TL;DR: 61% of organisations lack a complete, central inventory of privileged entitlements, 55% struggle to govern non-human accounts, and 82% do not feel fully prepared to govern new AI agent identities, according to SailPoint’s survey. The governance gap is no longer about access volume alone, but about whether privilege can still be discovered, classified, and contained.
At a glance
What this is: This research report argues that privileged access governance is breaking down because organisations cannot fully discover, classify, or govern entitlements across human users, non-human accounts, and AI agent identities.
Why it matters: IAM and PAM teams need to treat visibility as the prerequisite control, because privilege that cannot be inventoried or classified cannot be constrained, recertified, or safely extended to AI-driven workflows.
By the numbers:
- 61% of organizations lack a complete, centralized inventory of their privileged entitlements.
- 55% report non-human accounts are among their most difficult to govern.
- 62% already see new AI agent identities in their environments.
- 82% do not feel fully prepared to govern them.
Context
Privileged access is the set of elevated entitlements that let a user, service, workload, or agent do high-impact actions. In the AI era, the governance problem is not only who has those entitlements, but whether security teams can still see them across fragmented estates, cloud services, and emerging AI agents.
SailPoint’s research frames a visibility gap that weakens least privilege at the exact moment organisations are adding more dynamic forms of access. When privileged entitlements cannot be inventoried and classified consistently, recertification, governance, and containment all start from incomplete data.
That matters because AI adoption increases the number of identities that can act with elevated access without changing the basic governance requirement. The article’s starting point is typical for organisations modernising identity, but the mix of human and non-human privilege makes the gap materially harder to close.
Key questions
Q: What breaks when privileged access is not continuously governed?
A: When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities. In practice, that creates a larger blast radius for credential theft and a weaker ability to prove who had access, when, and why. The result is operational drift, not just security exposure.
Q: Why do service accounts and bots create more governance risk than many human accounts?
A: Service accounts and bots create more governance risk because they are often granted privileges for speed and left in place after the original use case changes. They can multiply quickly across integrations and workflows, making ownership, review, and deprovisioning harder to maintain. When lifecycle controls are weak, orphaned access becomes a standing risk surface.
Q: How should IAM teams govern AI agent identities differently from static service accounts?
A: IAM teams should treat AI agent identities as a separate privileged class because access can be exercised through changing tasks, tools, and contexts. That means scoping must cover tool boundaries and task purpose, not just account creation, and governance needs stronger runtime visibility than a static account model provides.
Q: What should organisations prioritise first: access reviews or privilege reduction?
A: Prioritise privilege reduction first when you already know there is excess access, then use reviews to keep it from coming back. Reviews verify the current state, but they do not eliminate broad entitlements on their own. If the environment is heavily over-permissioned, reducing standing access creates the biggest immediate risk drop.
Technical breakdown
Why privileged entitlement discovery breaks down
Privileged entitlement discovery fails when identity data is split across directory systems, cloud accounts, SaaS platforms, automation tooling, and ephemeral AI workflows. A complete inventory requires more than scanning users and roles. It must continuously resolve who or what can act, under which authority, and through which delegated path. Without that correlation, entitlement data becomes stale as soon as new accounts, APIs, or AI helpers are introduced. The result is a visibility gap, not a policy gap: teams may have controls on paper, but they cannot apply them to assets they do not know exist.
Practical implication: build entitlement discovery around continuous inventory, not periodic exports or one-time access reviews.
How non-human accounts change privileged access governance
Non-human accounts include service accounts, cloud entitlements, tokens, automation tools, and other machine identities that act without human login patterns. They are difficult to govern because they often outlive the project, application, or workflow that created them, and their access paths are embedded in runtime systems rather than user directories. That makes them harder to classify, recertify, and align to an owner. In privileged access programmes, this shifts the control focus from user-centric reviews to ownership, purpose, and lifecycle evidence for every non-human entitlement.
Practical implication: require explicit ownership and lifecycle records for every privileged non-human identity before it is allowed to persist.
Why AI agent identities expose a new privilege class
AI agent identities are distinct from ordinary automation because they can interact with tools and data in ways that are less predictable than static workflows. The governance challenge is not just that an agent has access, but that its privilege may be exercised across changing tasks and contexts. That makes least privilege harder to define at provisioning time and harder to validate later with traditional review cycles. When AI agent identities appear in the environment, privilege governance must account for dynamic use paths, delegated tool access, and scope that can expand faster than review cadence can catch.
Practical implication: model AI agent access as a governed identity class, with explicit scoping and tool boundaries from the start.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Privilege visibility is now the controlling variable in identity security. The article shows that the problem is not simply too much access, but too much access that cannot be fully discovered and classified. Once inventory fragments across humans, service accounts, cloud entitlements, and AI agents, least privilege becomes an aspiration rather than an enforceable state. Practitioners should treat visibility as the precondition for every downstream privilege control.
Non-human governance has moved from edge case to core programme requirement. Service accounts, cloud entitlements, and automation tools are now among the hardest privileges to govern because their lifecycle is often owned by systems, not people. That breaks the assumption that privilege can be reviewed through human-centric governance rhythms alone. The implication is that identity governance must expand ownership, purpose, and offboarding discipline to machine identities as a first-class population.
AI agent identities create an entitlement class that static PAM models do not describe cleanly. Traditional privileged access controls were built around stable subjects and known access paths, but AI agents introduce more fluid and task-dependent privilege use. Dynamic privilege drift: the access boundary can change as the agent changes context, which means provisioning-time assumptions age quickly. Practitioners should rethink whether their current classification model can keep pace with agent-timed access decisions.
This research validates that least privilege now depends on runtime classification, not just role design. If an organisation cannot automatically discover and classify privileged entitlements across the IT estate, then recertification will always trail reality. That is especially true when AI adoption adds new identity types faster than governance processes can be updated. The field needs privilege control models that start with inventory truth, not policy intent.
Identity security programmes will be judged on their ability to govern mixed privilege populations consistently. Human, non-human, and AI identities are converging inside the same operational environment, but they do not behave the same way. A single privilege framework only works if it can distinguish durable human access from machine-held and agent-exercised access. Practitioners should align governance models to identity behaviour, not to a legacy assumption that privilege is mostly human.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- Read next: Privileged Access Management Guide
What this signals
Privilege visibility is becoming the practical boundary of least privilege. When entitlements are fragmented across cloud, SaaS, automation, and agentic workflows, policy intent no longer equals control reality. Teams that still treat privileged review as a periodic human exercise will miss the identities that matter most.
Non-human identity governance now sits inside the privileged access programme, not beside it. The operational question is no longer whether service accounts exist, but whether they are owned, classified, and offboarded with the same discipline as human access. That shift changes IAM roadmaps, PAM scope, and recertification design at the same time.
Dynamic privilege demands runtime classification. Static role models struggle when AI agents and automation tools can exercise access in changing contexts, which means entitlement truth has to be maintained continuously rather than certified after the fact.
For practitioners
- Implement continuous privileged entitlement discovery Use automated inventory collection across directories, cloud platforms, SaaS applications, and orchestration layers so privileged accounts and entitlements are visible as they are created or changed.
- Establish named ownership for non-human privilege Assign accountable owners to every service account, cloud entitlement, token, and automation identity, and block persistence when ownership or purpose cannot be demonstrated.
- Classify AI agent identities as a separate privileged population Define AI agents as their own identity class in governance models so tool access, scope, and recertification rules are not copied from human user patterns.
- Rework recertification around current privilege evidence Base reviews on live entitlement data and usage context rather than static role assignments, especially where access spans cloud services, service accounts, and agent workflows.
Key takeaways
- The article shows that privileged access risk is increasingly a visibility problem, not only a volume problem.
- SailPoint’s research says 61% of organisations lack a complete inventory of privileged entitlements, 55% struggle with non-human accounts, and 82% are not ready for AI agent identities.
- Identity governance programmes now need continuous discovery, ownership, and classification if they are to contain privilege across human, non-human, and AI-driven access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on excessive and poorly governed privileged entitlements across non-human identities. |
| NHI-08 — Environment Isolation | The article notes privilege spans cloud, SaaS, automation, and AI environments that need distinct boundaries. | |
| Recommendation — Inventory privileged non-human identities and reduce standing access to the minimum scope required. Separate privileged access paths by environment so identities are not reused across trust zones. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core issue is incomplete discovery and governance of privileged entitlements across the estate. |
| Recommendation — Maintain a current entitlement inventory and align access permissions to verified business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article highlights difficulty governing human and non-human accounts with privileged access. |
| Recommendation — Centralise account management so privileged identities are owned, reviewed, and retired on schedule. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Privileged access depends on controlling the authenticators and credentials used by users and non-human accounts. |
| Recommendation — Apply authenticator lifecycle controls to rotate, revoke, and limit privileged credentials. | ||
Key terms
- Privileged Entitlements: Privileged entitlements are the permissions that allow an identity to perform elevated or high-risk actions in a cloud environment. These entitlements may belong to users, service accounts, or other synthetic identities. Effective governance depends on knowing where they exist, who can use them, and when they are active.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Privilege visibility: Privilege visibility is the ability to see which identities can reach which systems, under what conditions, and with what level of access. For SSH-based workflows, it is the difference between knowing traffic is encrypted and knowing who actually exercised the access path.
- AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org