TL;DR: Non-human identities often outnumber human identities by 50:1 or more while 85% of organisations are already using or piloting agentic AI, according to Omada Identity’s 2026 State of Identity Governance report based on research with 577 identity, IAM, and cybersecurity leaders. Governance now has to catch up to machine-scale identity exposure, not just measure operational throughput.
At a glance
What this is: Omada Identity’s annual governance report says identity environments are scaling through automation, NHIs, and agentic AI faster than governance visibility and accountability are keeping pace.
Why it matters: That matters because IAM, PAM, and IGA teams need leading indicators of privilege, ownership, and revocation timing before machine-scale identity growth turns into persistent exposure.
By the numbers:
- The report is based on primary research with 577 identity, access management, and cybersecurity leaders.
- Non-human identities now outnumber human identities in most organisations, often by factors of 50:1 or more.
Context
Identity governance is the discipline that decides who or what can access what, for how long, and under whose accountability. In this report, the governance gap is not about whether organisations are adopting automation, NHIs, or agentic AI. It is about whether current identity programmes can still explain ownership, privilege coverage, and revocation timing as identity volume and autonomy increase.
Omada Identity’s research also shows a familiar reporting blind spot. Executives are tracking operational activity such as provisioning speed and audit readiness, while fewer organisations consistently measure leading indicators like orphaned accounts and time to revoke access. That gap matters because machine-scale identity growth changes the control problem from administering access to proving that access is still governed.
The report also links Zero Trust adoption to a second-order challenge: interoperability across identity and security platforms. When visibility is fragmented, governance becomes a set of disconnected activity reports rather than a continuous control layer. For most programmes, that is now a structural issue, not a dashboard problem.
Key questions
Q: What breaks when identity governance can only see provisioning, not live use?
A: Governance breaks at the point where approved access diverges from actual behaviour. Provisioning records can show that an identity was allowed to act, but they cannot prove that every runtime action stayed within the intended scope. That is why runtime telemetry matters for NHI, service accounts, and AI agents that can cross system boundaries quickly.
Q: Why do NHIs create more governance risk than human accounts?
A: NHIs usually run non-interactively, can be copied across systems, and often persist longer than the workload they serve. That combination makes them harder to notice and easier to overprivilege. The risk is not only compromise, but also forgotten credentials, unclear ownership, and weak offboarding.
A: Teams should measure operational outcomes, not just response time. Useful signals include approval accuracy, exception rates, policy violations prevented, reduction in manual review effort, and the completeness of audit evidence. If automation is working, it should shorten cycle times while preserving review quality, control consistency, and the ability to explain every access decision.
Q: What should organisations do when Zero Trust reporting cannot unify identity data?
A: Treat fragmented reporting as a control gap, not a dashboard issue. If identity state, access scope, and revocation timing cannot be reconciled across platforms, continuous verification is incomplete. The programme should not claim full governance coverage until those views are joined.
Technical breakdown
Why machine-scale identity breaks traditional governance reporting
Traditional identity governance assumes the programme can enumerate identities, map ownership, and certify access before risk changes materially. That assumption weakens when NHIs outnumber humans by orders of magnitude and agentic systems can appear, act, and disappear across workflows faster than a review cycle can close. In that environment, provisioning reports are lagging indicators and audit readiness says little about live exposure. The control problem shifts from counting activity to proving authority, lineage, and revocation state across a far larger identity estate.
Practical implication: Treat access reporting as insufficient unless it also shows ownership, privilege scope, and revocation status in near real time.
Why agentic AI raises the bar for identity governance
Agentic AI is not just another workload because it can change tools, timing, and execution paths during runtime. Even when the article does not describe full autonomy, the governance challenge is still different from standard automation: policy intent may exist, but operational execution can diverge across identities, credentials, and delegated actions. That makes unique identity assignment, credential rotation, and accountability mapping central to governance design. If the control model only understands static users and service accounts, it will miss where agent behaviour changes the trust boundary.
Why ownership becomes the real control plane for NHIs
NHIs are not governed effectively when responsibility is split across platform teams, application owners, and security operations without a single accountable model. The report’s finding that ownership is distributed across multiple teams explains why orphaned accounts and weak revocation tracking persist. Governance breaks when no one can answer who approves creation, who renews access, and who removes it. In practice, accountability is the prerequisite for visibility, not the result of it.
Practical implication: Assign a single accountable owner to each NHI class and make orphaned-account review a governance metric, not an afterthought.
Threat narrative
Attacker objective: Exploit governance blind spots created by identity sprawl, weak ownership, and delayed revocation to keep access active longer than defenders expect.
- Entry begins with rapid expansion of automation, NHIs, and agentic AI into identity estates faster than governance processes can classify them.
- Escalation occurs when ownership, privileged access coverage, and revocation timing are not consistently tracked, leaving active identities outside effective review.
- Impact follows as fragmented visibility obscures who or what still has access, increasing the chance of persistent exposure, compliance gaps, and breach-prone identity sprawl.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity governance is becoming a control-layer problem, not a reporting problem. The report shows that organisations can be confident in their programmes while still failing to track the metrics that actually reveal exposure. Provisioning speed and audit readiness matter, but they do not prove ownership, privilege scope, or revocation discipline. Practitioners should treat governance as continuous control validation, not activity summarisation.
Machine-scale identity has created an identity exposure gap. When NHIs outnumber humans by factors of 50:1 or more, the old assumption that governance can keep up through periodic review breaks down. The problem is not just volume. It is that ownership and accountability fragment across teams, so risk becomes distributed faster than review processes can converge on it. Identity teams need a model that ties every machine credential to an accountable owner and a revocation path.
Agentic AI is forcing identity programmes to move from entitlement management to runtime accountability. A unique identity and rotating credentials are useful only if the operational model can prove who approved, who owns, and who can revoke the access behind the agent. The gap between policy intent and operational execution is now the central governance challenge. Practitioners should assume that static governance artefacts will understate real exposure in agentic workflows.
Zero Trust without unified identity visibility becomes a partial control, not a complete model. The report’s interoperability finding matters because fragmented identity and security data prevents consistent reporting across human, machine, and agentic identities. That does not invalidate Zero Trust. It means practitioners must test whether their architecture can actually reconcile identity state across platforms before claiming continuous verification.
Continuous identity governance is the new baseline for modern estates. As identity becomes the operational layer for automation and AI-enabled workflows, governance has to measure live authority, not just completed tasks. That shift aligns most directly with OWASP-NHI and NIST CSF thinking about access governance and continuous monitoring. The practitioner takeaway is clear: if the programme cannot describe current exposure, it cannot claim current control.
From our research library:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs
What this signals
Machine-scale identity changes the governance unit of measure. When NHIs and agentic systems grow faster than the review cycle, programmes that still centre on provisioning throughput will understate exposure. The control question shifts to whether the organisation can continuously prove ownership, privilege scope, and revocation state across the full identity estate.
Identity governance is now a runtime discipline. Static reporting cannot keep up with identities that are created, delegated, and retired by automation across multiple platforms. That is why the programme has to move from periodic assurance to continuous visibility over access state, especially where agentic workflows are in play.
Identity exposure debt: this is the accumulating gap between the identities organisations deploy and the governance evidence they can actually produce. As that debt rises, leaders may remain confident while the control plane becomes less trustworthy for humans, machines, and AI-driven workflows alike.
For practitioners
- Measure leading identity risk indicators Track privileged access coverage, orphaned accounts, and time to revoke access alongside provisioning and audit metrics so governance reflects exposure, not just activity.
- Assign explicit ownership for every NHI class Create a named accountable owner for each service account, token set, and agentic workflow so renewal, approval, and removal decisions are not spread across multiple teams.
- Validate governance controls against agentic workflows Test whether unique identities, rotating credentials, and approval paths still hold when an AI-driven workflow moves across tools and identities during execution.
- Reconcile identity and security data into one view Check whether Zero Trust reporting can join identity state, access scope, and revocation timing across platforms without manual stitching or delayed exports.
Key takeaways
- Non-human and agentic identities are scaling faster than the governance evidence most organisations use to judge their own control maturity.
- The core weakness is not adoption of automation or Zero Trust, but the loss of reliable ownership, revocation, and privileged access visibility.
- Identity programmes now need continuous accountability metrics, or they will keep reporting activity while missing exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on governance blind spots around NHI privilege, ownership, and revocation. |
| NHI-01 — Improper Offboarding | Orphaned accounts and revocation timing are central signals in the report's governance gap. | |
| Recommendation — Map NHI estates to NHI-05 and review where privilege exists without clear ownership or timely removal. Apply NHI-01 to detect identities that remain active after ownership or business need has ended. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The report highlights weak tracking of privileged access coverage and entitlement visibility. |
| DE.CM-01 — Monitoring for Security Events | The article frames identity governance as continuous visibility over exposure and revocation state. | |
| Recommendation — Use PR.AA-05 to maintain current entitlement visibility and verify access scope against ownership. Implement DE.CM-01 to monitor identity state changes and flag stale or orphaned access quickly. | ||
| NIST Zero Trust (SP 800-207) | Continuous Verification | Zero Trust adoption is central, but the article shows visibility gaps blocking consistent verification. |
| Recommendation — Design continuous verification so identity, access, and revocation state stay unified across platforms. | ||
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- Agentic AI Identity: The complete set of credentials, permissions, and governance controls applied to an autonomous AI agent, covering authentication, authorisation, action logging, and access revocation. Distinct from traditional NHI because agent identities are often ephemeral, delegated, and multi-hop.
- Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
- Privilege coverage: Privilege coverage measures how completely an organisation can see and govern elevated access across its identity estate. It is a leading indicator because a programme can have strong activity metrics while still missing high-risk access paths, especially among NHIs and agentic workflows.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org