By NHI Mgmt Group Editorial TeamBased on JumpCloud: “IT’s New Reality: Unify or Drown in Complexity” (August 12, 2025)

TL;DR: Only 19% of organisations have fully unified IT, while AI adoption is near universal and security concerns around non-human identities, system integration, and misuse are rising, according to JumpCloud’s Q3 2025 IT Trends Report based on a survey of 828 IT leaders in the U.S. and U.K. JumpCloud’s findings show that consolidation, visibility, and identity governance are now linked problems, not separate programmes.


At a glance

What this is: This is a report-driven view of how IT consolidation, Zero Trust, and AI identity risk are converging into one governance problem.

Why it matters: It matters because IAM, NHI, and security architecture teams can no longer treat visibility, consolidation, and AI governance as separate workstreams.

By the numbers:

  • Only 19% have achieved full IT unification.
  • IT professionals said improved user experience was a top consolidation benefit at 55%.
  • IT professionals said increased job satisfaction among IT staff was a top consolidation benefit at 54%.
  • IT professionals said a better focus on strategic work was a top consolidation benefit at 51%.

Context

IT consolidation is the attempt to reduce fragmented tools, policies, and operational handoffs into a more coherent identity and operations model. In this report, JumpCloud frames the issue as an IT governance problem, not just a procurement one, because unification, visibility, and security posture now move together.

The identity angle is clear: only 19% of organisations have fully unified IT, while AI adoption is near universal and concerns are growing around non-human identities, sensitive system integration, and misuse. That combination means teams are trying to govern more identities, more integrations, and more risk with incomplete architectural consistency.


Key questions

Q: What breaks when access, device, and identity controls are not unified?

A: Governance breaks first. Teams lose a dependable way to prove who has access, which device is trusted, and what changed those states over time. Operationally, they fall back to scripts and tickets, which increases error rates and slows response. Security then inherits contradictory records instead of a clean source of truth.

Q: Why do non-human identities become a bigger risk in AI-speed attacks?

A: Because NHIs often provide the shortest route from discovery to real access. Service accounts, tokens, and API keys are machine-readable, frequently over-privileged, and sometimes poorly owned, so an AI-driven attacker can pivot through them quickly after finding an initial weakness. Effective governance turns these identities into controlled boundaries rather than reusable entry points.

Q: How can security teams tell whether zero trust is actually working in AWS?

A: Look for evidence that access is issued for a narrow purpose, expires automatically, and is auditable across accounts and resource types. If teams still rely on long-lived credentials, broad roles, or manual revocation to control AWS access, zero trust is only partially implemented.

Q: Should organisations consolidate IT before expanding AI use?

A: Consolidation does not need to come first in every case, but expanding AI on top of fragmented identity and access control increases risk quickly. The practical test is whether the organisation can govern machine access, system integration, and visibility consistently across the stack. If not, AI adoption will amplify existing control gaps rather than simplify them.


Technical breakdown

Why IT consolidation changes identity governance

IT consolidation is not just a tooling reduction exercise. When identity, device, and access controls sit across multiple systems, the organisation loses a single view of entitlements, lifecycle status, and policy enforcement. That creates gaps in recertification, exception handling, and offboarding consistency. The report’s emphasis on unification reflects a deeper operational truth: governance quality depends on how many control points must agree before access is granted or removed. If the architecture is fragmented, even good IAM processes become harder to execute reliably across teams, platforms, and service boundaries.

Practical implication: map where identity decisions are still split across tools and remove duplicated approval and enforcement paths.

Zero Trust fails when visibility is partial

Zero Trust is often treated as a perimeter replacement, but the report points to a more basic requirement: central visibility plus a workable security-user experience balance. Without that, policy becomes unevenly enforced and exception-driven. In practice, fragmented environments make it difficult to prove who or what accessed which resource, under what trust condition, and whether the access was still appropriate at the time. That weakens continuous verification because the control loop depends on timely identity and context data, not just on policy intent.

Practical implication: verify that your visibility layer can support continuous authentication and authorisation decisions across the full stack.

Why AI identity risk is an NHI governance problem

AI adoption creates a non-human identity problem as soon as systems need access to data, tools, APIs, or workflows. The article specifically highlights concerns around non-human identities, sensitive system integration, and misuse, which are classic indicators that AI is operating through machine credentials and delegated access paths. Even when the underlying AI model is not autonomous in the strict sense, the identity surface expands quickly: tokens, service accounts, and integration privileges become the real control points. That shifts the governance question from model capability to access scope, lifecycle, and accountability.

Practical implication: govern AI systems as non-human identities first, then align access scope to the integrations they actually need.


Threat narrative

Attacker objective: Exploit trust in integrated identity paths to reach sensitive systems or misuse access at scale.

  1. Entry occurs when AI systems or integrated services are granted access through non-human identities such as tokens, service accounts, or delegated connectors.
  2. Escalation happens when fragmented IT and incomplete visibility allow those identities to retain broader access than the task or integration truly requires.
  3. Impact follows when misuse, sensitive system integration, or AI-driven abuse can move through trusted access paths without a consistent control loop.
  4. The objective is to let AI-enabled and other non-human actors interact with core systems at a scope that outpaces governance and detection.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity consolidation is now a governance control problem, not a platform preference. The report shows that organisations want the operational benefits of consolidation, but the real issue is whether identity decisions can be made consistently across fragmented stacks. When access, device, and policy data live in separate systems, governance becomes conditional and exception-heavy. Practitioners should treat consolidation as a control design decision, not a technology refresh.

AI identity risk is being introduced through ordinary integration patterns. The article does not describe exotic attacks so much as normal enterprise plumbing becoming an identity surface for AI, APIs, and service access. That means NHI governance needs to move upstream to account for machine credentials, delegated access, and system-to-system trust. The practitioner takeaway is that AI risk is often just unmanaged non-human access wearing a new label.

Zero Trust is only as strong as the identity signal that feeds it. The report links zero trust, central visibility, and user experience because policy enforcement breaks when the organisation cannot see the current trust state. This is where many programmes fail: they build policy intent faster than they build evidence. Teams should assume that partial visibility creates partial trust, even when the language of Zero Trust sounds complete.

Unification pressure is exposing an identity blast radius problem. The longer an organisation operates with overlapping tools and incomplete governance, the wider the range of identities, integrations, and exceptions that can be abused or misused. That blast radius is not only technical but operational, because teams lose the ability to answer basic questions about ownership and scope. The implication is straightforward: reduce the number of places where identity truth can diverge.

What this signals

Identity consolidation is becoming the hidden prerequisite for AI governance. Teams cannot govern non-human identities, delegated integrations, or Zero Trust policy consistently when the underlying access model is split across too many tools. The programme consequence is that AI risk work now depends on identity architecture work, not just security policy.

Partial visibility is a structural weakness, not a reporting issue. When identity state, device state, and access policy do not line up, the control loop breaks before enforcement even begins. That means IAM, PAM, and NHI teams should treat visibility gaps as operational defects that directly affect trust decisions.

Unified governance will matter more than tool count. The organisations that get ahead will be the ones that can define ownership, scope, and lifecycle for every human and non-human identity in one operating model. In practice, that pushes identity teams toward tighter integration between IAM, NHI governance, and AI access oversight.


For practitioners

  • Map identity decision points across fragmented tools Identify where authentication, authorisation, provisioning, and revocation still occur in different systems, then remove duplicate approval paths that create inconsistent outcomes.
  • Treat AI integrations as non-human identities Inventory service accounts, tokens, API connections, and delegated workflows used by AI-enabled systems, then assign ownership and lifecycle controls to each one.
  • Test Zero Trust against incomplete visibility Validate whether continuous verification still works when telemetry, entitlement data, or policy enforcement is missing from one part of the stack.
  • Reduce standing access in consolidated environments Review high-trust access that survives tool consolidation, especially admin privileges and service credentials that were inherited from older systems.

Key takeaways

  • The report shows that fragmentation is now a governance risk, because identity, visibility, and enforcement are being asked to work across too many disconnected systems.
  • AI adoption is turning ordinary integrations into non-human identity exposure points, which makes scope, ownership, and lifecycle controls more important than model choice.
  • Zero Trust only holds when the organisation can see and verify identity state continuously across the environment, not just on paper.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article highlights non-human identities, integration sprawl, and AI access scope.
NHI-10 — Human Use of NHIThe report points to AI and integration misuse through identity paths intended for machines.
Recommendation — Review machine and AI-connected access for overprivilege and trim privileges to task-specific scope. Separate human-operated and machine-operated access paths so NHI credentials are not used as convenience shortcuts.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe report is fundamentally about governing access across fragmented identity systems.
Recommendation — Align entitlements and authorisations across platforms so identity decisions stay consistent.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe report’s risk themes map to misuse of trusted access paths once credentials are exposed or overextended.
Recommendation — Map exposed integration credentials and trusted access paths to credential-access and lateral-movement detection.

Key terms

  • IT Consolidation: IT consolidation is the process of reducing the number of separate tools, vendors, or platforms used to deliver and manage technology services. In MSP environments, it is usually pursued to lower cost, simplify support, reduce workflow friction, and create a more unified operating model for both administrators and end users.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Zero Trust: A security model that assumes no identity, human or non-human, should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org