Welcome to the latest edition of our Non-Human & AI Identity Journal, where we cover:
- The NHI & AI Summit – The New NHI Risk Reality
- Our pick from our Non-Human & AI Identity Forum
- Recent Breaches and Security Incidents
- Upcoming Events, Webinars, Industry Announcements
NHI Mgmt Group At Identiverse
NHI Summit Session: The New NHI Risk Reality
At the NHI & AI Identity Summit at Identiverse 2026, industry leaders Shriram Santhanan, Andrej Safundzic, Don D’Souza, and Ashay Raut delve into the transformative impact of AI agents on the Non-Human Identity (NHI) risk landscape. As AI agents begin making decisions and acting on behalf of humans, traditional identity governance and security models face unprecedented challenges. Key themes include managing AI agent identity, accountability, and the critical need for context-aware authorisation. The session explores emerging standards and practices essential for preparing identity teams for the era of autonomous AI.
Watch the session here. Catch up on all sessions from the NHI Summit here and join the conversation shaping the future of NHI security.
Recent NHI & Identity Security Breaches
Storm-2949: How a Phone Call Turned One Cloud Identity into a Full Azure Breach
In May 2026, Microsoft Threat Intelligence exposed a sophisticated breach by Storm-2949, which exploited a single compromised cloud identity to infiltrate an entire Azure environment. Through social engineering, attackers gained persistent access to Microsoft Entra ID by manipulating Self-Service Password Reset (SSPR) and MFA processes, eventually accessing sensitive data across Microsoft 365 and Azure infrastructure. This breach underscores the importance for security professionals to scrutinize identity verification processes, as the misuse of legitimate credentials can lead to extensive data exposure without the need for malware or zero-day exploits.
Non-Human and AI Identity Forum Posts
Our suggested reading for this week from our forum — with over 10,000+ articles about NHIs, including Agentic AI.
- Not All Just-in-Time Access Is Created Equal: Why JIT Architecture Matters — Akeyless
- The Most Important AI Meeting You’ll Have This Quarter Costs Nothing — C1.ai
- From MCP Tool Filtering to Runtime Access Control — P0 Security
- AI for Access Administration: Why Expainability Decides Wether It Works — Nexis
- AI Agents Need Three Gateways. Most Enterprises Only Have One. — Saviynt
- The Future Of GitHub Actions Security And What You Can Do Right Now — GitGuardian
- Identity Security and the AI Adoption Maturity Curve — Opal Security
- What ISACA GRC 2026 Made Clear About the Future of Governance, Risk, & Compliance — Clarity Security
- How to Prevent RBAC Role Explosion with Nested Access Lists — Teleport
- Identity threat detection in 2026: Why 5-minute MTTD is now the benchmark — Unosecur
- How a European Bank Reduced Insider Risk by 90% with Centralized Privileged Access Control — Arcon
- The Connector Treadmill: Why Integration Never Ends — Opnova
- Your Identity Management Must Have an Adaptive Security Spine — Newcore
- The OpenAI & Hugging Face breach: the hidden risk of standing non-human privilege — Oleria Security
- 47-Day Countdown: Why Machine Identity Is Critical Now — Thryam
- Shadow AI Agents: How to Find the Agents Nobody Registered — Scramble ID
- AD Group Risks: Hidden Dangers in Backup Operators — Semperis
Latest Industry Announcements
Major updates shaping the NHI and identity security space this week:
- Teleport – Cisco and Teleport Strategic Partnership – Bringing Infrastructure Identity to Agentic IT
- Opal Security — New in Opal: Paladin, Access Campaigns, and OpalScript hit GA
- C1.ai — Introducing Agentic Vault: govern every secret like an identity
- Saviynt — Introducing Zuma: The Enterprise AI Identity Security Platform
- Venice.io — Venice integrates with the Claude Compliance API to bring every Claude identity under just-in-time access
- Oleria Security — Oleria and Happiest Minds partner to accelerate modern identity governance for AI-first enterprises
- Descope — The Descope MCP Server Is Available On Claude and ChatGPT
- Linx Security — Announces Integration with Snowflake to Solve the Trust Gap in Agentic AI
Upcoming Events and Webinars
To support your learning journey, here are key events happening across the industry. They feature experts discussing the latest challenges and innovations in identity security:
- Join GitGuardian at OWASP AppSec Days France 2026 — 2026-09-24 — by GitGuardian
- All Authorization Models Are Beautiful – When They Fit Their Purpose — 2026-09-29 — by Nexis
- SecureWorld Atlanta, GA — 2026-09-24 — by P0 Security
- Live Webinar EMEA – What’s new? The 1Password quarterly security spotlight and roadmap review — 2026-09-03 — by 1Password
- How to Secure Entra ID Workload Identities—Before AI Agent Sprawl Catches Up — 2026-09-08 — by Semperis
- The Biggest Security Challenge Isn’t AI or Quantum—It’s Trust — 2027-02-23 — by Keyfactor
The Most Comprehensive & Only CPD-Certified NHI Course
Our CPD Certified NHI Foundation Level course delivers practical guidance on governing, managing, and securing NHIs, including AI agents. Developed by Mr NHI, it’s designed for beginners, security professionals, and IT leaders, with hundreds of learners and an average 5-star rating.
Enrol here.
Are you planning a NHI Program in 2026 including Agentic AI?
As the premier authority on Non-Human Identities, with over 20 years of hands-on experience managing $10M–$20M+ global NHI programs, we offer independent guidance and advice tailored to your needs. Our expertise spans risk and maturity assessments, program initiation and hands-on execution, ensuring your organisation stays ahead of evolving threats and maximises risk reduction.
Reach out here for a free initial consultation.
Lalit Choda
Founder of the NHI Mgmt Group
