TL;DR: Clarity Security says non-human identities now outnumber human identities by more than 100 to 1 in many enterprise environments, while most organisations still lack systematic governance for service accounts, API keys, OAuth tokens, and AI agents. Access that compounds over time is turning NHI oversight into a structural identity problem, not a niche operations issue.
At a glance
What this is: This is a webinar preview arguing that NHI and AI agent governance is moving faster than IAM control design, with enterprise access sprawl outpacing current oversight models.
Why it matters: It matters because IAM, PAM, and IGA teams now have to govern machine and agent identities whose access accumulates faster than traditional review cycles can absorb.
By the numbers:
- Non-human identities now outnumber human ones by more than 100 to one in many enterprise environments.
👉 Read Clarity Security's webinar preview on AI agent and NHI governance
Context
NHI governance is the discipline of inventorying, authorising, reviewing, and revoking access for service accounts, API keys, OAuth tokens, certificates, and AI agents. The problem here is not that these identities exist. The problem is that most IAM programmes were designed around human users, while machine access is created, inherited, and forgotten at machine speed.
Clarity Security frames the issue as an identity governance gap rather than a narrow operations issue. That matters because access compounds over time, which means every delay in ownership, offboarding, or review widens blast radius before teams notice the control failure.
The article positions AI agents as the latest pressure point in a broader NHI governance problem. That is typical of the current market: enterprises have long struggled with service accounts and secrets, and agentic systems now expose the same structural weaknesses in a more dynamic form.
Key questions
Q: Why do IAM controls fail when non-human identities outnumber human users?
A: IAM controls fail when NHIs dominate because the governance model was built around stable human accounts with predictable owners, review cycles, and sign-in behaviour. Machine identities are created faster, reused more widely, and forgotten more easily, so the control problem shifts from authentication to lifecycle visibility and revocation discipline.
Q: When does AI agent access become harder to govern than service account access?
A: AI agent access becomes harder to govern when the agent can decide which tools to call during runtime, rather than following a fixed automation script. At that point, the effective privilege profile can shift mid-session, so teams must govern execution boundaries, not just provisioned entitlements.
Q: What breaks when non-human identities are not offboarded properly?
A: Orphaned NHIs remain valid long after the workload or integration they served is gone, which gives attackers a durable access path. The failure is not just administrative drift. It is living authentication that no longer has a legitimate owner, so compromise can happen through forgotten keys, tokens, or service accounts.
Q: How should security teams implement NHI governance before AI agents scale further?
A: Start with continuous discovery, then add ownership, lifecycle triggers, certification, and escalation. Security teams should not treat those as separate projects. They form one control loop that tells you what exists, who is responsible, when access should change, and when the identity should be removed.
Background and context
Why NHI sprawl breaks IAM assumptions
Traditional IAM assumes identities are comparatively stable, human-owned, and easy to review on a schedule. Non-human identities do not behave that way. Service accounts, API keys, OAuth tokens, and certificates can be created in bulk, reused across systems, and left active long after the original owner or purpose has changed. That makes governance depend on lifecycle visibility, not just authentication strength. The harder part is not signing in. It is knowing who owns the credential, what system depends on it, and whether revocation will break production.
Practical implication: map every NHI to an owner, a purpose, and a revocation path before relying on periodic access reviews.
How AI agents change the identity governance problem
AI agents are not just another workload identity. They can initiate actions, chain tool use, and create new access dependencies during runtime, which means the governance object changes while the session is active. That is a different problem from static account management. Conventional IAM can record that access exists, but it struggles to explain why an agent acquired it, how long it should persist, or what downstream tools the agent may touch next. Governance has to follow the execution path, not only the identity record.
Practical implication: define runtime guardrails for tool access, approval boundaries, and delegated permissions before agent deployment.
Why access compounds over time in NHI estates
Access compounding happens when credentials, role grants, and delegated permissions accumulate faster than teams can remove them. In NHI estates, that often occurs because ownership is unclear, offboarding is weak, and temporary access becomes permanent by default. The result is not a single misconfiguration but an expanding trust surface. Once an NHI is embedded in pipelines, data flows, or automation chains, revocation becomes both technically risky and politically delayed. That is why NHI governance is a lifecycle problem as much as a security problem.
Practical implication: make credential expiry, ownership change, and decommissioning part of the same control loop.
NHI Mgmt Group analysis
Non-human identity governance has become a core IAM discipline, not an edge case. Service accounts, API keys, and OAuth tokens now represent a large share of enterprise access, and the article’s more than 100 to 1 ratio shows why human-centric IAM models are insufficient. Governance that treats these identities as exceptions will continue to miss ownership, lifecycle, and revocation gaps. The practitioner conclusion is simple: NHI must be governed as a primary identity class, not a side channel.
Access compounding is the real control failure behind NHI sprawl. The article is pointing to a system where access persists because no one owns the full lifecycle from issuance to offboarding. That creates a governance blind spot that access reviews alone cannot repair. The practitioner conclusion is that oversight has to move upstream into issuance, ownership, and expiry controls.
AI agents expose the limits of static privilege models. Least privilege was designed for identities whose access profile is known before execution begins. That assumption weakens when an agent selects actions and tools during runtime, because the effective privilege set is not fixed at provisioning time. The practitioner conclusion is that identity governance now has to account for runtime delegation, not just assigned roles.
Ephemeral execution creates an identity governance gap that review cadences cannot close. Access review processes assume access persists long enough to be inspected, certified, and revoked on schedule. When an agent or workload can acquire and release access within a short operational window, the control loses visibility before the review cycle begins. The practitioner conclusion is that governance must shift from retrospective review to issuance-time policy and boundary enforcement.
Runtime governance gap: the article shows that the market is moving from static credential control to oversight of living, changing identity behaviour. That shift will push IAM, PAM, and IGA teams toward shared governance models for humans, NHIs, and agents. The practitioner conclusion is that identity programmes that still separate those domains will keep accumulating unmanaged access.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs
What this signals
Access review programmes will not keep pace unless they move closer to issuance. Access that can be created and consumed faster than review cycles can observe it needs governance at the point of grant, not at the point of certification. That is the practical consequence of machine and agent identity growth for identity teams.
Identity lifecycle control is becoming the shared language across human IAM, NHI, and agent governance. The organisations that can name ownership, expiry, and offboarding consistently across all three identity classes will have a cleaner operating model than those that treat them as separate programmes.
For practitioners
- Inventory every non-human identity Create a complete register for service accounts, API keys, OAuth tokens, certificates, and agent identities with ownership, purpose, and system dependency recorded for each entry.
- Tie issuance to expiry by default Set explicit expiration and renewal rules for machine credentials so access cannot persist indefinitely when teams lose track of the original business need.
- Separate human and NHI review workflows Use distinct governance paths for human users and machine identities so access reviews do not blur lifecycle, ownership, and offboarding requirements.
- Define runtime guardrails for AI agents Restrict which tools, data sources, and delegated permissions an agent can reach during execution, and require clear escalation boundaries before deployment.
Key takeaways
- NHI sprawl is no longer a niche hygiene issue. It is a governance problem that overwhelms human-centric IAM assumptions once machine identities dominate the access landscape.
- The scale signal is clear. Clarity Security says non-human identities outnumber human ones by more than 100 to 1, and only 20% have formal processes for revoking API keys.
- The control answer is lifecycle discipline. Ownership, expiry, and offboarding need to be enforced at issuance, not left to periodic review alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on excess privilege and access that compounds across non-human identities. |
| NHI-01 — Improper Offboarding | Weak offboarding is a core reason access persists after systems and owners change. | |
| NHI-07 — Long-Lived Secrets | API keys and tokens are described as accumulating and persisting beyond their intended window. | |
| Recommendation — Reduce standing access for NHIs and align entitlements to the minimum required business purpose. Build NHI offboarding into lifecycle governance so credentials are revoked when ownership ends. Enforce shorter credential lifetimes and renewal gates for machine identities. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing who or what is authorised to hold access. |
| Recommendation — Centralise entitlement governance so human and non-human access can be reviewed and revoked consistently. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | AI agents expand the privilege problem because runtime actions can exceed static authorisation assumptions. |
| Recommendation — Constrain agent privilege boundaries and monitor for runtime access expansion. | ||
Key terms
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Credential Compounding: A failure pattern where one exposed identity leads to discovery or misuse of additional credentials, tokens, or accounts. The risk is not just the first leak but the expanding access chain that follows when systems are linked and permissions are inherited too broadly.
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
- Runtime Delegation: The process by which an identity is allowed to choose actions, tools, or next steps while a task is in progress. In AI agent environments, runtime delegation is risky when it is broad, opaque, or disconnected from explicit policy, because the resulting behaviour may exceed the original intent.
What to expect at the briefing
Clarity Security's full webinar covers the operational detail this post intentionally leaves for the source:
- Direct guidance from Lalit Choda on where NHI governance breaks down in real enterprise environments
- Discussion of the biggest misconceptions security teams still hold about non-human identities
- A closer look at how AI agents change identity governance and regulatory scrutiny
- Two-to-three year outlook on where NHI and AI identity governance are headed
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org