By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: CakewalkPublished July 14, 2026

TL;DR: When AI significantly expanded the number of identities requiring access, reported breach rates reached 43% in the past year versus 11% where access patterns did not change, according to Cakewalk’s summary of Netwrix and ISACA research. The signal is not just adoption, but standing access that governance teams cannot revoke fast enough once AI systems are live.


At a glance

What this is: The article argues that organisations are expanding AI access faster than they can govern it, and that the result is higher breach rates and weak revocation control.

Why it matters: IAM, NHI, and security teams need to treat AI access as a governance problem, because broad standing permissions create exposure that policy writing alone does not fix.

By the numbers:

  • Among organizations where AI significantly expanded the number of identities requiring access, breach rates reached 43% over the past twelve months, compared with 11% where AI had not materially changed access patterns.
  • Only 19% of organizations say they fully govern their non-human identities, the service accounts and agent credentials that now act inside company systems.
  • 56% of professionals did not know how long it would take to halt an AI system during a security incident.

👉 Read Cakewalk's analysis of how AI access is outpacing governance


Context

AI access governance is failing because organisations are expanding the number of identities that can act inside systems faster than they can define, review, and revoke that access. In practice, this creates a gap between issuance and control, which is where breach exposure grows for both non-human identities and emerging AI agents.

The article combines two 2026 surveys to show the same pattern from two angles: more access on the front end, and little confidence in stopping or scoping AI once it is running. That is a familiar identity problem, but it becomes more serious when the actor is non-human and the access is standing rather than task-scoped.


Key questions

Q: How should security teams govern AI identities when they are deployed faster than review cycles can keep up?

A: Security teams should treat AI agents, service accounts, and integrations as first-class identities from the moment they appear. Governance must be continuous, not quarterly, with access scoped tightly, reviewed automatically, and revoked as soon as it is no longer needed. The key control is reducing the gap between identity creation, permissioning, and oversight so machine-speed deployment does not outrun human-speed process.

Q: Why do AI systems with standing access increase breach risk?

A: Standing access increases breach risk because the identity keeps its reach long after the original task or approval context has changed. In AI environments, that persistence expands the blast radius, makes containment harder, and leaves security teams dependent on manual revocation paths that are often too slow.

Q: What breaks when organisations cannot halt an AI system during an incident?

A: What breaks is containment. If teams do not know how long shutdown will take, they cannot reliably stop data access, tool use, or downstream actions before the system completes more work. That leaves the incident response process one step behind the identity that is already operating.

Q: Who is accountable when AI-related access outpaces governance?

A: Accountability sits with the owners of identity, data, and platform controls together, because AI-related access problems cross programme boundaries. IAM, IGA, PAM, and security leadership must share responsibility for visibility, revocation, and ownership. If one team can create access but no team can remove it quickly, the control model is incomplete.


Technical breakdown

Why standing AI access creates a governance gap

The core technical issue is not whether AI can authenticate, but whether its access can be governed as a lifecycle object. Once an AI system or agent receives standing permissions, the identity behaves like any other non-human identity with persistent entitlements, except the organisation often lacks reliable revocation timing, ownership clarity, or downstream scoping. That produces a governance gap between initial authorisation and actual operational control. In IAM terms, the problem is less about login and more about entitlement persistence across systems, logs, and policy boundaries.

Practical implication: treat AI access as a lifecycle-controlled entitlement, not a one-time provisioning event.

Why revocation matters more than policy volume

The article points to a common failure mode in identity programmes: policies exist, but the organisation cannot execute them quickly enough when the AI system is already active. That is a control gap, not a documentation gap. If revocation depends on manual coordination across application owners, security operations, and platform teams, the access window remains open long after the intended use case has ended. For NHI governance, the technical problem is standing privilege paired with slow deprovisioning.

Practical implication: test whether access can actually be removed across all systems before scaling AI usage.

Why AI systems need scoped execution boundaries

When AI is granted broad access, the system can read, act, and potentially chain operations across multiple tools or data sources without a clear operational boundary. Even when the AI is not autonomous in the strict sense, broad access increases blast radius because the identity may reach more systems than any single human workflow would justify. The key design issue is whether access is bounded by role, task, or session, and whether those limits are enforced consistently across the identity stack.

Practical implication: reduce AI blast radius by narrowing roles, tool scopes, and data access paths before deployment.


Threat narrative

Attacker objective: The objective is to exploit persistent AI or agent access to increase the reach of compromise before governance can intervene.

  1. Entry occurs when AI systems or agent credentials are granted broad access faster than governance teams can map the full entitlement footprint.
  2. Escalation happens when standing access cannot be revoked immediately, allowing the identity to retain operational reach after the original purpose has changed.
  3. Impact follows when persistent access expands breach exposure across systems, data, and tool chains, with limited containment once the identity is live.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Standing AI access is now the central governance failure. The article shows that organisations are not failing because they lack policies, but because they are issuing access faster than they can constrain it. That pattern creates persistent entitlement exposure across non-human identities and AI-enabled workflows. The practitioner conclusion is clear: access governance must be measured by revocation speed and entitlement scope, not by policy count.

Access review assumptions break down when AI access changes faster than review cycles. Traditional identity governance assumes there is enough time to observe, certify, and remediate access after it is granted. In AI-heavy environments, that assumption weakens because permissions are expanded at deployment speed and often remain standing. The implication is that governance teams need to rethink review cadence as a control, not just increase review frequency.

Ephemeral behaviour is becoming the exception, not the default, for AI-linked identities. The article’s data suggests that many organisations are still operating with broad, durable access models even as AI systems proliferate. That creates a wider identity blast radius than most IAM programmes are designed to tolerate. Practitioners should treat short-lived, task-scoped access as the baseline expectation for AI-connected identities.

Non-human identity governance is the missing control plane beneath AI adoption. Only 19% of organisations fully govern their NHIs, which means the underlying accounts and credentials that AI depends on are often outside strong lifecycle control. As AI expands the number of identities that touch systems, the exposure moves from isolated tool risk to programme-wide identity risk. Security leaders need to govern the machine identity layer before AI adoption outpaces it.

AI policy maturity is not the same as control maturity. The article shows that more organisations can now point to formal AI policies, yet many still cannot tell how quickly an AI system could be stopped during an incident. That gap matters because written policy does not reduce blast radius by itself. The practitioner takeaway is that operating controls, not policy documents, determine resilience.

From our research:

  • Only 19% of organizations say they fully govern their non-human identities, according to The State of Non-Human Identity Security.
  • In the same research, 85% of organizations lack full visibility into third-party vendors connected via OAuth apps, which leaves delegated access outside clean lifecycle control.
  • For the adjacent control problem, 52 NHI Breaches Analysis shows how credential exposure and weak offboarding turn access into breach fuel.

What this signals

Standing access will become the default failure mode in AI governance unless identity teams intervene earlier in the lifecycle. Once AI access is provisioned broadly, the remediation burden shifts from policy owners to operations teams that may not control every downstream entitlement. That is why the next phase of programme maturity is not more documentation, but faster deprovisioning and narrower access design. The control question is whether your programme can actually shrink the identity blast radius before it becomes incident response work.

Ephemeral access must become a design assumption, not an aspiration. For teams managing AI-connected systems, the practical benchmark is whether access exists only as long as the task requires it and can be revoked without manual escalation. Where that is not true, the organisation is carrying identity debt that will show up as longer containment times and wider breach exposure.

AI adoption is also an NHI governance test. If service accounts, tokens, and agent credentials are not fully governed, every AI deployment inherits that weakness. Security leaders should use this moment to connect AI access review, workload identity controls, and lifecycle management into one operating model rather than running them as separate programmes.


For practitioners

  • Map AI-linked identities to standing access paths Inventory every service account, token, and agent credential that can be used by AI systems, then trace where standing permissions remain after deployment.
  • Test revocation across the full access chain Measure how long it takes to remove AI access from applications, data sources, orchestration layers, and downstream integrations, then close the slowest handoff points.
  • Reduce blast radius with task-scoped permissions Replace broad entitlements with narrower roles, constrained tool scopes, and time-bound access that matches the actual task window.
  • Validate shutdown procedures before production use Run incident exercises that prove the team can halt or override AI-driven access without waiting for manual coordination across multiple owners.

Key takeaways

  • AI-related breach exposure rises when organisations expand access faster than they can govern or revoke it.
  • Standing NHI permissions, not policy volume, are the practical weakness this article exposes.
  • The right response is tighter lifecycle control, faster revocation, and narrower access boundaries for AI-linked identities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Standing access and revocation failure are central NHI governance risks in this article.
NIST CSF 2.0PR.AC-4The article is about access governance and least privilege across AI-connected identities.
NIST SP 800-53 Rev 5IA-5Credential and authenticator management underpins AI access persistence and revocation.
NIST Zero Trust (SP 800-207)Zero trust is relevant because AI access needs continuous verification and scoping.

Map AI-linked identities to NHI-03 and verify revocation works across every connected system.


Key terms

  • Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
  • Revocation Latency: Revocation latency is the time between a decision to remove access and the point at which that access is actually gone. It is a practical measure of how long stale privilege remains usable after a role change, offboarding, or contract end. Shorter latency means smaller exposure and cleaner audit evidence.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials — ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.

What's in the full report

Cakewalk's full article covers the operational detail this post intentionally leaves for the source:

  • The full survey breakdown from Netwrix and ISACA, including respondent counts and the underlying question set.
  • The article's direct comparison of breach rates, AI policy maturity, and revocation confidence across the two surveys.
  • The source's original framing of how organisations are handling AI access expansion and shutdown uncertainty.
  • The published citations and source notes for the two 2026 surveys used in the analysis.

👉 Cakewalk's full article includes the survey figures and source commentary behind the access and breach gap.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building identity security capability across human, machine, and AI-driven environments, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org