By NHI Mgmt Group Editorial TeamBased on Keeper Security: “Why AI Infrastructure Growth Demands Next-Gen Cybersecurity and PAM” (July 25, 2025)

TL;DR: Global AI infrastructure spending is set to exceed $200 billion by 2028, while AI-specific data centres could drive almost half of U.S. electricity demand growth through 2030, and expanding hybrid AI stacks are widening privileged access gaps, according to Keeper Security. Identity-centred PAM, not perimeter security, becomes the control plane for AI infrastructure.


At a glance

What this is: This is a Keeper Security analysis of how rapid AI infrastructure expansion increases privileged access exposure across hybrid and cloud environments.

Why it matters: It matters because IAM, PAM, and NHI teams have to govern privileged access, secrets, and session control around AI workloads before the attack surface outgrows legacy perimeter models.

By the numbers:

  • Global AI infrastructure spending is projected to surpass $200 billion by 2028.
  • U.S. AI-specific data centres could account for almost half of the country's electricity demand growth through 2030.

Context

AI infrastructure now means the GPUs, accelerators, data pipelines, APIs, and cloud services that support model training and runtime operations. As those components scale, the security problem shifts from protecting a bounded environment to governing privileged access across a fast-changing, hybrid control plane.

Keeper Security's article argues that traditional perimeter controls do not provide enough visibility or access control for AI-driven environments. The operational issue is not only more compute and more data exchange, but also more privileged users, more secrets, and more opportunities for standing access to persist longer than intended.


Key questions

Q: Why do AI infrastructure environments need PAM instead of perimeter security alone?

A: AI infrastructure spreads privileged activity across cloud services, APIs, GPUs, and administrative tooling, so the network edge is no longer the best control point. PAM matters because it governs who can do what inside the environment, how long access lasts, and whether privileged sessions are visible and reviewable.

Q: What breaks when API keys and privileged credentials are left unmanaged in AI-driven environments?

A: Unmanaged API keys and privileged credentials create hidden access paths that are hard to inventory, revoke, or audit. In AI-driven environments, that can let agents reach systems beyond their intended scope, expose sensitive data, and turn a single secret into broad lateral access. The control failure is usually governance, not just technology.

Q: How should organisations handle identity and secrets risk in AI-assisted pipelines?

A: Treat AI-generated code as a higher-volume source of identity and secrets exposure. That means continuous secret scanning, tighter approval for code touching access logic, and faster remediation of risky dependencies. The goal is to keep credentials, service identities, and access assumptions from scaling faster than the controls around them.

Q: Should organisations prioritise JIT access or session recording first for AI workloads?

A: JIT access should come first when the main problem is persistent privilege, because it removes unnecessary standing access before a session begins. Session recording adds a second layer of accountability, but it does not reduce exposure if access remains permanently available.


Technical breakdown

Why AI infrastructure expands the privileged access surface

AI infrastructure is not a single system. It is a layered stack of compute, orchestration, data movement, APIs, and administrative tooling that spans cloud and on-premise environments. Each layer introduces privileged paths for engineers, administrators, automation accounts, and service integrations. That makes access governance harder because the control plane is distributed across provisioning, model operations, and runtime administration. When access is granted broadly to keep AI workloads moving, the blast radius of a compromise grows with the stack itself.

Practical implication: treat AI infrastructure as a privileged-access domain, not just a workload platform.

How standing access and exposed secrets increase AI risk

The article highlights two recurring failure modes: standing privilege and secrets embedded in scripts or configuration files. Standing access gives privileged users a persistent path into systems that may only need temporary access for setup, troubleshooting, or model operations. Exposed secrets make that path reusable by anyone who finds them. In AI environments, those weaknesses matter more because training pipelines, APIs, and datasets often connect many systems at once, so one credential can unlock broad operational reach.

Practical implication: reduce always-on access and remove any secrets that are stored where tooling, logs, or scripts can expose them.

Why identity-centred PAM outperforms perimeter control in AI stacks

Perimeter security assumes the network edge is the main decision point. AI infrastructure breaks that assumption because access decisions now happen inside cloud services, ephemeral sessions, and delegated workflows. Modern PAM shifts control to the identity layer through just-in-time access, session monitoring, secrets management, and continuous validation. That matters because privileged activity in AI environments is often temporary, distributed, and difficult to spot from network controls alone. The access decision, not the network boundary, becomes the meaningful security event.

Practical implication: place authorization, session oversight, and secret lifecycle controls where privileged AI work actually happens.


Threat narrative

Attacker objective: The attacker wants broad operational control over AI infrastructure, including privileged systems, sensitive data, and the ability to alter AI outputs.

  1. Entry begins with privileged infrastructure access, often through engineers, admins, DevOps accounts, or exposed secrets embedded in AI scripts and configuration files.
  2. Escalation occurs when standing privilege or overly broad access lets a compromised account move from one AI component to adjacent systems, datasets, or APIs.
  3. Impact follows when the attacker uses that reach to access sensitive systems, corrupt AI outputs, or expand control across hybrid infrastructure.
  • Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI infrastructure privilege sprawl is becoming the new control-plane problem. The security issue is no longer just capacity growth, but the accumulation of privileged paths across GPUs, APIs, cloud services, and administrative tooling. Traditional perimeter logic does not describe this environment well because the decisive control point is identity, not network location. Practitioners should treat AI infrastructure as a privilege-governed domain with a larger blast radius than conventional application stacks.

Standing privilege is the wrong default for AI operations. AI environments need frequent administrative access for deployment, tuning, and troubleshooting, but persistent privilege turns every maintenance path into a durable attack path. That is especially dangerous when AI stacks integrate training pipelines, datasets, and cloud services that can be reached from a single compromised account. The practitioner conclusion is simple: access should be temporary by design, not permanently available for convenience.

Secret exposure in AI pipelines is an identity failure, not just a hygiene issue. When scripts and configuration files contain reusable credentials, the resulting risk is broader than leakage. It creates repeatable privileged reach into the systems that move and shape AI data. That is why AI governance must treat secrets lifecycle, ownership, and rotation as first-class identity controls. The implication is that the credential, not the model, is often the easiest path into the environment.

Identity-centred PAM is now the control layer for AI infrastructure. Just-in-time access, session oversight, and continuous validation are the mechanisms that constrain privileged activity when the environment is dynamic and distributed. This does not eliminate AI risk, but it changes where governance has to happen. The field should expect more convergence between PAM, cloud security, and workload identity governance as AI environments mature.

Identity blast radius is the right concept for AI infrastructure governance. A single privileged identity can now influence compute, data, and model behaviour across multiple environments. That makes access scope a governance metric, not just an operational detail. The practitioner takeaway is to measure how far one credential can reach before it is used, not after an incident proves the path.

From our research library:

What this signals

AI infrastructure changes the unit of governance from the server to the credential. As model operations spread across cloud services, APIs, and ephemeral compute, the security team has to control who can reach what, when, and for how long, rather than assuming the perimeter will absorb the risk.

Identity blast radius: the useful way to think about AI infrastructure is as the amount of damage one privileged account can cause before access is revoked. That lens forces PAM, secrets management, and session control into the same operational conversation, because each one limits how far a compromised identity can move.

Security programmes that still treat AI as a workload problem will miss the access-layer failure modes. The practical shift is toward governance of privileged paths, not just infrastructure scale, because the same identities that keep AI running can also become the shortest route into sensitive systems.


For practitioners

  • Map privileged AI access paths Inventory every administrative path into AI infrastructure, including engineers, DevOps accounts, service accounts, API keys, and cloud console roles.
  • Replace standing access with JIT control Use just-in-time access for setup, model maintenance, and troubleshooting so privileged access expires when the task ends.
  • Harden secrets in AI pipelines Find credentials embedded in scripts, notebooks, and configuration files, then move them into governed secrets management with rotation and ownership assigned.
  • Add session oversight to privileged work Record and review administrative sessions that touch training systems, datasets, or cloud control planes so abnormal activity is visible.
  • Validate least privilege across cloud and non-human identities Review whether AI-related service accounts and operational users can reach only the systems they need, and remove broad cross-environment permissions.

Key takeaways

  • AI infrastructure growth is turning privileged access into the primary governance issue because compute, APIs, and cloud services now share the same control plane.
  • Standing access and exposed secrets create repeatable entry paths that can reach datasets, administration tools, and model operations from a single compromised account.
  • PAM, JIT access, secrets lifecycle controls, and session oversight are the controls that actually shrink the attack surface in AI-driven environments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on excessive privileged access across AI infrastructure and non-human systems.
NHI-07 — Long-Lived SecretsThe article warns that secrets in scripts and files create persistent exposure in AI pipelines.
NHI-02 — Secret LeakageIt explicitly states that secrets should not be hardcoded or exposed in configuration files.
Recommendation — Reduce broad AI infrastructure entitlements and scope privileged NHI access to the task being performed. Replace long-lived AI pipeline secrets with governed rotation and short-lived issuance. Scan AI scripts and configuration stores for leaked credentials and remove them from source-controlled paths.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle control is central to the article's discussion of AI secrets and access exposure.
AC-6 — Least PrivilegeThe article repeatedly argues for least-privilege access in AI infrastructure.
Recommendation — Apply IA-5 to manage AI credentials through issuance, rotation, and revocation. Use AC-6 to limit privileged AI access to the minimum needed for each operational task.
NIST Zero Trust (SP 800-207)Continuous verification — Continuous verificationThe article explicitly recommends continuous validation of users, devices, and sessions.
Recommendation — Enforce continuous verification for every privileged AI session before and during access.
CIS Controls v8CIS-5 — Account ManagementThe article is about controlling privileged users, admins, and non-human accounts in AI environments.
Recommendation — Use account management controls to inventory, review, and restrict privileged AI identities.

Key terms

  • AI Infrastructure Platform: An AI infrastructure platform is software that supports teams building and deploying machine learning models themselves rather than embedding AI directly into a business function. These platforms can cover parts of the workflow such as training, evaluation, deployment, monitoring, governance, or explainability, depending on their scope.
  • Privileged Access: Privileged access is any elevated entitlement that can change systems, data, or security settings. When privilege is excessive or poorly scoped, a single compromised identity can create outsized blast radius across environments.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • Secrets Management: The discipline of securely storing, distributing, rotating, and auditing secrets across an organisation's systems and pipelines, typically implemented via a centralised secrets vault such as HashiCorp Vault, AWS Secrets Manager, or Akeyless.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org