By NHI Mgmt Group Editorial TeamBased on Delinea: “Delinea Report Finds 90% of Organizations Pressure Security Teams to Loosen Identity Controls for AI” (March 18, 2026)

TL;DR: AI adoption is pushing 90% of organisations to loosen identity controls, even as 80% say they cannot always explain why an NHI performed a privileged action and 59% lack alternatives to standing access, according to Delinea research. The governance problem is no longer visibility in the abstract; it is whether identity programmes can keep pace with AI-driven privilege use without weakening control boundaries.


At a glance

What this is: This is Delinea's research on how AI adoption is pushing organisations to relax identity controls, with visibility gaps, standing access, and weak accountability emerging as the core governance issues.

Why it matters: It matters because IAM teams now have to govern human, machine, and agentic AI access under the same control model while AI programmes are actively pressuring them to widen privilege boundaries.

By the numbers:

  • 90% of organizations pressure security teams to loosen identity controls to enable AI initiatives.
  • 80% of organizations say they are unable to always understand why an NHI performed a privileged action.
  • 59% of organizations report lacking viable alternatives to standing privileged access for NHIs and AI agents.
  • 42% of organizations say AI expansion has been one of the top factors increasing NHI risk in the past 12 months.

Context

AI identity control is the governance problem that appears when organisations expand AI use faster than they can maintain access boundaries, auditability, and privilege discipline. In this article, the primary issue is not AI capability itself but the pressure it places on NHI and IAM programmes to relax controls before governance has adapted.

Delinea's research frames that pressure as a measurable trade-off: teams are being asked to make access easier for AI while still proving who or what acted, why it acted, and whether the access was actually necessary. That tension is especially sharp where NHIs and AI agents share production access with human operators.

The article is a market signal as much as a security one. It suggests that AI programmes are already changing identity policy in practice, and that visibility, standing access, and real-time validation are becoming the operational fault lines.


Key questions

Q: What happens when organisations loosen identity controls for AI before governance is ready?

A: They create a gap between deployment speed and control fidelity. AI systems may still function, but privilege becomes harder to explain, limit, and audit. That usually shows up first as standing access, weak traceability, and identity sprawl across NHIs and AI agents that share production permissions.

Q: Why do AI agents and other NHIs create more governance risk than traditional user identities?

A: AI agents and NHIs can scale faster than human accounts, often operate across multiple systems, and may act without direct human review at runtime. That combination increases the chance of overprivilege, orphaned access, and unclear accountability. Governance gets harder when ownership, intent, and access paths are not continuously tracked and enforced.

Q: How do organisations know if AI identity governance is working?

A: They should be able to answer three questions quickly: which agents exist, which credentials each one uses, and who is accountable for each identity’s lifecycle. If any of those answers require manual searching across teams, the governance model is still incomplete and the environment remains difficult to audit.

Q: Should organisations keep standing access for NHIs when AI adoption accelerates?

A: Only as a temporary exception, not as a default operating model. Standing access increases persistent privilege risk and makes it harder to separate legitimate automation from misuse. The better test is whether the organisation can issue access contextually and revoke it when the task ends.


Technical breakdown

Why AI expansion increases NHI risk

AI-driven automation increases the number of identities that can request, inherit, or reuse access in production environments. In practical terms, the risk is not only more credentials, but more identity paths that security teams must inventory, monitor, and govern. The article points to NHIs and AI agents as the largest visibility gap because those identities often operate outside the controls designed for human login patterns. When access decisions are made for speed, identity sprawl follows. Practical implication: treat AI rollout as an identity expansion event, not just a workload deployment.

Practical implication: Map every AI-enabled workflow to its identity dependencies before expanding access scope.

What standing access means for AI agents and NHIs

Standing privileged access gives an identity persistent permissions rather than task-scoped authorization. For NHIs and AI agents, that becomes more dangerous because the actor can use access repeatedly without passing through a fresh governance checkpoint. The article shows that many organisations still have no viable alternative, which means privilege is being left in place because the programme lacks a better issuance model. Practical implication: identify where persistent machine access is being used as a substitute for runtime authorization.

Practical implication: Replace persistent machine permissions with task-scoped access where operationally possible.

Why accountability breaks when privileged actions cannot be explained

Traceability depends on being able to connect an action to an identity, a decision, and a business context. The article's 80% figure signals that many organisations cannot always explain why an NHI performed a privileged action, which means audit evidence is incomplete even when the action was logged. That is a governance failure, not just a logging gap, because the organisation cannot reliably distinguish expected automation from misuse. Practical implication: validate that privileged actions are explainable at the point of execution, not only after the fact.

Practical implication: Require runtime context and approval lineage for privileged NHI activity.


Threat narrative

Attacker objective: Exploit weak identity governance around AI-driven automation to gain persistent, hard-to-explain privileged access across enterprise environments.

  1. Entry occurs when AI initiatives are granted broader identity access and security teams are pressured to loosen control boundaries to keep deployment moving.
  2. Credential access and privilege use follow when NHIs or AI agents operate with persistent permissions that are difficult to distinguish from legitimate automation.
  3. Impact accumulates as organisations lose the ability to explain, validate, and constrain privileged actions across human, machine, and agentic identities.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
  • DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI expansion is now an identity governance pressure test, not a pure technology rollout. The article shows security teams being asked to loosen controls so AI initiatives can move faster, which means the governance model is being shaped by deployment pressure rather than risk tolerance. That is a programme-level problem because the control boundary changes before the identity model is ready.

Standing access has become the default compensation for weak runtime governance. When 59% of organisations say they lack viable alternatives to standing privileged access for NHIs and AI agents, the real issue is not convenience. It is that many IAM programmes still assume persistent privilege is acceptable for non-human execution, which is increasingly incompatible with AI-driven operations.

Traceability gaps are now an accountability gap, not just a visibility gap. If an organisation cannot always explain why an NHI performed a privileged action, then auditability is incomplete even when monitoring exists. The practitioner consequence is that logging alone no longer proves control, especially when automated identities are acting at machine speed.

Identity programmes need a named concept for the new failure mode: control loosening debt. This is the accumulation of governance compromise created when AI adoption repeatedly forces exceptions to identity policy before the programme can replace them with contextual authorization. The longer that debt persists, the harder it becomes to enforce least privilege consistently across human, machine, and agentic identities.

The AI confidence paradox shows that perceived readiness is not the same as governance maturity. Organisations may believe they are ready for AI because they can deploy it, yet still lack discovery, validation, and privilege control in the places that matter most. The practical conclusion is that AI identity governance must be measured by control fidelity, not adoption velocity.

From our research library:

What this signals

Control loosening debt: every exception granted to speed AI adoption increases the distance between policy and actual privilege behaviour. That debt matters because identity programmes are being asked to prove control while simultaneously widening access boundaries, and those two goals quickly collide.

The better operating model is not broader standing access with more monitoring layered on top. It is contextual authorization that can distinguish a legitimate AI action from an over-permissioned one, especially where NHIs and AI agents share production paths.


For practitioners

  • Inventory AI-driven identity paths Map every AI initiative to the human, machine, and agentic identities it creates, inherits, or depends on. Pay special attention to production access, service accounts, and any path that can persist beyond a single task.
  • Replace standing privilege with contextual authorization Use just-in-time issuance and session-based controls where AI workloads currently rely on always-on access. Prioritise any identity that can reach production data or infrastructure without a fresh authorization step.
  • Validate why privileged actions occurred Require a traceable runtime context for every privileged NHI or AI agent action, including policy rationale, session lineage, and approval source where applicable. If the action cannot be explained, treat the governance model as incomplete.
  • Measure AI governance against discovery fidelity Test whether your discovery process can find and validate NHI or AI agent activity in real time, not just on paper. The article shows that discovery confidence can coexist with weak operational validation.

Key takeaways

  • AI adoption is forcing identity teams to relax controls faster than governance models can adapt, which shifts the risk from abstract visibility to operational accountability.
  • The strongest evidence in the article is the combination of 90% pressure to loosen controls, 80% inability to explain privileged NHI actions, and 59% dependence on standing access.
  • Organisations should treat AI identity expansion as a control redesign problem, with runtime authorization and explainability taking priority over access persistence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyAI adoption pressure is a governance and risk appetite problem across identity programmes.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on loosening access controls and weak entitlement discipline.
Recommendation — Set an explicit risk strategy for AI identity expansion before relaxing access boundaries. Continuously review AI entitlements and remove permissions that exceed task necessity.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIStanding access and weak privilege control are central to the article's NHI risk findings.
Recommendation — Shrink NHI privilege scope and eliminate persistent permissions that are not essential.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementPersistent machine access and weak traceability support credential abuse and movement across environments.
Recommendation — Map AI identity exposure to credential access and lateral movement behaviours in detection content.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPersistent machine access points to credential lifecycle control weaknesses.
Recommendation — Enforce authenticator lifecycle controls for AI and machine identities.

Key terms

  • AI-Driven Identity Governance: AI-driven identity governance uses machine analysis to process large volumes of identity data, identify anomalies, and prioritize risky access for human review. It does not replace governance owners. It helps them act on the data they already have by adding pattern recognition, contextual scoring, and decision support at scale.
  • Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Identity Visibility: Identity visibility is the ability to see which identities exist, what they can access, and how those access paths relate across systems. In NHI programmes, it means correlating service accounts, tokens, certificates, and agents into one operational view so governance decisions are based on evidence, not assumptions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org