By NHI Mgmt Group Editorial TeamBased on Aembit: “Veteran CISO and Aembit Adviser Renee Guttmann on Guiding Security into the AI Age” (November 6, 2025)

TL;DR: Renee Guttmann argues that rapid AI adoption has created a gap between non-human identity risk and traditional IAM, with non-human identities now outnumbering human ones by ratios exceeding 80:1 in some organisations, according to Aembit. The key issue is not just access volume but governance assumptions that were built for static systems and human users.


At a glance

What this is: This adviser interview argues that AI agent identity governance is now outrunning IAM controls designed for human users and static systems.

Why it matters: IAM, IGA and PAM teams need to reset assumptions about lifecycle, authorisation and review when AI agents operate as non-human identities at machine speed.

By the numbers:

  • Non-human identities now outnumber human ones by ratios exceeding 80:1 in some organisations, according to Aembit.

Context

AI agent identity governance is the problem space here, not the adviser announcement itself. The core issue is that traditional IAM was built around static systems and human users, while AI agents can request, use, and retire access at machine speed.

That creates an identity governance gap across lifecycle, privilege scope, and accountability. For IAM and IGA teams, the question is no longer whether access exists, but whether the programme can govern non-human access before it becomes operational noise.


Key questions

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.

Q: Why do AI assistants create more risk than traditional service accounts?

A: AI assistants create more risk because they can be influenced by inputs, context, and hidden instructions after authentication succeeds. A traditional service account usually executes fixed logic, while an AI identity may summarize, retrieve, or act in ways that are harder to predict. That makes access scope and behavioral testing equally important.

Q: What are the signs that access governance is failing in practice?

A: The clearest signs are slow remediation, repeated rubber stamp access reviews, and missed permissions outside traditional HR linked systems. If governance teams rely on manual audits, they often struggle to see access granted to non-human identities or systems adopted outside normal IT cycles. That usually means the organisation lacks reliable visibility and consistent enforcement of least privilege.

Q: When should organisations separate AI agent governance from human IAM reviews?

A: Organisations should separate them as soon as AI agents begin acting inside production workflows. Human access reviews assume a person, a role, and a review cadence that fit a stable entitlement. AI agents require task-scoped boundaries, lifecycle ownership, and monitoring that can keep up with runtime behaviour.


Technical breakdown

Why traditional IAM assumptions break for AI agents

Traditional IAM assumes the subject of access is comparatively stable, that identity is provisioned for a known user or workload, and that access review can observe a durable entitlement over time. AI agents disrupt all three assumptions because the actor can appear, act, and disappear in tightly bounded runtime windows. That makes provisioning-time policy necessary but insufficient. The governance problem is not only authentication, but who decides what the agent may do, when it may do it, and under which boundaries it may persist or escalate. Practical implication: govern agent identity as a runtime state, not just a directory object.

Practical implication: Shift governance from static account administration to runtime-bound authorisation and lifecycle tracking for AI agents.

Non-human access needs lifecycle controls, not just credentials

The interview points to a familiar IAM pattern that still applies: privileges should be right-sized, non-shared, and retired when no longer needed. For AI agents, that lifecycle becomes more urgent because credentials can be embedded in workflows, passed between systems, or left active after the agent’s purpose changes. In non-human identity terms, the risk is not simply secret leakage, but persistent authority that outlives the task it was meant to support. Practical implication: treat agent credentials and access scopes as managed lifecycle objects with explicit ownership and retirement conditions.

Practical implication: Define ownership, expiry, and retirement for AI agent credentials the same way you would for high-risk service accounts.

Why boards need business impact, not technical abstractions

Renee Guttmann’s framing is that executives need to understand what non-human access can stop, expose, or compromise. That is the right governance lens because AI identity risk becomes material when it affects processes, data, trust, or operational continuity. Boards do not need protocol detail, but they do need a defensible explanation of what happens if an AI agent’s credentials are misused or its privileges exceed intent. Practical implication: translate AI agent identity controls into business interruption, data exposure, and trust-impact scenarios for oversight conversations.

Practical implication: Report AI identity risk in operational and business terms so oversight bodies can fund the controls that matter.


Threat narrative

Attacker objective: The objective is to abuse legitimate non-human access so that enterprise processes, data, or trust can be disrupted or compromised.

  1. Entry occurs when an AI agent is granted credentials and access to enterprise systems as part of a legitimate workflow.
  2. Escalation happens when those credentials or privileges are reused beyond the intended task boundary or shared across systems without strict governance.
  3. Impact follows when misused non-human access can halt processes, expose data, or undermine trust in the information the agent handles.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent identity governance exposes a runtime decision problem, not just an account management problem. Traditional IAM was designed for identities whose privileges could be assigned and reviewed against a stable role or workload. AI agents change that model because the meaningful control point is often the session or task boundary, not the directory entry. The implication is that governance teams must stop treating agent access as a static entitlement and start treating it as a runtime authorization decision.

Long-lived, shared, or unclearly owned agent credentials create identity debt. The article’s emphasis on right-sized privileges, non-sharing, and retirement maps directly to the failure mode many programmes already know from service accounts. The difference is that AI adoption compresses the time between issuance and abuse potential, so stale authority becomes operationally visible faster. Practitioners should read this as a governance signal that lifecycle discipline is now central to AI deployment safety.

Non-human identity governance is converging with human IAM and workload governance, but the operating assumptions are not the same. Renee Guttmann’s point that the same IAM principles apply across humans and system accounts is directionally correct, but agentic behaviour adds runtime variability that classic review cycles were never designed to observe. That makes the governance challenge less about inventing a new access model and more about proving that existing models can represent autonomous or semi-autonomous action boundaries. The practitioner conclusion is that identity policy must track behaviour, not just identity type.

Non-human access at 80:1 is a governance scale problem, not a niche control issue. When non-human identities outnumber humans by that magnitude, manual oversight patterns collapse into exception handling. The article reinforces a broader field truth: the more AI agents enter core business processes, the more identity control becomes a prerequisite for safe innovation rather than a follow-on compliance task. Practitioners should assume agent identity governance will increasingly define IAM programme maturity.

Bounded authorisation is the right named concept for this phase of AI identity governance. The article describes a model where AI agents operate freely only within the boundaries of who they are and what they are authorised to do. That is the practical governance pivot for the field because it reframes access from static permissioning to tightly bounded operational scope. The implication is that identity programmes must be able to express and enforce those boundaries consistently across creation, use, and retirement.

What this signals

Bounded authorisation: AI agent governance works only when the organisation can express what the actor may do, where it may do it, and when that authority ends. Once access decisions are tied to runtime behaviour, static recertification alone is no longer enough.

For programme owners, the practical shift is from reviewing entitlements after the fact to governing issuance, scope, and retirement as one continuous control surface. That is where identity, lifecycle, and runtime enforcement start to merge.


For practitioners

  • Map AI agents to distinct identity lifecycles Create separate governance paths for AI agents, service accounts, and human users so each subject has an explicit owner, purpose, and retirement condition.
  • Bind agent privileges to task scope Define the minimum access an AI agent needs for a specific workflow and prohibit reuse of that access outside the approved runtime context.
  • Eliminate shared non-human credentials Remove credential sharing across agents, pipelines, and teams, then assign each agent its own accountable identity boundary and revocation path.
  • Build AI identity risk for the board Translate misuse scenarios into process interruption, data exposure, and trust impact so executives can see the operational consequences of weak governance.

Key takeaways

  • AI agent identity governance is forcing IAM teams to confront controls that were built for stable human and workload identities.
  • The article’s 80:1 ratio shows that non-human identity scale is already large enough to break manual governance assumptions.
  • The control that matters most is bounded lifecycle governance, because agent access must be defined, monitored, and retired around actual runtime use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents operating within and beyond intended authority boundaries.
Recommendation — Map agent access boundaries to ASI03 and constrain runtime privilege expansion.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns that AI agents can accumulate access beyond the minimum needed for the task.
NHI-01 — Improper OffboardingThe article stresses that agent credentials must be retired when they are no longer needed.
Recommendation — Review AI agent privileges for overreach and reduce any access not needed for the approved workflow. Tie AI agent offboarding to workflow retirement so credentials cannot persist after purpose ends.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing permissions and authorisations for non-human identities.
Recommendation — Apply PR.AA-05 to define, approve, and verify AI agent entitlements before they enter production.
MITRE ATT&CKTA0006;TA0004 — Credential Access; Privilege EscalationThe risk pattern described is misuse of agent credentials and expansion of authority beyond intent.
Recommendation — Hunt for AI agent credential abuse and privilege escalation paths in telemetry and access logs.

Key terms

  • AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
  • Bounded Authorisation: Bounded authorisation means an identity is only allowed to operate inside explicit limits for task, scope, and time. For AI agents, this is the core governance pattern because privilege must be constrained to the session or workflow in which the agent is permitted to act.
  • Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
  • Non-human access: Non-human access is access to systems, data, or services by software rather than a person. It covers service accounts, API keys, tokens, certificates, bots, workloads, and AI agents. In identity governance, it must be inventoried, authenticated, authorized, monitored, and revoked with the same rigor as human access.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org