TL;DR: Identity is now the control plane for cloud, SaaS, and AI systems, but most organisations still cannot inventory or govern the service accounts, API keys, workload identities, and AI agents expanding faster than human users, according to Britive. The runtime control gap is now the real security problem: if access cannot be enforced, observed, and revoked at task speed, least privilege remains theoretical.
At a glance
What this is: Britive argues that identity, not the network perimeter, has become the operative control plane for cloud and AI, with runtime governance now the key gap.
Why it matters: For IAM, PAM, and NHI teams, this matters because the control model must now cover humans, service identities, and AI agents under one runtime authorization approach.
By the numbers:
- Studies across 2025 consistently show that NHIs now outnumber humans by factors ranging from 40:1 to over 100:1, depending on the industry.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
👉 Read Britive's 2026 predictions on identity as the cloud and AI control plane
Context
Identity has become the control plane for cloud and AI because access decisions now govern every workflow, API call, model invocation, and administrative action. The article frames 2026 as the point where runtime authorisation, visibility, and lifecycle governance must work across human users, non-human identities, and AI agents instead of being treated as separate programmes.
The core security gap is not the absence of policies in the abstract, but the inability to see, own, and enforce access on identities that multiply faster than human headcount. That includes service accounts, pipeline tokens, workload identities, and agents that call downstream services through tools such as MCP.
For NHI and IAM teams, the practical issue is that legacy access reviews and static privilege models do not map cleanly to ephemeral, cloud-native, or agent-driven access. The governance question is whether the organisation can explain and control identity behaviour at runtime, not just record it after the fact.
Key questions
Q: How should security teams govern AI models that can call tools and access data?
A: Security teams should govern AI models as non-human identities with named owners, limited scope, short-lived credentials, and continuous authorization. The critical shift is to treat every tool call, data read, and update path as a privileged action that can be logged, revalidated, and revoked. Without that discipline, model risk becomes identity risk.
Q: Why do cloud environments make zero trust harder to enforce?
A: Cloud environments distribute data, automate access, and reuse credentials across tools and services, which weakens perimeter-based assumptions. Zero trust becomes harder because the same identity can be used in many places, often by machines rather than people. That requires continuous authorization, better inventory, and much stricter lifecycle control.
Q: What breaks when organisations rely only on periodic access reviews?
A: Periodic reviews miss access that changes between certification windows, which leaves risk hidden until after the fact. That is a structural weakness when entitlements are dynamic or temporary, because the control is looking backward while the system is changing forward. Teams need real-time signals for the most sensitive access paths.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
Technical breakdown
Why runtime identity control replaces perimeter security
The article treats identity as the operative control plane because cloud and AI systems no longer depend on a stable network boundary. In practice, every sensitive action is authorised through an identity object, whether that object is a human, a service account, a workload credential, or an AI agent. The technical shift is from location-based trust to policy-enforced access at the moment of execution. That requires identity inventory, contextual authorisation, and continuous observability across clouds and SaaS platforms.
Practical implication: teams need a single runtime access model that can authorise actions at execution time rather than relying on perimeter assumptions.
How AI agents inherit identity, policy, and lifecycle boundaries
The article argues that AI agents are not just tools or scripts when they can branch, choose actions, and touch multiple downstream services. They need policies, scoped permissions, human ownership, and offboarding, because they behave like first-class identities in operational systems. This is especially important where an agent uses an LLM plus toolchain to request or invoke services, because the access path is identity-driven even when the reasoning layer is probabilistic.
Practical implication: treat agent access as governed identity state, not as an application setting or model prompt issue.
What just-in-time privilege means in cloud and AI environments
The article presents just-in-time access as the runtime answer to standing privilege, especially for high-risk cloud actions and agent-driven workflows. JIT here means temporary, scoped permission issued for a task and removed automatically when the task ends. That model matters because long-lived admin roles, embedded tokens, and permanent elevations create silent blast radius even when the actor is only intermittently active. The control objective is zero standing privilege at execution time.
Practical implication: replace persistent elevation with task-scoped access that expires automatically across humans, NHIs, and agents.
Threat narrative
Attacker objective: The objective is to exploit invisible or over-privileged identities to gain persistent access to cloud and AI operations.
- Entry begins with identities the organisation has not fully inventoried, including service accounts, API keys, workload identities, pipeline tokens, and AI agents with broad permissions.
- Escalation occurs when unseen identities accumulate standing privilege, ownership remains unclear, and legacy IAM or PAM reviews fail to capture temporary roles or embedded tokens.
- Impact follows when attackers or misbehaving automations can use those identities to reach cloud resources, invoke downstream services, or perform administrative actions without effective runtime restriction.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity as the control plane only works when runtime enforcement replaces static trust: Identity governance built for periodic reviews assumes access can be examined after it exists. Cloud and AI workflows now execute too quickly and across too many systems for that assumption to hold. The practical conclusion is that access control must be enforced at the moment of action, not after entitlement assignment.
Unseen identity sprawl is now the dominant governance problem: Service accounts, workload identities, pipeline tokens, and AI agents outpace human inventories in most environments. That is not just a visibility issue, it is an ownership issue, because anything without an accountable owner becomes impossible to offboard or recertify cleanly. Practitioners should treat unmanaged identity growth as a control-plane defect, not an administrative nuisance.
AI agents become first-class identities only when their access is bounded by policy, not by intention: The article is right to link agent governance with IAM and PAM rather than with model settings alone. Agents that can branch, call tools, and touch downstream services need the same lifecycle discipline as other non-human identities, plus stronger runtime observability. The implication is that AI governance becomes an identity problem before it becomes a model problem.
True zero standing privilege is the practical endpoint of runtime identity security: Standing roles, reusable tokens, and broad service permissions are still the easiest way for identity risk to persist unseen. If access is created when the task begins and removed when it ends, the blast radius shrinks materially across human, NHI, and agent workflows. Practitioners should measure whether privilege actually disappears at task completion, not whether a policy exists on paper.
From our research:
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
- Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities.
- That gap is why the Ultimate Guide to NHIs remains the practical reference for inventory, ownership, rotation, and offboarding.
What this signals
Identity as the control plane becomes real only when organisations can prove that access disappears at task completion. In practice, that means moving from static entitlements to runtime authorisation and measuring whether the privilege window is truly ephemeral. With 70% of organisations granting AI systems more access than human employees, per the 2026 Infrastructure Identity Survey, the governance gap is already structural.
Runtime governance will increasingly be judged by lifecycle discipline, not by policy volume. If service accounts, tokens, and AI agents do not have clear owners and offboarding paths, the control plane will remain partially theoretical. Teams should expect auditors and security leadership to ask whether they can explain every identity’s purpose, scope, and expiry without manual reconstruction.
For practitioners
- Inventory every non-human identity continuously Build a live inventory of service accounts, API keys, workload identities, pipeline tokens, and AI agents across cloud and SaaS platforms. Tie each identity to an owner, purpose, and offboarding path so no account can remain operational without accountability.
- Enforce task-scoped runtime authorisation Replace broad standing permissions with time-bound access issued at the moment of execution and removed automatically when the task ends. Apply the same control model to human administrators, pipelines, and AI agents that invoke downstream services.
- Measure privilege by expiry, not by assignment Track how often high-risk access is created, how quickly it is revoked, and how much unused privilege remains after workflows complete. Use those metrics to identify where zero standing privilege is still only a policy statement.
- Treat AI agents as governed identities Define the allowed action set, human owner, and offboarding procedure for every agent that can branch or call tools. Restrict access through identity policy and identity-level logging rather than model prompts or application-side allow lists.
- Align PAM with cloud-native identity patterns Extend privileged access controls to cloud-native roles, temporary tokens, and automated workflows instead of focusing only on vault-managed passwords. The goal is runtime control over administrative action, not custody of static secrets.
Key takeaways
- Identity governance now has to operate at runtime across humans, NHIs, and AI agents, because perimeter-based assumptions no longer match cloud and SaaS reality.
- The biggest control-plane gap is invisible identity sprawl, where service accounts, tokens, and agents accumulate privilege faster than teams can inventory them.
- Zero standing privilege is the practical standard that will separate real identity control from policy-only programmes in 2026.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The article centres on inventory, ownership, and governance of non-human identities. |
| OWASP Agentic AI Top 10 | AI agents are treated as governed identities with policies and lifecycle controls. | |
| NIST CSF 2.0 | PR.AC-4 | The post is fundamentally about access control at runtime across identity types. |
| NIST Zero Trust (SP 800-207) | Section 3.1 | The runtime authorization model aligns with continuous verification and least privilege. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the central control principle behind runtime identity enforcement. |
Map all service identities and token-bearing actors to NHI-01 and assign an owner before granting access.
Key terms
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
- Identity Inventory: Identity inventory is the process of discovering and recording every identity that can access systems or data. For NHIs, it includes owner, purpose, privilege scope, lifecycle status, and where the credential is used. Without inventory, governance, audit evidence, and incident response all become partial and unreliable.
- AI Agent Lifecycle Governance: The set of controls that assigns, constrains, monitors, and retires autonomous agents across their full operating life. It extends IAM practice to software that can act on its own, making ownership, scope, auditability, and revocation mandatory rather than optional.
What's in the full article
Britive's full blog post covers the operational detail this post intentionally leaves for the source:
- Examples of runtime authorisation patterns for cloud and AI workflows that go beyond standing roles.
- Practical breakdowns of how teams can measure zero standing privilege across humans, NHIs, and agents.
- The article's own view of how PAM, CIEM, ITDR, and AI governance converge in real environments.
- The specific operational implications of treating agents as first-class identities with lifecycle controls.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org