By NHI Mgmt Group Editorial TeamBased on Clutch Security: “The Enterprise Agentic AI Security Crisis No One Is Ready For” (July 2, 2025)

TL;DR: Enterprises are moving from roughly 45 non-human identities per human in 2023 to an 82:1 ratio in 2025, while early adopters report 300% to 500% annual NHI growth as AI agents combine multiple credentials across systems, according to Clutch Security. The identity problem is no longer scale alone; autonomous tool use breaks static provisioning assumptions and makes traditional IAM visibility insufficient.


At a glance

What this is: This is a Clutch Security analysis arguing that agentic AI is accelerating NHI sprawl by driving many more credentials, tokens, and service accounts into enterprise workflows.

Why it matters: It matters because IAM, IGA, and PAM programmes built for stable, human-paced access provisioning will miss how autonomous tools select and combine credentials at runtime.

By the numbers:

  • Enterprises typically managed about 45 NHIs per human identity in 2023, according to Clutch Security.
  • Early adopters are seeing 300% to 500% annual NHI growth as agentic AI spreads, according to Clutch Security.
  • In 2025, an 82:1 ratio is the new reality for NHIs to human identities, according to Clutch Security.

Context

Agentic AI changes identity governance because the actor is no longer a fixed workflow or a single service account. The system can interpret a request, choose tools at runtime, and draw on multiple credentials in one task, which breaks the assumptions behind static provisioning and human-paced approval cycles.

Clutch Security's article argues that this is not just an NHI volume problem. It is a governance problem created by autonomous tool use, shadow deployments, and write-enabled access paths that traditional IAM visibility does not model well.

The article's starting position is atypical only in its speed, not in its underlying pattern: enterprise identity sprawl was already growing, but agentic AI compresses that growth into a much shorter operational window.


Key questions

Q: What breaks when agentic AI is allowed to act with embedded credentials?

A: The control problem changes from isolated secret protection to governed runtime access. Embedded credentials let agents reach SaaS applications, internal systems, or code execution paths without the usual visibility into who owns the access, what it can reach, or when it should be revoked. The result is hidden privilege accumulation.

Q: Why do read-only AI agents still create serious security risk?

A: Read-only agents can still expose secrets, topology, environment variables, and other sensitive operational data. In practice, disclosure often creates the same downstream risk as modification because attackers can use the information for lateral movement, credential theft, or targeted follow-on attacks. Security teams should govern read-only access as a data-exposure path.

Q: How do security teams know whether an agent identity is actually governed?

A: An agent identity is governed only when teams can identify the owner, locate the credentials, define the allowed scope, and revoke access without hunting across endpoints or backup files. If any of those pieces are missing, the identity is partially shadowed. The practical signal is whether access can be answered in minutes, not days.

Q: What do IAM teams get wrong when they treat AI agents like service accounts?

A: They assume an agent is just another fixed non-human identity, when its behaviour may be runtime-driven and tool-selecting. That can lead to under-scoped oversight, misplaced trust in static entitlements, and review processes that do not match how the actor actually operates.


Technical breakdown

Why agentic AI multiplies NHI sprawl

Agentic systems can combine multiple credentials across systems to complete a task, which means one runtime session may touch a database token, a cloud key, and an API credential in sequence. That is materially different from traditional automation, where the credential path is usually fixed in advance. The security problem is not only inventory growth, but the loss of predictability around which credential will be used next, for what system, and under which contextual trigger. Once the agent reasons over multiple steps, identity scope becomes a moving target rather than a provisioning decision.

Practical implication: Model agent workflows as credential consumers with changing scope, not as static service accounts.

Write permissions turn identity growth into blast radius

Read-only agents can leak data, but write-enabled agents can change state across systems and propagate errors at machine speed. In practice, write access creates compound risk because one bad interpretation can trigger downstream updates, configuration drift, or financial actions that are hard to unwind. The key technical point is that the danger comes from both privilege breadth and the speed of chained actions. Traditional review controls are too slow when the credential can be used, combined, and discarded within a single task window.

Practical implication: Treat write access as a separate governance tier with much tighter issuance and approval rules.

Shadow agents and unmanaged credentials

Shadow AI appears when agents are deployed without central approval, inventory, or lifecycle management. In that state, credentials become invisible assets: they are created for convenience, reused across experiments, and left behind when the experiment ends. The result is a mix of exposed tokens, missing ownership, and no dependable offboarding path. This is an NHI problem because the credential, not the model, is what carries the operational risk. If the organisation cannot enumerate the agent and its secrets, it cannot govern the access path that the agent depends on.

Practical implication: Inventory every agent, then tie each one to explicit credential ownership and revocation workflows.


Threat narrative

Attacker objective: The objective is to obtain broad, hard-to-audit operational control through credentials that an autonomous system can chain together faster than humans can govern.

  1. Entry occurs when an unmanaged or sanctioned agent is given access to multiple systems through API keys, service accounts, or tokens.
  2. Credential access expands as the agent selects additional credentials at runtime to satisfy a multi-intent request.
  3. Escalation follows when write permissions let the agent trigger changes across interconnected systems, increasing the blast radius of one task.
  4. Impact appears as uncontrolled data exposure, broken data propagation, or unauthorized financial or configuration changes that are difficult to trace back.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic AI creates an identity problem before it creates an AI governance problem. The article shows that autonomous tool use increases the number of credentials in circulation and changes how those credentials are consumed at runtime. That means the immediate governance issue is not model quality, but whether IAM can still enumerate, scope, and revoke identities that do not behave like users or scripts.

Static provisioning is the wrong mental model for autonomous access. Least privilege was designed for access that can be defined at issuance and reviewed later. That assumption fails when an agent dynamically selects tools and credentials during execution. The implication is that identity governance has to move from assignment-time thinking to runtime control of what an agent can combine.

Shadow agents are a lifecycle failure, not just a discovery gap. Unmanaged agents create NHIs without clear ownership, offboarding, or traceability, which means the organisation loses the ability to certify or retire the access path at all. The decisive issue is not whether the agent was approved once, but whether its credentials remain governable after deployment.

Write privileges are becoming the main determinant of identity blast radius. Read access creates exposure, but write access turns identity misuse into system state change, which is where recovery cost rises sharply. The control question for the field is no longer how many NHIs exist, but how many of them can alter business records, configurations, or transactions.

Identity teams need a distinct governance model for autonomous actors. The article reinforces that AI agents should not be treated as enhanced users or ordinary service accounts. Their ability to reason, select tools, and chain credentials across systems means the field needs explicit agent identity governance, not just expanded NHI inventory management.

From our research library:

What this signals

Credential chaining is the new identity risk pattern. The central governance issue is no longer whether an organisation has NHIs, but whether an autonomous actor can combine several of them inside one task. That shifts priority from simple inventory to runtime boundaries, because the harm appears when credentials are composable rather than merely present.

Agent identity governance now needs blast-radius thinking. Traditional review cycles assume privilege persists long enough to be observed and certified. Agentic behaviour compresses that window, so the control objective becomes constraining what can be combined, changed, or written during execution rather than relying on after-the-fact review.

82:1 is not a maturity badge, it is a governance warning. According to the Ultimate Guide to NHIs, 82:1 is the new reality for NHIs to human identities, and that ratio becomes harder to govern when agents are the mechanism multiplying credentials across systems.


For practitioners

  • Inventory every agent and its credentials Build a current register of sanctioned and unsanctioned agents, then map each one to the tokens, service accounts, and API keys it can use.
  • Separate read and write access paths Give agents read-only access by default and require stronger approval and tighter scope for any write-capable workflow that can change state.
  • Tie each NHI to an owner and an offboarding path Require explicit ownership, lifecycle dates, and revocation procedures for every agent credential so shadow deployments cannot persist indefinitely.
  • Review runtime credential combinations Identify workflows where one agent can chain multiple credentials across systems, then isolate the combinations that create the largest blast radius.
  • Move governance checks closer to issuance Use real-time controls and anomaly detection where access decisions are made, because post-hoc review will miss short-lived autonomous activity.

Key takeaways

  • Agentic AI is accelerating NHI sprawl by making one runtime actor consume multiple credentials across systems.
  • The real control failure is not just scale, but the loss of predictable credential paths and reviewable privilege windows.
  • Identity teams need ownership, lifecycle, and runtime boundary controls before agentic workflows become normalised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseAgentic systems in this article dynamically combine tools and credentials at runtime.
Recommendation — Restrict tool combinations and runtime action scope for autonomous agents.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centers on agents accumulating more access than their task requires.
NHI-07 — Long-Lived SecretsShadow agents and unmanaged credentials increase the persistence of exploitable secrets.
Recommendation — Reduce agent privilege to the smallest credential set needed for each task. Shorten secret lifetime and revoke agent credentials on every ownership change.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThis is fundamentally about how entitlements are issued and bounded for non-human actors.
Recommendation — Map every agent entitlement to an approved business purpose and review its scope.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe risk path is credential accumulation followed by cross-system movement.
Recommendation — Hunt for credential chaining and lateral use of agent-held identities across systems.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Credential Chain: A credential chain is the sequence of identities, tokens, sessions, and secrets an attacker can reuse after an initial compromise. The concept matters because one exposed password or API key often leads to broader access, especially when human and non-human credentials are not governed together.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org