TL;DR: AI agents are already performing around 30% of daily work at about 3x the rate leaders estimate, while fewer than 20% of companies have written AI policies and AI credential leakage rose 81% year over year to 1.27 million exposed secrets, according to Abnormal AI. Human-first IAM, DLP, and SIEM assumptions are collapsing as non-human actors increasingly behave like account takeovers.
At a glance
What this is: This is an Abnormal AI analysis arguing that AI agents and shadow AI are already stretching human-first IAM, with behavioural risk, policy gaps, and exposed credentials now defining the attack surface.
Why it matters: It matters because IAM, IGA, PAM, and monitoring programmes built for people need to distinguish sanctioned human activity from unmanaged non-human behaviour before those gaps become routine incident paths.
By the numbers:
- Employees use AI for about 30% of daily work at roughly 3x the rate leaders believe, according to Abnormal AI.
- AI credential leakage climbed 81% year over year to 1.27 million exposed secrets, according to Abnormal AI.
- Fewer than 20% of companies have written AI policies, according to Abnormal AI.
Context
AI agents are non-human actors that can read data, take actions, and use tools inside enterprise systems. The governance problem is not simply that they exist, but that current IAM models still assume the primary actor is a person and the primary anomaly is a human account behaving badly.
Abnormal AI argues that this assumption is already breaking across discovery, authorisation, and monitoring. Shadow AI tools, exposed AI credentials, and autonomous agents using sanctioned access all create a control gap where identity behaviour no longer maps cleanly to HR-managed accounts or traditional security policy.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.
Q: Why does unmanaged AI tool adoption increase identity and data risk so quickly?
A: Every AI tool, embedded feature, or agent identity can become a new access path to sensitive data. If security teams do not define who approved it, what it can reach, and how it is monitored, the tool inherits broad permissions and creates audit gaps. That combination turns fast adoption into unmanaged exposure across identity and data controls.
Q: What are the warning signs that shadow AI is becoming a security problem?
A: Look for AI tools connected outside approved procurement, unexplained API or token usage, and data leaving normal SaaS boundaries. Those signals show that access has expanded beyond governance, even if the user-facing application still appears legitimate.
Q: How should organisations govern AI agents alongside human identity and device access?
A: Organisations should treat AI agents as a separate identity class with their own entitlement boundaries, logging expectations, and approval model. Human IAM controls often assume interactive sign-in and review cycles, which do not fit autonomous or programmatic access. The safer approach is to define actor-specific policy and verify which access paths can be delegated without expanding trust unnecessarily.
Technical breakdown
Why human-first IAM fails when the actor is a non-human identity
Human-first IAM assumes a stable person behind every account, with intent, usage patterns, and accountability anchored to employee lifecycle events. AI agents and shadow AI break that model because access can be created outside HR, used at machine speed, and exercised through tools that look like ordinary application behaviour. Once behaviour becomes the primary signal, an identity control stack built around login events and approved users loses much of its explanatory power. The operational issue is not only access sprawl, but attribution sprawl: who owns the actor, who approves its scope, and who can tell normal from abnormal when the same account can act like both a user and a workload.
Practical implication: Classify AI systems and agents as governed identities, not just software, and tie ownership to explicit lifecycle and access accountability.
How shadow AI turns credential exposure into governance failure
Shadow AI becomes an identity problem when tools, tokens, and API keys are created, copied, or embedded without governance. That is why public repository leakage matters so much: exposed credentials let a non-human actor retain access long after the original user or team has lost visibility. In practical terms, the issue is less about a single leaked secret than about how quickly one unmanaged credential becomes a persistent access path. Once credentials are outside inventory, IAM cannot certify scope, revoke cleanly, or prove that access remains justified. The article’s point is that leakage is now a routine condition, not a rare exception.
Practical implication: Treat AI credentials as inventory-sensitive assets and force ownership, rotation, and revocation into the same governance workflow as other privileged secrets.
What behavioural monitoring has to do that DLP and SIEM cannot
DLP and SIEM were built to spot data movement and suspicious events, but they do not by themselves explain whether an AI actor is behaving within its intended role. Abnormality in this context is not just volume or velocity. It is an account or agent taking a new path through systems that should not match its usual task profile. That is why discovery alone is insufficient. Once an organisation finds the tools, it still has to determine what normal behaviour looks like for each actor type and where sanctioned activity ends. Behavioural monitoring becomes the control that bridges inventory and policy enforcement.
Practical implication: Build behavioural baselines for AI accounts and agents so monitoring can flag scope drift, not merely log activity after the fact.
Threat narrative
Attacker objective: To gain durable access through unmanaged AI pathways that enable data exfiltration, unauthorized action, and hidden persistence under the cover of legitimate-looking identity activity.
- Entry occurs when employees or teams adopt AI tools, extensions, or agents outside approved governance, often through downloads, trials, or signups that bypass central inventory.
- Credential exposure follows when those tools or workflows use hardcoded, copied, or leaked AI secrets and API keys, creating persistent access paths in public repositories or other uncontrolled locations.
- Escalation happens when an AI actor or shadow AI tool uses the exposed credentials to query data, read email, access repositories, or act inside business systems at machine speed.
- Impact is the loss of data, control, and attribution, where the resulting activity can look indistinguishable from account takeover and expands the enterprise attack surface.
Breaches seen in the wild
- Vercel Context.ai OAuth Supply Chain Breach: Shadow AI app Context.ai OAuth integration exposes Vercel customer data via unmanaged third-party token.
- OmniGPT breach claim 2025: A hacker claims to have leaked 34 million OmniGPT AI chat messages holding users' API keys and credentials; OmniGPT has not confirmed it.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Human-first IAM is no longer a complete identity model. The article’s core claim is not simply that AI is changing workflows, but that enterprise controls still assume the actor is a person with predictable lifecycle events. That assumption fails when a non-human identity can execute work, call tools, and access data without fitting HR-centric governance. Practitioner takeaway: identity policy has to classify AI actors as governed subjects, not just applications.
Shadow AI is an inventory problem only until it becomes a privilege problem. Once unmanaged tools obtain credentials, tokens, or delegated access, the issue is no longer discovery but accountability for what those identities can do. This is exactly where human-first access governance breaks down, because the access path is often created outside formal onboarding. Practitioner takeaway: governance must follow the credential, not just the application.
Abnormal behaviour in AI systems can resemble account takeover because the control plane was built for people. Security teams that rely only on static allowlists, login telemetry, or DLP miss the more important question of whether the actor is staying within its intended task boundary. That is why behavioural analysis becomes the bridge between identity and runtime risk. Practitioner takeaway: baseline intent and scope for AI identities as distinct control objects.
Identity blast radius is the right concept for the AI era. Each new agent, workflow, or tool can multiply the number of systems and datasets reachable before review, and the article’s numbers show that this is happening faster than policy maturity. The security problem is no longer simply access creep but access acceleration. Practitioner takeaway: measure how quickly AI identities can widen their effective reach, not just how often they are reviewed.
Governance cycles built for humans cannot keep pace with machine-speed identity behaviour. Annual policy updates, periodic recertification, and manual approvals were designed for slower, observable human patterns. AI actors collapse that cadence by acting continuously and often invisibly between review points. Practitioner takeaway: align governance to issuance, runtime behaviour, and revocation, because after-the-fact review alone no longer contains the risk.
From our research library:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- One in five organisations reported a breach due to shadow AI, and 97% of those breached through an AI model or application lacked proper AI access controls, according to IBM's 2025 Cost of a Data Breach Report.
- Read next: Shadow AI and AI Agent Discovery Guide
What this signals
Governance teams need a non-human identity boundary, not just an AI policy. The practical shift is to decide which tools, agents, and workflows qualify as governed actors before they accumulate access that outpaces review cycles. Without that boundary, IAM, PAM, and monitoring all end up chasing activity after it has already widened the blast radius.
Identity teams should expect AI credential leakage to behave like a standing access channel. Once secrets are copied into public code, shared notebooks, or unmanaged integrations, the access path can persist long after the original tool is forgotten. That is why ownership, revocation, and behavioural monitoring have to operate together, not in separate programmes.
For practitioners
- Classify AI actors as governed identities Create an explicit inventory of AI systems, agents, and shadow AI tools, and assign each one an owner, purpose, and approval path. Treat unmanaged AI as an identity governance issue, not just a software discovery task.
- Bind credentials to lifecycle ownership Track every AI credential, token, and API key back to a business owner and a revocation process so leaks do not become permanent access paths. Include repository scanning, rotation triggers, and offboarding for abandoned tools.
- Baseline behavioural scope for each AI identity Define expected actions, data boundaries, and tool usage for sanctioned AI actors, then alert on new paths, unusual timing, or expanded resource access. The goal is to detect scope drift before it is misread as ordinary usage.
- Separate human and non-human policy enforcement Do not apply the same review and approval mechanics to people and AI actors. Build policy branches that recognise machine-speed execution, delegated access, and the absence of HR-driven lifecycle events.
Key takeaways
- AI agents and shadow AI are forcing IAM to treat non-human actors as governed identities rather than treating them as ordinary software.
- The article points to a widening gap between rapid AI adoption, weak policy coverage, and exposed credentials that can be reused for unauthorized access.
- The practical answer is to combine identity ownership, credential lifecycle control, and behavioural monitoring so AI access is governed at runtime, not only after discovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on AI agents gaining and using access beyond human-first assumptions. |
| Recommendation — Map AI agent access paths to ASI03 and constrain privilege to explicitly approved runtime scope. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article highlights exposed AI credentials and repository leakage as a primary risk driver. |
| NHI-05 — Overprivileged NHI | The piece argues that AI actors often receive more access than their role justifies. | |
| Recommendation — Scan for leaked AI secrets under NHI-02 and revoke any exposed credentials immediately. Review AI access grants against NHI-05 and trim any permissions not needed for the defined task. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle control is central to preventing AI secrets from becoming standing access. |
| Recommendation — Apply IA-5 to rotate, revoke, and track authenticators used by AI systems and agents. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about permission scope and authorisation for human and non-human actors. |
| Recommendation — Use PR.AA-05 to align AI entitlements with documented business purpose and ownership. | ||
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- AI Credential: A credential used by an AI service, model, or pipeline to access data, tools, or billing systems. In practice, it functions like a privileged machine secret and should be governed with ownership, scope, rotation, and revocation controls rather than treated as ordinary configuration.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org