TL;DR: 62% of financial firms say legacy IAM is not ready for agentic AI, according to Ory, while NHIs now outnumber humans 144:1 and 92.1% of enterprises have already seen negative operational impacts from rushed AI rollouts. The governance gap is structural: human-centric IAM models cannot safely absorb machine-speed identity sprawl and over-privileged automation.
At a glance
What this is: This is an analysis of why legacy IAM in financial services is not keeping pace with agentic AI, with survey data showing readiness gaps, over-privileged automation, and identity sprawl.
Why it matters: It matters because IAM teams now have to govern AI agents, NHIs, and human access in the same environment, and legacy directory assumptions are already failing under machine-scale access patterns.
By the numbers:
- Non-human identities now outnumber human identities at a ratio of 144 to 1 in enterprise environments.
- 62.2% of financial services organizations say their IAM systems are not ready for agentic AI resiliency requirements.
- 92.1% of enterprises have already recorded visible negative operational impacts directly related to hasty AI implementations.
👉 Read Ory's analysis of legacy IAM readiness for agentic AI in finance
Context
Legacy IAM was built for human users, stable roles, and predictable access lifecycles. Agentic AI breaks those assumptions because access is now exercised by software entities that can execute tasks at machine speed, often across multiple systems and data sets.
In financial services, that mismatch is becoming operational, not theoretical. The article frames the problem around compliance pressure, resilience limits, and over-privileged machine access, all of which are familiar IAM issues that become harder when the actor is a non-human identity rather than a person.
The primary issue is not whether organisations want AI adoption. It is whether their identity stack can distinguish, constrain, and revoke machine access fast enough to avoid turning automation into a standing privilege problem.
Key questions
Q: What breaks when AI identities are handled outside IAM?
A: When AI identities sit outside IAM, organisations lose a consistent record of who has access, why access exists, and who approved it. That creates policy drift, weak accountability, and incomplete audit evidence. The programme may still function operationally, but it will not provide dependable governance or defensible compliance evidence.
Q: Why do NHIs complicate traditional IAM governance?
A: NHIs are created in many places, often outside central identity workflows, and they frequently outnumber human identities by a wide margin. That means reviews designed around slower human joiner-mover-leaver cycles miss the speed and scale of machine access. The result is persistent privilege drift and weak visibility.
Q: How do security teams know if an AI agent has too much access?
A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores. A healthy deployment leaves a clear audit trail of what the agent can do, what it actually did, and which credentials it used.
Q: Should organisations treat agentic AI access differently from service account access?
A: Yes. Service accounts are usually persistent and can be managed through lifecycle controls, while agentic AI access is often ephemeral, runtime-selected, and initiated on demand. The right governance model is different because the identity behaviour is different. Treating both as the same class leads to control gaps and delayed policy decisions.
Technical breakdown
Why legacy IAM struggles with agentic AI identities
Legacy IAM platforms usually assume a fixed human principal, a stable role set, and a review cycle long enough for access to be observed and certified. Agentic AI changes that pattern because the identity may be a service account, token, or agent credential that acts across tools and data stores without a person in the loop. In finance, that matters because regulatory pressure increases the cost of over-broad access while the execution model itself is becoming more dynamic. The result is not just scale pressure, but a mismatch between governance cadence and machine-speed execution.
Practical implication: teams should assess whether their IAM architecture can govern non-human identities with task-scoped access and rapid revocation, not just user logins.
Why over-privileged AI access creates identity blast radius
The article points to a common workaround: engineers over-privilege automated systems to make them work inside rigid platforms. That approach expands blast radius because a compromised or faulty machine identity can move across internal silos with far more reach than intended. This is the same failure mode seen in broader NHI governance, where convenience overrides least privilege and the identity becomes a pivot point rather than a bounded executor. In agentic AI, that risk is amplified because the system can continue acting until an operator notices the impact.
Practical implication: define access by task and data boundary, then test whether a single compromised identity can cross those boundaries without detection.
Why directory-centric IAM is a poor fit for NHI sprawl
Traditional directory models are built around employee records, not thousands of volatile machine identities. The article notes that NHIs already outnumber humans 144 to 1, which exposes the limits of human-centric schemas and monolithic identity stacks. Once automated workloads, API services, and AI agents all require lifecycle governance, the real issue becomes whether identity systems can model ownership, purpose, and revocation cleanly across non-human actors. Without that, reporting and control drift apart.
Practical implication: map machine identities outside employee-centric directories and treat their lifecycle as a separate governance domain.
Threat narrative
Attacker objective: The attacker or faulty automation seeks broad, persistent access to internal systems so it can alter, delete, or extract data beyond its intended scope.
- Entry occurs when an automated system or AI agent is provisioned with broad credentials to bypass rigid IAM configuration limits.
- Escalation follows when the non-human identity is over-privileged and can move across internal data silos without task-level constraints.
- Impact occurs when a compromised or misbehaving agent can delete data, exfiltrate information, or trigger unauthorized operational changes at scale.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Legacy IAM assumes access is stable long enough to be reviewed, and that assumption is breaking under agentic AI. Access review, certification, and recertification processes were designed for principals whose privileges persist across predictable governance cycles. When the actor is an autonomous or semi-autonomous machine identity, the access window can be shorter than the review window, which means the programme is measuring a state that no longer exists. The implication is that IAM teams must rethink the governance model itself, not just add more review tooling.
Identity blast radius is the central control variable in finance-era AI adoption. The article's warning about over-privileged machine access is not a niche implementation issue. It is the difference between bounded automation and an identity that can traverse data silos, permissions zones, and operational domains with no human pacing constraint. Practitioners should treat blast radius as the primary design metric for NHI and agentic AI governance.
Machine identity density has already crossed the threshold where human-centric IAM becomes structurally insufficient. When non-human identities outnumber humans by 144:1, the old model of directory-first governance stops being operationally realistic. That scale changes the problem from provisioning users to governing fleets of executable identities, which requires ownership, purpose, and revocation discipline built for non-human actors.
Financial services are validating the broader market shift from user IAM to identity control for everything that executes. The fact that 62.2% of financial firms say their IAM is not ready for agentic AI shows this is not a future-state concern. It confirms that security architecture is moving toward a unified control plane for human users, NHIs, and AI agents, with the governance burden increasingly sitting on identity teams rather than application owners.
Static credentials are now a liability multiplier in agentic workflows. The survey's finding that many organisations still rely heavily on static credentials fits a wider pattern across NHI security: long-lived secrets are incompatible with software that can decide and act continuously. The practitioner takeaway is straightforward. If machine identity is the execution layer, then credential lifespan and revocation speed become board-level risk variables.
From our research:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to The 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to The 2026 Infrastructure Identity Survey.
- For teams working through machine identity lifecycle controls, Ultimate Guide to NHIs , 2025 Outlook and Predictions is the next resource to compare lifecycle governance against emerging AI access patterns.
What this signals
Static secrets are becoming the least defensible part of AI governance. When machine identities are expected to make autonomous or semi-autonomous decisions, long-lived credentials turn every workflow into an exposure window. That is why identity teams should align their roadmap with the Ultimate Guide to NHIs and reduce the number of places where secrets can outlive their purpose.
Identity teams should prepare for a world where AI access policy is judged by outcome, not issuance. With 53% of leaders expecting AI to run major portions of infrastructure within three years, governance will shift toward revocation speed, task scoping, and ownership clarity. The practical test is whether your current control plane can stop a machine identity before it completes the wrong action.
Blast radius will become the most useful metric in NHI and agentic AI programme reviews. If a single machine identity can cross data boundaries, administrative boundaries, or tenant boundaries, the programme is overexposed regardless of how many policy documents exist. That is where AI governance starts to meet workload identity discipline and why operational control must be measurable, not assumed.
For practitioners
- Inventory all machine identities separately from human users Build a distinct register for service accounts, API keys, tokens, certificates, and AI agent credentials. Tie each identity to an owner, a purpose, and a revocation path so it is not hidden inside employee-centric IAM records.
- Measure identity blast radius before expanding AI access Test what a single automated identity can reach across data, infrastructure, and admin functions. Use that analysis to reduce cross-silo permissions and block implicit trust between systems.
- Replace static credentials with shorter-lived machine access Reduce reliance on long-lived secrets in AI and automation workflows, especially where those credentials can be reused across tools or environments. Pair this with rapid revocation and continuous discovery of exposed secrets.
- Separate agent governance from human recertification cycles Do not force AI agents and other NHIs into user access review processes that assume human work patterns. Create governance checks that operate at the cadence of machine execution and task completion.
- Consolidate fragmented IAM platforms around machine governance Use the expansion of agentic AI as a reason to reduce duplicated identity systems and remove brittle control gaps between them. The goal is a single governance model for access, ownership, and revocation across all actor types.
Key takeaways
- Legacy IAM is failing because it was designed around stable human access, not machine identities that can act at software speed.
- The scale problem is already visible: NHIs now outnumber humans 144:1, and financial firms are reporting clear readiness gaps for agentic AI.
- Practitioners should redesign governance around machine ownership, task-scoped access, and revocation speed before automation expands the blast radius.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article concerns AI agents and their identity risk in production workflows. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | The post centers on machine identities, static credentials, and over-privileged access. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access is the central governance issue discussed in the article. |
| NIST Zero Trust (SP 800-207) | The article argues for stronger identity boundaries and continuous verification for automation. | |
| NIST AI RMF | MANAGE | AI governance and risk management are central to the readiness gap described. |
Inventory NHIs, reduce standing privilege, and enforce revocation for long-lived machine credentials.
Key terms
- Agentic AI Identity: The complete set of credentials, permissions, and governance controls applied to an autonomous AI agent — covering authentication, authorisation, action logging, and access revocation. Distinct from traditional NHI because agent identities are often ephemeral, delegated, and multi-hop.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
What's in the full article
Ory's full article covers the operational detail this post intentionally leaves for the source:
- EMA survey breakdowns by financial services segment, including readiness scores for resiliency, compliance, and security
- The operational case for consolidating fragmented IAM systems rather than layering another platform on top
- The article's practical five-question framework for securing machine automation execution threads
- Survey context and commentary from Ory's team on why finance is feeling the pressure first
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org