow agents, and how to build an inventory that stays updated. The article Discovery and Inventory: Gaining Visibility into AI Agents is the logical next step after this piece.
Least Privilege for AI Agents
Permission for an agent is more difficult to acquire than permission for a human since the boundaries of the tasks of an agent are less predictable. The Least Privilege for AI Agents guide covers design patterns, such as just-in-time access, time-constrained credentials, and human-in-the-loop approval gates for high-risk operations.
IAM + PAM for Non-Human Identities
The IAM + PAM for Non-Human Identities guide covers the technology stack: which platforms support NHI discovery, governance, and vaulting; how legacy PAM compares with new NHI-specific tooling; and what an integrated architecture means in a mid- to large-size enterprise.
Governance for Agentic Identities
The intersection of the human and technical layers is in governance—analysis: Individual Governance program. The Governance for Agentic Identities article covers ownership models, review cadences, alignment of NIST, ISO, and OWASP NHI remediation mapping, and how to build a governance program for the agent estate.
The basis is centralized secrets storage in a specific vault (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or another equivalent). In it, the main practices are:
What Good Secrets Hygiene Looks Like
In my experience, the gap between secrets management policy and secrets management reality in an organization is often large. Policies dictate that all the secrets should be kept in a vault. In reality, secrets show up as environment variables, .env files stored in private repositories that weren’t as secure as they should be, and Slack messages that seemed easier than setting up a vault back then.
NHI security work exists in a category that can hardly get a featured spot on conference agendas, but it has a disproportionately large number of real-world incidents: secrets management. The term practitioner encompasses everything from storing keys, to rotating certificates, and the possibility of your build pipeline retusilently rning tokens to the dard output in ecrets Management and Cryptographic Hygiene: The Unglamorous Work That Actually Matters.
Automatic searching of the code repositories, build artifacts, and container images for accidentally exposed secrets.
- No secret sharing among agents; each is granted its own scope credential.
- Each secret access event is logged in the audit logs with reference to the individual NHI, or agent, that transmitted a request.
- Expiry enforcement: non-renewed credentials are not flagged; they are also revoked.
- Rotated automatically on a schedule or due to some event, as opposed to being manually rotated when somebody remembers.
- Even though migration may be two or three years away, organizations that use AI agents by 2026 need to be recording the cryptography posture of their NHI estate. The agents currently being provisioned will very likely still be operational when a mandate to start migrating to PQC arrives.
In 2024, NIST finalized its post-quantum cryptography standards. Migration is a long process, but planning to migrate machine identity credentials is even more protracted than many best teams expect, since it requires knowing which cryptographic algorithms all certificates and keys in the environment currently use. Even an audit without live inventory can take months.
Post-Quantum Cryptography: A Longer-Horizon but Urgent Preparation
Automated key rotation would be easy. Practically, this demands that all systems that consume a secret can support a change of credentials without any downtime, i.e., not necessarily tested in production, but in advance.
What the 2026 NHI Challenge Means in Practice
The problem of machine identity crisis is not in the future. The proliferation of AI agents has already occurred, and the credentials of the AI agents are already traversing cloud environments, SaaS applications, and internal systems, mostly without the oversight, control, and cleanliness that human identity programs assume.
My review of these environments has revealed a pattern: the groups ahead of the problem are not necessarily using the most advanced tooling. They have viewed NHI governance as a first-grade security issue since the beginning of their AI agent deployments, not as a retrofit. They did discovery before going live. They used agent-role-scoped credentials. They built rotation into the pipeline.
The three-pillar model, which includes visibility of information, least privilege, and monitoring, is not complicated in its concept. The problem is implementing it at the rate and scale that entic AI will require. That is why individual capsules should receive the same attention as the child articles they contain.
To security architects, platform engineers, and anyone in charge of deployments of AI agents: It is high time that we start discussing Identity Crisis – Securing Non-Human Identities for AI Agents, because the issue of non-human identity self-declared agent identity mismanagement will become urgent in no time. The qualifications are gold-standard. The question is, could you see them?
I’m a technology writer passionate about AI and digital marketing. I create engaging and useful content that bridges the gap between complex technology concepts and digital technologies. My writing makes the process easy and engaging. I encourage participation I continue to research innovation and technology. Let’s connect and talk technology!



