TL;DR: AI agents and machine identities are exposing a structural gap in IAM, because two decades of identity tooling were built around login events and declared accounts rather than continuous runtime behaviour, according to Orchid Security. The real break point is authority, not another integration layer: existing fabric models can correlate what is already visible, but they cannot govern identities that were never declared.
At a glance
What this is: This is an analysis of why identity fabric and traditional IAM models fail to govern AI agents and other non-human identities that act continuously without a login event.
Why it matters: It matters because IAM, IGA, PAM, and NHI programmes now have to account for runtime authority, dark matter identities, and accountability when access is exercised outside the classic authentication flow.
By the numbers:
- 46% of identity activity already occurs outside centralized IAM visibility entirely.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
👉 Read Orchid Security's analysis of redefining IAM for AI agents
Context
AI agent identity governance is breaking because modern IAM was built around the login event, while AI agents often act continuously without one. That creates a gap between declared access and real runtime authority, especially when service accounts, API tokens, and embedded application credentials sit outside the identity provider's line of sight.
Orchid Security argues that this is not a dashboard problem, but an architectural one. If identity platforms only correlate what has already been declared, they will continue to miss the identities that matter most in agentic and machine-to-machine environments.
For IAM, IGA, PAM, and NHI leaders, the practical question is no longer whether systems can authenticate users well enough. It is whether the organisation can see, attribute, and govern actions taken by software that never enters the classic front door.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.
Q: Why do AI agents expose the limits of identity fabric?
A: Identity fabric is effective for correlating declared data across IAM, IGA, PAM, and cloud tools. It fails when the identity was never declared, because correlation cannot discover shadow accounts, embedded secrets, or application-local access. AI agents make that limitation urgent because they can exploit whatever credential is already available and move faster than review cycles can respond.
Q: How do organisations know whether non-human identity governance is working?
A: Look for three signals: fewer standing credentials, faster revocation of secrets and tokens, and evidence that access decisions match the actual runtime behaviour of the identity. If reviews, logs, and lifecycle events do not line up, governance is only documenting access rather than controlling it.
Q: Who is accountable when an AI agent acts outside its intended scope?
A: The organisation is accountable, but operational responsibility should sit with a named owner and a governance process that can explain the agent’s purpose, access, and recorded actions. Without that, autonomous behaviour becomes unassignable risk rather than managed automation.
Technical breakdown
Why the login-centric identity model breaks for AI agents
Modern IAM assumes identity behaviour starts with authentication, then flows into provisioning, authorisation, review, and offboarding. That model works when the actor is a person who logs in, requests access, and leaves a visible trail. AI agents and other NHIs change the timing. They can call APIs, combine credentials, and execute tasks continuously without a human-paced login event. A fabric can correlate declarations, but it still depends on systems describing themselves accurately. It cannot govern behaviour that was never declared or that occurs entirely inside an application boundary.
Practical implication: map which parts of your identity estate only exist as declarations, then identify where runtime behaviour is missing from governance coverage.
What identity fabric can see, and what it cannot
Identity fabric is useful for connecting IdP, IGA, PAM, and cloud entitlement data into one view. Its limitation is that it only weaves together what the source systems already know. That means it can improve visibility across connected tools without discovering shadow NHIs, hardcoded credentials, or application-local accounts that never entered the governed inventory. In agentic environments, this distinction becomes material because the fastest path for an agent is often the nearest standing credential, not a newly issued, reviewed one. Correlation is not discovery.
Practical implication: separate integration projects from discovery work so you can find identities that have never been onboarded into your control stack.
Why authority is now the governing unit
The article's central shift is from access as a record of permission to authority as the ability to act. A login event tells you who entered a system. Authority tells you whether software can execute, select tools, and keep moving without another approval gate. For AI agents, that matters more than the old access-review rhythm because the meaningful control point is no longer the certification cycle. It is the point where runtime action becomes possible and attributable. NIST AI Risk Management Framework thinking fits here because the governance problem is decision authority, not just account lifecycle.
Practical implication: redesign governance around who or what can exercise authority at runtime, not only who is listed as having access on paper.
Threat narrative
Attacker objective: The objective is to use existing non-human access paths to perform actions that exceed intended scope while avoiding the visibility and review limits of classic IAM.
- Entry occurs when an AI agent or NHI uses a standing credential, token, or embedded application secret that was already available in the environment.
- Escalation happens when the actor uses that credential to reach systems or data beyond the original human-reviewed task scope.
- Impact follows when the agent completes unauthorised actions at machine speed, leaving governance teams to reconstruct activity after the fact.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- CoPhish OAuth Token Theft via Copilot Studio — CoPhish campaign exploits Microsoft Copilot Studio agents to steal OAuth tokens via AI-assisted phishing.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity fabric is a visibility layer, not an authority layer. Correlating IdP, IGA, PAM, and cloud signals improves the completeness of declared access data, but it does not create ground truth for identities that never entered those systems. The industry keeps treating better correlation as a substitute for runtime control. That is the wrong mental model for agentic environments, where software can act outside the old authentication rhythm and still produce business-impacting outcomes.
Authority is now the right unit of governance for agentic identity. The old IAM model was designed to manage access after authentication, which assumes a visible login event and a stable human operator. AI agents break that assumption because they can initiate action, select tools, and execute continuously. The implication is not just that more controls are needed, but that the governance unit itself has changed from access declaration to runtime authority.
Dark matter identities are no longer a side issue. When a material share of identity activity occurs outside central visibility, the programme is already governing with incomplete data. That gap is especially dangerous for service accounts, API tokens, and application-local credentials because they become the shortest path for both humans and agents. Teams should treat undeclared identity activity as a first-class architecture problem, not an exception process.
Ephemeral credentials do not solve a visibility problem by themselves. They reduce standing exposure, but they do not automatically make identity behaviour observable or attributable. If the organisation cannot see which software actor used the credential, when it was exercised, and what it did next, the credential lifecycle is only partially governed. Practitioners need to separate reduced dwell time from true runtime accountability.
Runtime identity blind spot: This is the named concept that best captures the failure mode exposed here. The blind spot is not that teams have no tools. It is that the tools are still organized around declared identity states while the risk is happening in runtime behaviour. That means the next governance boundary is not another dashboard, but a control plane that can observe and attribute identity action at the point of execution.
From our research:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Another NHIMG finding shows that only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities.
- For a deeper NHI baseline, see Ultimate Guide to NHIs for the governance lifecycle that underpins discovery, ownership, rotation, and offboarding.
What this signals
Runtime identity blind spot: programmes that still rely on declared accounts and access reviews will keep missing the identities that actually move data, because action is now occurring outside the cadence of human governance. The right next step is to connect non-human attribution to control ownership, not just entitlement reporting, using the Ultimate Guide to NHIs as the baseline governance reference.
With 88.5% of organisations already acknowledging that non-human IAM lags human IAM, the operational gap is no longer speculative. Identity teams should expect more pressure to prove runtime visibility, especially where agents and service accounts can exercise access without a login event.
This is where identity and AI governance converge. The same programme that manages human entitlements must now prove it can track software actors that select and use credentials continuously, which aligns closely with the NIST AI Risk Management Framework.
For practitioners
- Inventory identities that never enter the IdP Find service accounts, API keys, embedded application secrets, and local accounts that exist outside centralized IAM visibility. Classify them by business function, owning team, and blast radius so you can see where governance depends on declarations that never happened.
- Separate discovery from integration programmes Do not treat connector rollout as discovery. Build a dedicated workstream to identify application-local identity, shadow NHI usage, and credentials issued outside the control plane, then feed those findings into IGA and PAM ownership models.
- Define runtime authority owners for agents and workloads Assign a human owner for each AI agent or workload identity and require accountability for every action path that can be exercised without a login event. The ownership record should include the systems the identity can reach and the approval boundary it can cross.
- Instrument for action at the point of execution Add telemetry that captures which non-human identity used which credential, against which application, and with what result. Without point-of-execution attribution, access reviews and post-incident reconstruction will continue to trail the real event.
Key takeaways
- AI agents expose the fact that identity governance built around login events cannot reliably control runtime authority.
- The evidence points to a structural visibility gap: declared identity data is not enough when non-human actors can use standing credentials outside the IAM front door.
- Practitioners should shift from access-centric thinking to runtime attribution, ownership, and observation of every non-human actor that can execute work.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The post centres on visibility gaps and undeclared non-human identities. |
| OWASP Agentic AI Top 10 | Agent autonomy and tool use are central to the article's governance argument. | |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access governance is directly implicated by standing non-human credentials. |
| NIST AI RMF | GOVERN | The article focuses on accountability and governance for AI-driven decision and action. |
| NIST Zero Trust (SP 800-207) | Zero Trust assumptions are challenged when software acts continuously without login events. |
Use the agentic application risks framework to test runtime authority, tool use, and approval boundaries.
Key terms
- Identity Fabric: An identity fabric is a connected control model that shares context across governance, privileged access, and access management. It is not a product category. The aim is to make identity decisions coherent across the full lifecycle so ownership, privilege, and enforcement reinforce each other.
- Runtime authority: Runtime authority is the permission an AI system has while it is actively deciding and acting, not just when it is approved. In governance terms, it is the point where access, tool use, and action scope become operational, which is why build-time review alone cannot prove safety.
- Dark Matter Identity: Dark matter identity is NHIMG shorthand for identity activity that exists and acts but is not visible to central IAM governance. These identities may be service accounts, embedded secrets, local application users, or AI agent credentials that operate outside the governed inventory and therefore escape normal review cycles.
- Point-of-Execution Attribution: Point-of-execution attribution means capturing which identity used which credential, in which application, and with what outcome at the moment action occurred. It is the difference between post-incident reconstruction and real governance, especially for agents and other non-human actors that do not log in like humans.
What's in the full article
Orchid Security's full blog post covers the architectural argument and implementation context this post intentionally leaves for the source:
- The distinction between identity fabric, control plane, and point-of-execution visibility in real enterprise architectures
- The AI-agent scenario used to illustrate how undeclared access can remain invisible to traditional IAM tooling
- The vendor's critique of connector-based governance and what it means for next-generation identity programmes
- The closing architectural recommendation for teams deciding whether to extend, replace, or supplement their current identity stack
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org