By NHI Mgmt Group Editorial TeamBased on 1Password: “1Password Earns Recognition on the Third Annual CRN AI 100 List” (May 27, 2026)

TL;DR: AI agents and machine identities are increasingly operating outside traditional identity controls, while 1Password says its platform is built to discover, secure, and continuously audit those accesses, as its recognition on CRN’s 2026 AI 100 list lands in a market where identity programmes now have to account for credentials, autonomy, and visibility across human and non-human actors.


At a glance

What this is: 1Password’s CRN AI 100 recognition is presented as a signal that AI agents and machine identities are pushing access governance beyond legacy human-centric controls.

Why it matters: IAM, PAM, and NHI programmes now have to govern discovery, continuous authorisation, and audit across human, agent, and machine access paths.


Context

The governance gap here is straightforward: access programmes were built around human users, while AI agents and machine identities can now create and use credentials in ways those programmes were not designed to observe. That shifts the problem from authentication alone to discovery, ownership, and continuous oversight across mixed identity estates.

1Password’s AI 100 recognition is the trigger for a broader identity question, not the subject in itself. The article points to a market where partners and security teams have to account for AI tools, exposed credentials, and non-human access paths at the same time as human identity controls remain in place.

For practitioners, the interesting part is not the award list. It is the signal that channel-facing security conversations are moving toward governance of access across human, AI agent, and machine identities as one operating model rather than three disconnected ones.


Key questions

Q: How should security teams govern access when AI agents and humans share the same apps?

A: Treat AI agents as separate identity subjects with their own approvals, scope limits, and monitoring. Human access policy assumes a person controls the session, but agentic access can chain actions across tools and timing. Governance should separate authentication from authorisation and require explicit policy for non-human actors before they are allowed to reach business apps.

Q: Why do AI agents and other NHIs create more governance risk than traditional user identities?

A: AI agents and NHIs can scale faster than human accounts, often operate across multiple systems, and may act without direct human review at runtime. That combination increases the chance of overprivilege, orphaned access, and unclear accountability. Governance gets harder when ownership, intent, and access paths are not continuously tracked and enforced.

Q: What are the signs that non-human identity governance is starting to slip?

A: Warning signs include reliance on manual upgrade paths, ad hoc secret handling, and fragmented access management across tools and environments. The article mentions caveats, dispatch limits, SSO support, and automated update channels, all of which point to the need for controlled operational discipline. When teams cannot explain how identities are provisioned, updated, and constrained, governance is already weaker than it should be.

Q: How should organisations govern AI agents alongside human identity and device access?

A: Organisations should treat AI agents as a separate identity class with their own entitlement boundaries, logging expectations, and approval model. Human IAM controls often assume interactive sign-in and review cycles, which do not fit autonomous or programmatic access. The safer approach is to define actor-specific policy and verify which access paths can be delegated without expanding trust unnecessarily.


Technical breakdown

Why AI agents break human-paced access governance

AI agents can initiate work, call tools, and consume credentials on runtime decisions rather than on fixed human schedules. That changes access from a user event into a machine-directed workflow where entitlement may be created, consumed, and discarded faster than review cycles can observe it. In practical terms, human-centric approval, certification, and ownership models lose fidelity when the identity subject is acting independently across tool chains. The governance challenge is not just who logged in, but which actor decided to use which access path, and when that decision was made.

Practical implication: shift access governance toward issuance-time controls, runtime visibility, and explicit accountability for agent-driven access paths.

Machine identities need continuous discovery, not periodic inventory

Machine identities include service accounts, tokens, secrets, and other non-human credentials that often proliferate outside standard joiner-mover-leaver processes. The article’s emphasis on exposing credentials across environments reflects a basic governance reality: if identities are not continuously discovered, they are not governable. In hybrid environments, the risk is not only overprivilege but also unseen ownership drift, stale access, and unmanaged credential reuse. Visibility is the prerequisite control because you cannot certify, revoke, or scope what you have not found.

Practical implication: build continuous discovery of machine identities and tie it to ownership, rotation, and revocation workflows.

Continuous audit is the control that connects human, AI, and machine access

The article frames continuous auditing as part of the response to AI-era access sprawl. That matters because audit is the only governance layer that can span humans, AI agents, and machine identities without assuming they behave the same way. For humans, audit validates behaviour after access is granted. For non-human identities, audit has to show whether access was created, used, and constrained in the way policy intended. Without that continuity, organisations end up with fragmented evidence that cannot support accountability across the full identity estate.

Practical implication: unify audit trails across human, AI agent, and machine identities so governance evidence survives mixed access patterns.


  • Okta support system breach 2023: A support service account credential saved in a personal Google profile let attackers take HAR files and hijack five Okta customers' sessions.
  • DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI governance now depends on identity governance, not the other way around: The article reflects a market shift where AI adoption creates identity exposure faster than traditional access programmes can adapt. Once agents and machines can create and use credentials outside normal human workflows, the control plane becomes identity-centric rather than application-centric. Practitioners should treat AI access as an identity governance problem first.

Continuous visibility is the new baseline for non-human access: The phrase that matters here is hybrid identity governance gap. That gap exists when organisations can describe human access but cannot continuously account for AI tools, exposed credentials, and machine identities in the same control model. The implication is straightforward: discovery and audit must become continuous, or the estate becomes partially ungoverned by design.

Human-first lifecycle models no longer cover the full access estate: Joiner-mover-leaver processes, access reviews, and recertification still matter, but they were built for actors whose access patterns are comparatively stable and reviewable. AI agents and machine identities can appear, act, and disappear across environments without fitting those cadences neatly. Practitioners need lifecycle governance that recognises non-human identity as a first-class subject, not an exception case.

The channel signal is as important as the product signal: CRN’s AI 100 recognition shows that AI security is moving into partner-facing operational conversations, not staying in innovation labs. That usually means practitioners should expect more pressure to govern access across multiple identity types in a single operating model. The near-term priority is to align procurement, governance, and audit assumptions before AI access sprawl becomes normalised.

Ownership, not just visibility, will separate control from noise: Discovering AI tools and machine identities is necessary, but it does not create governance by itself. Organisations still need an accountable owner for each access path, each credential class, and each non-human runtime. Without that, visibility becomes a dashboard exercise rather than a control surface, and the programme cannot sustain revocation, review, or incident response.

From our research library:

What this signals

Hybrid identity governance gap: Organisations should expect AI security discussions to converge on access discovery, continuous authorisation, and lifecycle ownership rather than on AI tooling alone. Once non-human actors can create or consume credentials in production, identity governance becomes the enforcement layer that determines whether the environment is actually controllable.

Identity programmes will be judged on mixed-estate visibility: The practical question is no longer whether a security team can protect users, but whether it can see and govern credentials across humans, AI agents, and machine identities at the same time. That means the control model has to surface ownership, privilege scope, and audit evidence in one place, not three.

If AI access is allowed to grow without a unified inventory and review model, the organisation will accumulate governance debt that looks like normal operational complexity until it becomes an incident or audit finding.


For practitioners

  • Map human, agent, and machine access paths separately Build an identity inventory that distinguishes people, AI agents, service accounts, tokens, and other machine identities so access ownership is explicit.
  • Deploy continuous discovery for exposed credentials Search for credentials created or used outside standard workflows, then connect findings to ownership, rotation, and revocation workflows.
  • Extend access reviews to non-human identities Do not rely on human recertification cadences alone. Define review triggers for machine identities and AI-driven access paths that can change between review cycles.
  • Unify audit evidence across identity types Correlate authentication, credential issuance, and action logs so governance teams can reconstruct who or what accessed a system and why.
  • Assign named owners to every non-human credential class Require an accountable business or technical owner for service accounts, AI agent credentials, and shared secrets before they are allowed into production.

Key takeaways

  • The article points to a widening gap between human-centric identity programmes and environments where AI agents and machine identities now use credentials in production.
  • Visibility, ownership, and continuous audit are the controls that determine whether non-human access stays governable as AI adoption moves from testing to deployment.
  • Practitioners should treat AI access as an identity governance problem across humans, agents, and machine identities rather than as a standalone technology issue.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents using credentials and access outside human-only controls.
Recommendation — Apply ASI03 to govern agent identity, privilege scope, and runtime access boundaries.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article highlights exposed credentials and non-human access paths that need tighter scope control.
Recommendation — Use NHI-05 to reduce machine identity privilege and constrain exposed access paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is controlling entitlements across human and non-human identities.
Recommendation — Enforce PR.AA-05 to govern entitlements and authorisations across mixed identity estates.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCloud and SaaS access governance for humans and non-humans is central to the article.
Recommendation — Use IAM controls to keep non-human and human access under one governance model.

Key terms

  • Hybrid Identity Management: Hybrid Identity Management is the coordinated control of identities across on-premises and cloud environments. It links directories, authentication, authorization, and lifecycle processes so people, applications, and machines can access resources consistently. Technically, it spans federation, synchronization, policy enforcement, and governance across multiple identity domains.
  • Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
  • Continuous Auditing: A control assurance approach that validates effectiveness as changes happen rather than at fixed review points. It relies on timely evidence, automated monitoring, and repeatable checks so exceptions are detected early and audit readiness is maintained throughout the year.
  • Agentic Access: Agentic access is delegated system access granted to an AI agent or autonomous workflow so it can perform defined tasks across tools and data sources. It differs from human access because the actor can execute continuously, combine actions quickly, and amplify mistakes at scale.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org