By NHI Mgmt Group Editorial TeamBased on Lumos: “AI, Automation, and Risk in 2026” (November 1, 2025)

TL;DR: Identity security is at a breaking point, with leaders reporting low preparedness, ongoing identity-related incidents, and rising expectations that AI will reshape detection and response across IGA, NHI, and least-privilege programmes, according to Lumos’ 2026 research. The real issue is not more automation, but governance models that still assume identity risk is slow, visible, and human-paced.


At a glance

What this is: This is Lumos’ 2026 identity research on AI, automation, and risk, arguing that legacy IAM models are colliding with faster identity attacks, dormant account exposure, lateral movement, and growing NHI risk.

Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now have to govern identity-driven attacks that move faster than manual review cycles and increasingly depend on AI-assisted detection and response.


Context

Identity risk is no longer just about who has access. It now includes how quickly attackers can weaponise accounts, credentials, and non-human access paths before governance teams notice.

Lumos frames the problem as a gap between perceived readiness and real operational resilience. That gap matters for identity governance because the same manual controls used for human access reviews are increasingly expected to cover dormant accounts, lateral movement paths, and NHI estates.

The central question is whether current IAM models still fit an environment where identity attacks are faster, more automated, and less visible than the processes designed to stop them.


Key questions

Q: Why do current IAM controls fail when identity attacks move faster than review cycles?

A: Current IAM controls fail because they assume privilege exists long enough to be reviewed, challenged, and removed through human-paced processes. Attackers using valid identities, dormant accounts, or standing access can often exploit that gap before recertification or ticket-based approval has any effect. The issue is not visibility alone, but the mismatch between attack speed and governance speed.

Q: When should organisations prioritise AI-driven identity detection over more manual access review?

A: Organisations should prioritise AI-driven detection when manual review cannot keep pace with identity anomaly volume, lateral movement risk, or rapid entitlement changes. AI is most useful when the goal is to surface unusual access patterns and accelerate decision-making, not to replace poor identity hygiene. If the identity inventory is incomplete, AI will only automate ambiguity faster.

Q: What breaks when non-human identities are not governed like human accounts?

A: Service accounts, API keys, tokens, and AI agents can retain access long after the original task ends because they do not naturally pass through joiner-mover-leaver processes. That creates hidden privilege accumulation, weak ownership, and poor revocation discipline. The result is broader attack surface and slower response when access needs to be removed.

Q: How do security teams know whether identity governance is reducing risk?

A: Look for shorter time from access change to visibility, fewer unmanaged entitlements, and faster completion of review and remediation cycles. If access risk remains unchanged after deployment, the programme may be reporting activity without changing control outcomes.


Technical breakdown

Why identity attacks now outrun manual governance

Identity attacks exploit the speed gap between compromise and review. In practice, attackers use valid accounts, dormant identities, or over-permissioned access to move laterally before access recertification, ticket-driven approval, or periodic review can intervene. That makes the control failure temporal as much as technical. Legacy IAM assumes identity risk can be observed, queued, and remediated on a human schedule, but modern attack paths compress that window. Practical implication: shift governance attention from periodic review alone to controls that reduce the lifetime and usefulness of exposed identity paths.

Practical implication: reduce the time an identity path remains exploitable, not just the time it remains documented.

How AI changes identity detection and response

AI in identity security is not only about automation volume, but about decision support at machine speed. Detection engines can correlate behavioural signals, access anomalies, and policy context faster than manual triage, while response tooling can recommend or trigger access changes more quickly than conventional service desk workflows. That matters because identity incidents often start with subtle anomalies rather than obvious compromise. The architectural shift is from static entitlement management to risk-aware operations that can assess context continuously. Practical implication: treat AI as a governance accelerator only if the underlying identity inventory, policy model, and exception handling are already reliable.

Practical implication: use AI to compress decision time, but only after identity data quality and policy logic are trustworthy.

The non-human identity problem is now part of the identity stack

Non-human identities are no longer a side concern. Service accounts, tokens, API keys, and automated workflows often hold persistent access that is difficult to certify through human-centric review processes. Their risk profile is different because they do not forget, self-report, or exit through normal employee offboarding. That creates governance blind spots when the organisation applies joiner-mover-leaver logic designed for people. Practical implication: classify machine identities as first-class subjects in IAM and lifecycle governance, with ownership, rotation, and revocation controls that match their operational role.

Practical implication: govern NHI access as a separate lifecycle problem, not as a subset of human access administration.


Threat narrative

Attacker objective: The attacker’s objective is to turn legitimate-looking identity access into broad lateral movement and high-value compromise before defenders can contain it.

  1. Entry begins with identity as the attacker’s primary access route, often through dormant accounts, reused credentials, or another valid identity foothold rather than obvious malware.
  2. Credential access and privilege use then widen the attacker’s reach, especially when standing access or poorly scoped permissions let them move laterally through connected systems.
  3. Impact follows when identity-driven movement reaches sensitive data, administrative functions, or operational workflows before detection and response can interrupt the chain.
  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity security has crossed from governance problem to execution problem. The article’s core signal is that identity attacks now outpace the cadence of traditional access governance. That means the old assumption, that review cycles can catch the dangerous identity before it is abused, is no longer reliable. Practitioners should read this as a shift from policy sufficiency to operational containment.

Preparedness reporting is a weak proxy for actual identity resilience. A team can be compliant, reviewed, and still exposed if dormant accounts, lateral movement paths, and standing privilege remain viable. The field needs to stop treating access certification as proof of control effectiveness. Instead, it should ask whether identity governance measurably reduces reachable privilege under attack conditions.

Non-human identities now define the edge of IAM maturity. Service accounts, automation tokens, and workload credentials are where human-centric governance models most visibly break down. Their lifecycle does not match employee offboarding, their access often persists without meaningful review, and their abuse does not depend on a user being fooled. That makes NHI governance a baseline maturity test for modern identity programmes.

Identity blast radius is the right organising concept for 2026. The question is no longer whether an identity can be managed, but how much damage it can do before containment. This reframes IAM, IGA, and PAM around exposure scope, entitlement concentration, and response speed. Teams should treat blast-radius reduction as the practical measure of whether identity security is keeping up.

What this signals

Identity programmes are entering a phase where the key measure is no longer control presence but how fast a single identity compromise can be contained. The practical shift is toward reducing standing privilege, shrinking reachable access, and instrumenting anomaly response before lateral movement completes.

Identity blast radius: if an organisation cannot explain the maximum damage one account can cause, it does not yet have a useful identity risk model. That question now applies equally to human users, service accounts, and automated access paths.


For practitioners

  • Measure identity blast radius Map the maximum reachable systems, data, and administrative functions behind each high-risk account, then rank identities by the damage they can cause before containment.
  • Separate NHI governance from human access review Create ownership, rotation, and revocation workflows for service accounts, tokens, and API keys that do not depend on employee-centric joiner-mover-leaver logic.
  • Shorten the lifetime of standing privilege Replace persistent elevated access with task-scoped or time-bound entitlement patterns wherever operationally possible, especially for administrative and cross-system access paths.
  • Use AI for anomaly triage, not policy excuses Apply AI to prioritise unusual access behaviour and speed up response, but only after identity data quality, entitlement inventory, and exception handling are dependable.
  • Test whether one account can still move laterally Run scenario-based reviews against dormant users, privileged service accounts, and overbroad entitlements to see whether a single compromise can still traverse core environments.

Key takeaways

  • The article’s central warning is that identity risk is moving faster than governance processes built for slower, human-paced review cycles.
  • Its strongest evidence is the combination of low reported preparedness, ongoing identity incidents, and rising expectation that AI will matter to detection and response.
  • The practical response is to reduce standing privilege, govern non-human identities as a separate lifecycle, and measure blast radius instead of process completion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on standing privilege, dormant access, and machine identities with excessive reach.
NHI-07 — Long-Lived SecretsLong-lived secrets and persistent credentials are implied by the article's focus on dormant access and exposure windows.
NHI-01 — Improper OffboardingThe article highlights dormant accounts and access that outlives normal lifecycle controls.
Recommendation — Reduce excessive NHI entitlement scope and remove persistent access from service accounts and automation tokens. Shorten secret lifetime and enforce rotation for credentials that can remain valid after users or systems change. Tie offboarding to revocation of all human and machine access paths before accounts become dormant.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about whether identity entitlements are governed tightly enough to withstand attack.
Recommendation — Continuously review entitlements and remove access that exceeds current business need or attack tolerance.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article explicitly refers to identity-driven attacks, dormant accounts, and lateral attacks.
Recommendation — Map identity attack scenarios to credential access and lateral movement to improve detections and containment.

Key terms

  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Access Recertification: Access recertification is the periodic review of user or account permissions to confirm that access is still justified. It is useful, but it is not enough on its own because it reacts after entitlements already exist, which is why lifecycle governance must reduce the volume of exceptions before review time.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org