TL;DR: Machine identities now outnumber humans by more than 80 to 1 and 68% of organisations still lack proper identity security controls for AI, according to Oasis Security, as agentic AI multiplies service accounts, tokens, API keys, and certificates faster than teams can govern them. ISPM is becoming the control plane for discovery, rotation, least privilege, and monitoring across machine identity sprawl.
At a glance
What this is: This is an analysis of why machine identity sprawl is becoming a core governance problem as agentic AI expands the volume and variety of NHIs.
Why it matters: IAM, PAM, and NHI teams need to treat discovery, rotation, privilege, and monitoring as a single lifecycle problem across service accounts, API keys, tokens, and certificates.
By the numbers:
- Machine identities now outnumber humans by more than 80 to 1 in enterprise environments.
- 68% of organisations lack proper identity security controls for AI.
Context
Machine identity sprawl is the uncontrolled growth of service accounts, API keys, tokens, and certificates across cloud, on-prem, and hybrid environments. In this article, Oasis Security argues that agentic AI is accelerating that sprawl faster than identity programmes can inventory and govern it.
The governance gap is not simply visibility. The harder problem is that machine identities often outlive the workloads that created them, remain overprivileged, and evade the review cadences used for human accounts. That makes ISPM a lifecycle discipline, not a point tool or a narrow secrets task.
Key questions
Q: What breaks when machine identity inventory is incomplete?
A: Rotation, revocation, and decommissioning all break down when you cannot see the full population of credentials. Incomplete inventory leaves blind spots for orphaned tokens, duplicated secrets, and over-permissioned accounts. Without visibility, security teams cannot prove ownership or identify which identities still have valid access to production systems.
Q: Why do long-lived secrets create more risk for workloads and agentic AI systems?
A: Long-lived secrets increase blast radius because any exposed key can be reused until it is rotated or revoked. In workload and AI environments, those credentials are often embedded in automation, shared across services, or retrieved repeatedly, which weakens accountability. Short-lived, identity-based access reduces persistence, limits reuse, and makes compromise easier to contain.
Q: How should teams reduce standing privilege for service accounts?
A: Teams should bind each service account to one workload, one purpose, and one minimal entitlement set. That means removing broad administrative rights, segmenting credentials by function, and revoking any access that is not required for the current execution path.
Q: Why do machine identities and agentic AI complicate traditional identity security programmes?
A: They complicate programmes because the number of non-human actors grows faster than manual governance processes can track. Access may be ephemeral, delegated, or embedded in workflows, which weakens assumptions built around human users. Security teams need policies for lifecycle control, privilege boundaries, and continuous verification across both human and machine identities.
Technical breakdown
Why machine identities become ungovernable at scale
Machine identities do not behave like human users. They are created by applications, pipelines, and AI systems, then reused across environments with little natural ownership or offboarding discipline. Once the count of service accounts, tokens, and API keys grows into the thousands, manual tracking fails because the estate changes faster than reviews can catch up. The result is a control gap in inventory, entitlement scope, and ownership. ISPM tries to collapse that chaos into a governed lifecycle so that every non-human credential has a known purpose, scope, and expiry.
Practical implication: build an authoritative inventory before trying to tune rotation or access policies.
How agentic AI changes NHI risk
Agentic AI changes the problem because these systems can request access and execute work dynamically, which increases the number of credentials in motion and the number of contexts in which they are used. That expands the blast radius of each secret, especially when the same API keys or service accounts can be invoked from multiple tools or local environments. The challenge is not just volume, but unpredictable use patterns that make static assumptions about when and why a credential will be used less reliable. The governance model has to account for machine identities that appear and disappear inside the same operational window.
Practical implication: classify AI-linked credentials separately from standard application secrets and track their usage paths explicitly.
What breaks when secrets are long-lived and overprivileged
Long-lived secrets and excess privilege are the combination that turns routine compromise into material access. If a token never rotates, or a service account holds broader permissions than its task requires, attackers only need one successful exposure to gain durable reach. This is why ISPM programmes focus on reducing standing access, forcing rotation, and limiting privilege by workload function rather than by convenience. The technical issue is not just secret hygiene. It is the persistence of access that survives the workload lifecycle and can be reused long after the original business need has changed.
Practical implication: tie each credential to a specific workload, privilege scope, and expiry rule.
Threat narrative
Attacker objective: The objective is to turn a single exposed machine identity into durable access that outlasts the original workload and reaches more systems than intended.
- Entry occurs when exposed API keys, tokens, or service accounts are discovered in sprawling environments that lack complete inventory and ownership.
- Escalation follows when those credentials still carry excessive permissions or remain valid long after the workload that created them has changed.
- Impact comes when the same non-human identity can be reused across systems, allowing the attacker to move from one service context into broader cloud or application access.
Breaches seen in the wild
- Cisco Active Directory credentials leak 2025: Kraken leaked Cisco Active Directory hashes, including service and krbtgt accounts; Cisco says they came from its 2022 breach, not a new one.
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Machine identity sprawl is now a lifecycle governance problem, not a secrets-management side issue. The estate now includes service accounts, API keys, tokens, and certificates that are created faster than teams can inventory them. Once ownership, purpose, and expiry are unclear, the control model has already failed. Practitioners should treat ISPM as the operating model for non-human identity governance, not as an add-on to vaulting.
Agentic AI intensifies NHI risk because it increases credential churn without simplifying accountability. The article's core point is that AI systems do not just consume machine identities, they multiply the contexts in which those identities are requested and used. That creates a broader governance surface across discovery, authorization, and review. Security leaders need to reframe AI identity controls around runtime usage, not just issuance.
Long-lived credentials are the real multiplier behind machine identity compromise. A secret that persists after its workload changes is an access path waiting to be reused. This is where NHI governance intersects with PAM discipline: standing privilege is the vulnerability, not just the secret itself. The practitioner conclusion is straightforward, but it is organizationally hard: kill the persistence window before it becomes the blast radius.
ISPM is becoming the control plane for machine identity accountability. When identities are created by pipelines, applications, and AI agents, the question is no longer only who can sign in. It is who owns the credential, who can revoke it, and what evidence proves it is still needed. That is the governance shift the market is converging on, and it will reshape how identity teams measure maturity.
Shadow AI turns NHI sprawl into an inventory problem with security consequences. Local AI usage and autonomous systems can introduce credentials outside standard approval paths, which means the gap is not just exposure but invisibility. The broader lesson is that identity programmes built around human joiner-mover-leaver logic do not automatically extend to machine creation and retirement. Practitioners should expect governance gaps to show up first in unmanaged AI-linked credentials.
From our research library:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
- Read next: Service Account Security Guide
What this signals
Machine identity sprawl is forcing identity teams to move from periodic review to continuous governance. Reviews that depend on a stable human-style lifecycle do not work when service accounts and API keys are created by pipelines, applications, and AI systems. The practical shift is to govern credentials at issuance and revocation time, not after the fact.
Shadow AI and local AI usage widen the blind spot around non-human credentials. When models run outside central security visibility, the organisation loses the clean ownership chain that most IAM programmes still assume. Teams should expect the next control gap to appear where AI-linked secrets enter the environment without standard registration or offboarding.
Machine identity blast radius is now a programme metric, not an incident metric. The more broadly a credential can be reused, the more a single exposure can spread across workloads and environments. That is why identity leaders need to measure privilege scope, rotation discipline, and unmanaged credential count together, not as separate hygiene tasks.
For practitioners
- Map every machine identity to an owner and purpose Create a single inventory for service accounts, API keys, tokens, and certificates across cloud, on-prem, and hybrid estates. Require each entry to record business purpose, technical owner, expiry, and the systems that can consume it.
- Enforce rotation and expiry on high-risk secrets Prioritise unrotated secrets, dormant credentials, and shared keys first, then set hard rotation rules for the credentials that support production workloads or agentic AI systems.
- Remove standing privilege from machine identities Strip excessive permissions from service accounts and replace broad, persistent access with task-scoped rights that match the exact workload or workflow.
- Separate AI-linked credentials from standard application secrets Track credentials used by agentic AI and local AI workflows as a distinct class because their request patterns, ownership, and runtime contexts change faster than ordinary application secrets.
- Monitor for abnormal machine identity use Alert on new geographies, unexpected tooling paths, and credential use outside the workload pattern so anomalous activity is visible before it becomes a compromise.
Key takeaways
- Machine identity sprawl is now a governance problem because service accounts, API keys, tokens, and certificates multiply faster than manual inventory and review processes can track.
- The article cites CyberArk research showing machine identities outnumber humans by more than 80 to 1 and that 68% of organisations still lack proper identity security controls for AI.
- Practitioners should treat ISPM as the operating model for non-human identity lifecycle control, with inventory, rotation, least privilege, and monitoring tied to ownership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article centers on exposed keys, tokens, and secrets across machine identities. |
| NHI-05 — Overprivileged NHI | The article highlights excessive permissions on service accounts and AI-linked identities. | |
| NHI-07 — Long-Lived Secrets | Unrotated API keys and persistent tokens are a central risk in the article. | |
| Recommendation — Scan for leaked machine secrets and revoke exposed credentials before they become durable access paths. Reduce machine identity entitlements to the minimum permissions needed for each workload. Enforce expiry and rotation for secrets that support production workloads or AI systems. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle management directly applies to rotation and revocation of machine credentials. |
| Recommendation — Apply IA-5 to govern issuance, rotation, and invalidation of machine authenticators. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post focuses on governing entitlements and authorization scope for non-human identities. |
| Recommendation — Review and tighten machine identity entitlements under PR.AA-05. | ||
Key terms
- Machine Identity Sprawl: Machine identity sprawl is the uncontrolled growth of non-human identities across teams, platforms, and business processes. It becomes a governance problem when identities are created faster than they can be inventoried, reviewed, rotated, or retired, leaving security teams with incomplete visibility and weak accountability.
- Identity Security And Privileged Management: Identity Security and Privileged Management is the discipline of discovering, governing, and reducing risk across privileged machine identities. It combines inventory, policy, rotation, and monitoring so organisations can control non-human access at scale rather than rely on manual review.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org