TL;DR: AI and non-human identities dominated Identiverse 2025, and Saviynt used the event to argue that identity programmes must evolve for autonomous AI agents, cross-functional governance, and converged control across human and machine identities. The central assumption breaking down is that identity is stable, enumerable, and governed by human-paced review cycles.
At a glance
What this is: This is a commentary on Identiverse 2025 that argues AI agents and NHIs are forcing identity teams to rethink governance, visibility, and control-plane design.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams now have to govern identities that do not fit human-centric lifecycle assumptions, especially as agentic AI expands access scope and operational complexity.
By the numbers:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so.
👉 Read Saviynt's Identiverse 2025 commentary on AI agents and NHI governance
Context
AI agent identity governance is becoming a core identity security problem because autonomous software entities are now acting with decision-making power, tool use, and access needs that do not map cleanly to human IAM patterns. The article frames Identiverse 2025 as a moment when practitioners were forced to confront that shift.
The governance gap is not just visibility. It is the mismatch between fast-moving machine behaviour and identity programmes built around static entitlements, periodic review, and human accountability structures. NHIMG has long argued that lifecycle control is the discipline that connects human identities, NHIs, and autonomous actors, with the Ultimate Guide to NHIs providing the baseline model for that governance.
The article also points to the need for shared language and policy frameworks. That is typical of early-category maturation: teams can see the risk before they can consistently name, classify, and govern it.
Key questions
Q: How should security teams govern AI agents and NHIs differently?
A: Security teams should govern NHIs as predictable machine identities and AI agents as runtime actors that can alter behaviour after authentication. That means static entitlements, inventory, and rotation remain central for NHIs, while agents need behaviour monitoring, delegation tracing, and ownership controls that account for tool choice and execution timing.
Q: Why do AI agents complicate traditional access reviews?
A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe. A review process built for stable human accounts does not fit an executor that can act across systems, create new access paths, and complete work before the next review window begins.
Q: What do IAM teams get wrong when they treat AI agents like service accounts?
A: They assume an agent is just another fixed non-human identity, when its behaviour may be runtime-driven and tool-selecting. That can lead to under-scoped oversight, misplaced trust in static entitlements, and review processes that do not match how the actor actually operates.
Q: How can organisations tell whether NHI governance is actually working?
A: NHI governance is working when every machine identity has an owner, a purpose, a minimum-necessary entitlement, and evidence of rotation and review. If teams can produce that chain without manual reconstruction, the programme is mature enough to withstand audit pressure. If they cannot, the governance model is still fragmented.
Technical breakdown
Why AI agent identity is not just another NHI
AI agents are not merely automated service accounts. When they can choose actions, interact with tools, and alter execution paths based on runtime context, the identity problem shifts from credential possession to behaviour control. That changes how least privilege, auditing, and accountability work because access is no longer static and intent is not fixed at provisioning time. The governance challenge is therefore not just who has access, but what the identity can decide to do with that access across sessions, tools, and data domains.
Practical implication: treat agent behaviour as a governance object, not just the credentials attached to it.
Why a single control plane matters for human and machine identities
A converged identity control plane is about more than convenience. In mixed environments, human identities, service identities, and AI agents all feed the same entitlements, logs, policy checks, and evidence workflows. If those controls stay split across silos, teams lose the ability to correlate who approved access, which identity used it, and whether the access was still appropriate at runtime. The technical issue is control fragmentation, which creates blind spots in auditability and weakens policy enforcement across environments.
Practical implication: build one governance model that can see entitlement, usage, and evidence across all identity classes.
Why shared language is a technical control, not just a communications issue
The article’s emphasis on most executives not knowing what NHIs are points to a deeper operational problem. If teams cannot consistently classify an identity as human, non-human, or autonomous, they will misapply lifecycle rules, review cadences, and ownership models. That leads to broken evidence chains, unclear control ownership, and inconsistent remediation. In practice, taxonomy is a prerequisite for enforceable policy because policy engines and audit workflows depend on unambiguous identity classification.
Practical implication: standardise identity taxonomy before expanding policy automation or governance will drift.
NHI Mgmt Group analysis
AI agent governance is becoming the new test of whether an identity programme is actually lifecycle-aware. The article shows that identity teams can no longer stop at human users and service accounts. Once autonomous AI enters the environment, lifecycle, access, and accountability must cover systems that can act, select tools, and change behaviour at runtime.
The named concept here is identity governance convergence: one control model for human identities, NHIs, and AI agents. The article’s core point is that silos between these identity classes create blind spots in audit, policy, and remediation. Practitioners should read that as a warning that separate governance stacks will not keep pace with converged access patterns.
Autonomous actors collapse the assumption that identity intent is known at provisioning time. That assumption was designed for humans and static NHIs. It fails when an actor can alter actions mid-session, so least privilege cannot be treated as a one-time designation. The implication is that governance has to be designed around runtime behaviour, not only assigned access.
Shared language is part of the security model, not a side effect of maturity. If leaders cannot agree on what an NHI is, who owns it, or how an AI agent differs from a workload identity, they cannot produce reliable policy or evidence. That makes taxonomy, ownership, and control mapping foundational to any credible identity security programme.
The market is moving toward converged identity platforms because the problem itself has converged. Human IAM, NHI governance, and agentic AI controls are no longer separable planning tracks. Teams should expect vendors, frameworks, and internal operating models to be judged on how well they support one identity fabric across all three domains.
From our research:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- Read OWASP NHI Top 10 for the control patterns that help teams govern agentic behaviour before it becomes normalised.
What this signals
Identity governance convergence: the next phase of programme maturity is not adding another tool, but aligning human IAM, NHI governance, and agent oversight into one operating model. Teams that keep these disciplines separate will struggle to produce consistent policy, evidence, and escalation paths.
The practical signal for practitioners is that taxonomy and ownership now matter as much as access policy. If an organisation cannot distinguish a workload identity from an AI agent, it will misapply lifecycle rules and miss the behaviour that actually creates risk.
For teams formalising their agent controls, the right reference point is NIST AI Risk Management Framework and the agentic guidance in OWASP Agentic AI Top 10, because runtime behaviour and accountability have become governance issues, not just technical ones.
For practitioners
- Define identity classes explicitly Create a shared taxonomy for human identities, NHIs, and autonomous agents, then map ownership, review cadence, and control requirements to each class. Use the taxonomy in architecture reviews, access requests, and audit evidence packs so policy decisions do not depend on informal interpretation.
- Converge entitlement and audit data Unify logs, approvals, and entitlement records into one evidence model so teams can trace what was approved, what was actually used, and which identity used it. That matters most where agents and machine identities share application, data, and infrastructure access.
- Rework access reviews for runtime actors Do not use review processes that assume access remains stable long enough to be periodically certified. For autonomous or fast-moving non-human actors, the control question is whether access can be bounded and observed in the same execution window.
- Assign one accountable owner per identity population Separate operational responsibility for humans, NHIs, and AI agents if needed, but keep a single accountable authority for policy decisions, escalation, and exceptions. Fragmented ownership is where blind spots and approval delays usually appear first.
Key takeaways
- AI agents are pushing identity teams beyond human-centric IAM assumptions and into runtime governance.
- The central failure mode is not lack of interest, but lack of shared taxonomy, ownership, and cross-domain control visibility.
- Practitioners should converge human, NHI, and agent governance now, because the operating model is already changing faster than the review cycle.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article centres on AI agents and their governance risk. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | The post focuses on non-human identity governance and visibility. |
| NIST AI RMF | GOVERN | The article raises accountability and policy issues for autonomous AI. |
| NIST Zero Trust (SP 800-207) | Section 2.1 | The article’s converged access model aligns with continuous verification principles. |
| NIST CSF 2.0 | PR.AC-4 | Least privilege and access management are central to the discussion. |
Map agent behaviour, tool use, and access scope to OWASP agentic risks before expanding deployment.
Key terms
- Autonomous Agent: A software entity that can act with its own execution authority and use tools or data sources to complete tasks. In security terms, an autonomous agent is also a non-human identity, so its permissions, approval boundaries, and credential lifecycle must be governed like any other privileged workload.
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Runtime Behaviour Monitoring: Runtime behaviour monitoring is the practice of watching what an identity actually does during execution, not just what it was configured to do. For AI agents, this means tracking tool calls, session activity, data volume, and unusual action sequences so semantic abuse can be detected in flight.
- Identity Taxonomy: Identity taxonomy is the way an organisation classifies identity types so that policy, monitoring, and lifecycle controls can be applied correctly. In NHI governance, a precise taxonomy helps teams separate workloads, service accounts, certificates, and agents instead of forcing one control model onto all of them.
What's in the full article
Saviynt's full post covers the event-specific examples and product positioning this analysis intentionally leaves aside:
- Session-level context from Identiverse 2025 conversations and panels that shaped the discussion on AI and NHIs
- Product and platform detail on how the Identity Cloud is described for converged governance across identity types
- Customer example material from the GE HealthCare discussion and the ISPM framing used in the article
- Additional commentary from Saviynt speakers on the evolving identity workforce and IAM operating model
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org