TL;DR: Identity has become the main attack vector in the AI enterprise, with Palo Alto Networks citing 9 out of 10 organisations experiencing an identity-related breach, 109-to-1 machine and AI identity sprawl, and 61% of privileged access requests still fulfilled with standing privilege. The governance shift is from managing access to controlling every identity at runtime.
At a glance
What this is: Palo Alto Networks positions Idira as a response to the AI enterprise identity gap, arguing that standing privilege, identity sprawl and agentic access have made identity the primary control point.
Why it matters: IAM, PAM and NHI teams need to treat runtime privilege, not static provisioning, as the real governance boundary when human, machine and agentic identities all hold access.
By the numbers:
- 9 out of 10 organisations experiencing an identity-related breach in the past year.
- Machine and AI identities now outnumber humans 109 to 1.
- 61% of privileged access requests are fulfilled with standing privilege rather than on-demand.
Context
Identity security in this article is the control problem created when human, machine and agentic identities all have access to sensitive systems. The issue is not simply that there are more identities, but that privilege is now distributed across actors that traditional PAM and identity governance models were built to treat differently.
Palo Alto Networks argues that standing privilege, identity sprawl and agentic access have made the enterprise harder to govern with static access models. For identity programmes, the question is no longer who was granted access at onboarding, but what each identity can do at runtime and how quickly that privilege can be removed or constrained.
The article is a vendor announcement, but the underlying governance point is broader. Identity programmes that still separate workforce access, secrets, machine identities and emerging agentic access into different operational lanes will struggle to control blast radius in an AI enterprise.
Key questions
Q: What breaks when standing privileged access is still the default?
A: Standing privilege breaks least-privilege governance because access remains available long after the specific task has ended. That widens the attack surface, increases the impact of credential compromise, and makes it harder to prove that elevated rights were justified. Temporary elevation only reduces risk when the default state is non-privileged.
Q: Why do machine and agentic identities change privileged access risk?
A: Machine and agentic identities multiply the number of actors that can hold elevated access and use it continuously. That shifts the risk from a small set of privileged humans to a broad operational estate where access is harder to inventory, review and remove before it is abused.
Q: How do security teams know whether identity governance is reducing risk?
A: Look for shorter time from access change to visibility, fewer unmanaged entitlements, and faster completion of review and remediation cycles. If access risk remains unchanged after deployment, the programme may be reporting activity without changing control outcomes.
Q: Who should own AI identity decisions when human, machine, and agentic access overlap?
A: Ownership should sit with the team responsible for the full access path, not with separate owners for each credential type. When AI workflows use human approvals, machine identities, and production privileges together, fragmented ownership creates gaps in accountability. Governance must be assigned to one control owner with authority across lifecycle, access, and audit.
How it works in practice
Why standing privilege breaks down in the AI enterprise
Standing privilege means an identity retains elevated access until someone removes it. That model assumes the privileged window is long enough to govern through review, ticketing or recertification. In an AI enterprise, human users, workloads and agentic systems can all exercise privilege continuously and at scale, which makes static privilege grants a poor fit for dynamic execution patterns. The control problem shifts from whether access was approved to whether the privilege still needs to exist at the moment of use.
Practical implication: Treat standing privilege as a runtime risk, not just a provisioning issue.
How machine and agentic identities change the PAM model
Traditional PAM was designed around a smaller set of elevated human users and break-glass access. The article extends that model to machine and agentic identities, which changes the scope of governance. These identities may request, consume and reuse privileges in automated flows rather than interactive sessions, so the main question becomes how to bind privilege to task, workload or agent context. That requires consistent identity inventory, entitlement visibility and governance across all non-human identities, not separate control planes with different rules.
Practical implication: Unify machine, agentic and human privilege governance before privilege sprawl outpaces your inventory.
AI-driven governance turns lifecycle control into a continuous process
The article frames AI-powered policy as a way to transform compliance into governance by automating the identity lifecycle. The technical significance is that lifecycle events are no longer limited to joiner-mover-leaver workflows for people. They now include issuance, rotation, revocation and access changes for secrets, workload identities and AI-driven actors. That pushes identity governance closer to continuous enforcement, where policy is evaluated whenever access is created, used or retired.
Practical implication: Anchor lifecycle controls to issuance and revocation events, not only periodic access reviews.
NHI Mgmt Group analysis
Standing privilege is now a runtime exposure, not a convenience trade-off. The article shows that access granted at rest is no longer a stable security boundary when humans, machines and agents all operate continuously. Static privilege models were built for an environment where elevated access was rare and slow-moving. In the AI enterprise, that assumption no longer holds, so practitioners should treat privilege duration as a first-class governance variable.
Machine and agentic identities expose the limits of human-centred PAM. The article’s 109-to-1 ratio is not just a scale problem, it is a governance category change. PAM programmes that were designed around named users and interactive sessions cannot absorb machine and agentic access simply by extending the same workflows. Identity security now has to govern non-human actors as operational identities, not exceptions.
Dynamic privilege controls are becoming the baseline for identity governance. The shift the article describes is from managing access records to controlling effective access at the moment of use. That is a meaningful change for IGA, PAM and workload identity teams because review cycles alone cannot contain identity sprawl. The practical conclusion is that governance needs to follow execution, not just entitlement.
Identity sprawl is the new blast-radius problem. The article ties breach exposure to a fragmented identity estate where the same policies do not consistently cover workforce, workload and agentic access. This creates a broader blast radius than traditional PAM models were designed to absorb. Practitioners should treat cross-domain identity consolidation as a control objective, not an architecture preference.
AI enterprise identity security now sits at the intersection of PAM, workload identity and agentic governance. The article is signalling a market where those previously separate disciplines are converging into one operating model. That convergence matters because each domain has different lifecycle expectations, but the same attacker can abuse any of them once privilege is loose. The implication for security leaders is to align governance across all three rather than fund them as disconnected programmes.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Runtime privilege is becoming the decisive control boundary. Identity programmes that still measure success by approval state or periodic review are missing where compromise now happens. The relevant question is whether privilege exists for longer than the task that needs it, because that is where blast radius grows.
Identity consolidation is now an architectural issue, not just a tooling issue. Human IAM, PAM, secrets and workload identity can no longer be governed as separate islands if the enterprise wants consistent control over access paths. The programme implication is to standardise policy across all identity classes before agentic access adds another unmanaged layer.
For practitioners
- Map every privileged identity class Build a single inventory that covers human admins, service accounts, workload credentials, secrets and emerging agentic identities. Separate the labels from the actual privilege paths so you can see where elevated access persists outside intended workflows.
- Replace standing privilege with task-bound access Shift high-risk access from persistent grants to just-in-time provisioning with explicit expiry and revocation logic. The goal is to make privilege disappear when the task ends, not when a review cycle eventually catches up.
- Govern machine and agentic identities together Use the same lifecycle rules for issuance, rotation, revocation and offboarding across workloads, secrets and AI-driven identities. Separate tooling may still exist, but the policy model should not treat non-human access as a special case.
- Track access paths instead of only entitlements Monitor which identities can reach sensitive data and systems through multiple delegated paths, not just which roles they hold on paper. Identity risk is often hidden in the path, not the permission label.
Key takeaways
- The article frames identity as the main attack surface in the AI enterprise, with standing privilege and identity sprawl creating the core control gap.
- Palo Alto Networks cites 9 out of 10 organisations with an identity-related breach, 109-to-1 machine and AI identity growth, and 61% standing privilege usage.
- Security teams need governance that follows runtime access across human, machine and agentic identities, not just periodic review of granted entitlements.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on standing privilege across machine and agentic identities. |
| NHI-07 — Long-Lived Secrets | The article highlights persistent credentials and access that outlive their intended use. | |
| NHI-01 — Improper Offboarding | Identity lifecycle automation is a core theme, including revocation and offboarding. | |
| Recommendation — Reduce standing access and enforce task-bound privilege for every non-human identity. Shorten credential lifetime and revoke secrets that no longer match active use. Automate offboarding and revocation so access ends when the identity no longer needs it. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle management is central to the article's privilege model. |
| Recommendation — Apply authenticator management controls to rotate and retire privileged credentials on schedule. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes adversaries leveraging identity paths rather than perimeter intrusion. |
| Recommendation — Map identity abuse to credential access and lateral movement to prioritise monitoring and containment. | ||
Key terms
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
- Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on June 5, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org