By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SemperisPublished September 4, 2026

TL;DR: As AI adoption reshapes access, resilience, and governance priorities, a survey of 1,100 IT and security professionals across eight countries examines how organizations are managing identity security, according to Semperis. The central issue is not AI novelty but whether identity controls can still govern systems, accounts, and lifecycle processes at the speed modern operations require.


At a glance

What this is: This is Semperis’ survey-based look at identity security in the AI era, with the core finding that organizations are underprepared for the governance demands AI adds to identity resilience.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams now have to govern more identities, more delegation paths, and more machine-driven access with the same control model.

By the numbers:

👉 Read Semperis’ report on identity security in the AI era


Context

AI is changing identity security because more systems now request, broker, or act on access without fitting the old human-centric assumptions of IAM. That creates pressure on governance, lifecycle, and access review processes that were built for stable users and predictable entitlement patterns.

Semperis frames the issue through resilience, but the deeper identity question is whether organizations can still govern access when the actor may be a service account, workload, or AI-enabled workflow. The starting point for most enterprises is typical: they have identity controls, but not yet an identity model that treats human, NHI, and AI-driven access consistently.

The governance gap is not simply about adding another tool layer. It is about aligning identity lifecycle, privileged access, and access review practices to the way access is actually created, delegated, and retired across modern environments.


Key questions

Q: How should security teams govern access across human, NHI, and AI identities?

A: Security teams should govern all three through a shared lifecycle and policy layer, but with different operating rules for each actor type. Humans need review and approval flows, NHIs need ownership, rotation, and offboarding discipline, and AI agents need continuous control over actions, permissions, and escalation paths. The key is to keep governance consistent without forcing one workflow onto every identity class.

Q: Why do AI-accelerated platforms increase identity and access risk?

A: They increase risk because the platform concentrates sensitive data, compute, and decision-making in one place. If an attacker compromises one control plane, the blast radius can extend across datasets, models, agents, and downstream experiments. That is why identity, authorization, and logging need to be coordinated as one control system.

Q: What are the signs that AI governance controls are not keeping pace with adoption?

A: Common warning signs include unclear ownership for AI use cases, inconsistent approval processes, limited visibility into where sensitive data enters models, and weak evidence for audits or assessments. Teams also struggle when privacy, security, and legal review happen late or manually, because that usually means governance is reactive rather than embedded in the AI delivery process.

Q: Should organisations treat AI coding agents as part of IAM and PAM governance?

A: Yes, when those agents can act on code, data, or tools in ways that affect production risk. Their permissions should be scoped, reviewed, and audited like other privileged systems, especially when they interact with sensitive routes, secrets, or regulated data. The governance question is who can let the agent act, and under what policy.


Technical breakdown

Why AI changes the identity governance model

AI raises identity risk because it increases the number of systems that can initiate access-dependent actions at runtime. Even when an AI feature is not fully autonomous, it can still expand the surface area for secrets, service accounts, tokens, and delegated permissions. That means identity governance can no longer focus only on authenticated users and static entitlements. The control problem shifts toward how access is issued, observed, and retired across machine and workflow identities that may exist for short periods and operate across multiple platforms.

Practical implication: inventory every AI-adjacent identity path, including service accounts and tokens, before treating AI use as a separate governance program.

How identity resilience differs from traditional access control

Identity resilience is the ability to keep access trustworthy as systems, dependencies, and delegates change. Traditional access control assumes the subject, entitlement set, and review cycle remain stable long enough for governance to catch up. In AI-heavy environments, those assumptions weaken because access can be created dynamically, chained through tools, and consumed by non-human actors. Resilience therefore depends on lifecycle speed, credential visibility, and the ability to revoke or rebind access without waiting for a scheduled review.

Practical implication: measure revocation latency and lifecycle coverage, not just policy completeness.

Where lifecycle governance becomes the control plane

When identity risk spans people, machines, and AI-enabled processes, lifecycle governance becomes the control plane that ties everything together. Joiner-mover-leaver processes, recertification, and privileged access reviews are no longer separate administrative tasks. They are the mechanism that determines whether access remains attributable, time-bounded, and removable. If lifecycle ownership is fragmented across IAM, PAM, cloud, and engineering teams, the result is persistent access with unclear accountability.

Practical implication: assign one owner for identity lifecycle decisions across human and non-human identities, then enforce shared review standards.


Threat narrative

Attacker objective: The objective is to exploit identity confusion and persistence so access remains usable longer than defenders can govern it.

  1. Entry begins when AI-adjacent access is granted through service accounts, tokens, or delegated workflows that are not mapped into a single governance model.
  2. Escalation occurs when those identities accumulate standing permissions, cross-system trust, or reuse patterns that outlive the original operational need.
  3. Impact follows when identity sprawl reduces visibility, slows revocation, and leaves organizations unable to prove who or what had access at a given point in time.
  • Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI-era identity security is really a governance stress test, not a technology category shift. Once AI touches access, the problem stops being confined to authentication and becomes a question of identity lifecycle, delegation, and revocation across systems. Organizations that keep treating AI as a separate security silo will miss the fact that the same access model now has to govern humans, NHIs, and AI-enabled workflows together.

Identity resilience fails when review cycles are slower than access creation cycles. The assumption that access can be provisioned, observed, and later reviewed was built for human-paced administration. That assumption weakens when access is requested, consumed, and retired by machine-driven processes at operational speed. The implication is that governance teams need to rethink what counts as reviewable access in the first place.

Standing access is becoming the hidden failure mode in AI-enabled environments. Service accounts, API keys, and delegated tokens often survive long after the business need that created them. In that condition, the real problem is not just privilege creep but the inability to attribute ownership across the lifecycle. Practitioners should treat unexplained persistence as a governance defect, not an operational inconvenience.

Identity teams need a unified control model for human and non-human access. The more AI influences enterprise workflows, the less defensible it becomes to separate IAM, PAM, and NHI governance into disconnected programs. What matters is whether every actor type is covered by the same visibility, lifecycle, and revocation logic. That is the baseline for resilience, not an advanced maturity state.

From our research:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the same report.
  • That risk profile is why the NHI Lifecycle Management Guide matters for teams trying to govern access across provisioning, rotation, and offboarding.

What this signals

Identity programmes that separate human IAM from machine governance will struggle as AI-driven workflows expand the number of non-human credentials in circulation. With 72% of organisations having experienced or suspecting an NHI breach, according to 2024 ESG Report: Managing Non-Human Identities, the practical question is whether governance can still keep pace with access creation and removal.

Lifecycle drift: when access outlives the business need that created it, and no team owns the removal path. That condition is now common enough to require a dedicated operating model, not ad hoc remediation.

Teams should prepare for more cross-functional pressure between IAM, PAM, cloud security, and engineering as AI adoption makes identity ownership less obvious. The right response is to make lifecycle accountability visible before access sprawl becomes impossible to unwind.


For practitioners

  • Map AI-adjacent identity paths Identify every service account, token, API key, and delegated workflow that AI features can touch, then record the owner, purpose, and revocation path for each.
  • Unify lifecycle ownership Define one cross-functional owner for joiner-mover-leaver, recertification, and offboarding decisions that affect human and non-human identities.
  • Measure revocation latency Track the time between access no longer being needed and access actually being removed, then escalate identities that remain active outside policy windows.
  • Separate reviewable access from ephemeral access Classify which AI-related permissions can be recertified and which must be designed as short-lived, task-bounded access instead of standing entitlements.

Key takeaways

  • AI-era identity security is a governance problem because machine-driven access changes how identity is created, reviewed, and retired.
  • Organizations need to measure lifecycle speed and ownership, not just policy design, if they want identity resilience to hold under AI pressure.
  • The control model must cover human, NHI, and AI-enabled access together or the weakest lifecycle path will define the breach surface.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The article centers on insecure non-human identities and lifecycle gaps.
Recommendation — Map AI-adjacent credentials to NHI-03 and remove standing access that lacks lifecycle ownership.
NIST CSF 2.0PR.AC-4The post is about managing access permissions across changing identity types.
Recommendation — Align human and non-human access reviews to PR.AC-4 and verify every entitlement has an owner.
NIST Zero Trust (SP 800-207)Zero Trust is relevant because the article focuses on continuous verification and reduced standing trust.
Recommendation — Use Zero Trust principles to minimize persistent access and force revalidation across AI-adjacent workflows.
NIST SP 800-53 Rev 5IA-5Credential lifecycle and authenticator management are central to the identity risk described.
AC-2Account management is directly implicated by unclear ownership and delayed offboarding.
Recommendation — Apply IA-5 discipline to token, key, and credential lifecycle controls for machine and delegated access. Use AC-2 to ensure every human and non-human identity has accountable ownership and deprovisioning.

Key terms

  • Identity resilience: Identity resilience is the ability to keep authentication, authorisation, and recovery functions operating when identity systems are attacked or degraded. In practice it means trusted access can be restored without reintroducing compromised state, and with enough evidence to prove the restored identity plane is clean.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Lifecycle Ownership: Lifecycle ownership is the assignment of responsibility for creating, changing, reviewing, and retiring an identity or its access. For customer and non-human identities, weak lifecycle ownership usually shows up as orphaned access, inconsistent policy enforcement, and unclear accountability during change.
  • Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.

What's in the full report

Semperis' full report covers the survey detail this post intentionally leaves for the source:

  • Breakdowns of how 1,100 IT and security professionals answered across eight countries
  • The study's AI and identity resilience findings by respondent group and geography
  • The underlying survey framing that connects identity security to cyber resilience
  • The report context behind the statistics and conclusions summarized here

👉 The full Semperis report includes the survey detail, respondent context, and resilience framing behind these findings.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or NHI programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org