TL;DR: Identity programmes now have to govern both human authentication and machine trust assumptions, not treat them as separate problems, according to Yubico. The company says it is expanding from hardware-backed authentication into a digital identity platform that protects user and AI agent identities end to end, while also reporting its largest fixed-currency quarterly bookings and accelerated subscription growth.
At a glance
What this is: Yubico is broadening its identity strategy from hardware-backed authentication into protection for user and AI agent identities, with trust and service as the core message.
Why it matters: That matters because IAM teams now have to assess how human login controls, NHI governance, and emerging autonomous identity patterns fit into one trust model.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
👉 Read Yubico's discussion of AI identity strategy and trust-driven growth
Context
Digital identity security now spans more than human login flows. Once a vendor starts talking about protecting AI agent identities end to end, the real question for practitioners is whether existing IAM and NHI controls can describe ownership, trust, and revocation clearly enough for both people and software actors.
Yubico's message is also a signal that hardware-backed authentication is being positioned alongside broader identity lifecycle and trust services, not as a point product. For IAM, PAM, and NHI teams, that shifts the discussion from authentication alone to how identity is provisioned, governed, and retired across users, service accounts, and emerging agentic systems.
For a deeper baseline on how these identity classes are defined and governed, see the Ultimate Guide to NHIs and the 2025 outlook section in the same resource.
Key questions
Q: How should security teams govern human, machine, and AI agent identities in one programme?
A: Start by separating identity behaviour, then unify reporting and policy intent only where the controls genuinely overlap. Humans need authentication and access review discipline, machine identities need secrets, certificate, and lifecycle control, and AI agents need runtime entitlement boundaries. A single programme can cover all three, but it must not force identical enforcement patterns onto different identity types.
Q: Why do hardware-backed authenticators not solve identity governance by themselves?
A: Hardware-backed authenticators reduce phishing and credential theft, but they do not govern downstream access, delegation, or lifecycle risk. If entitlements, secrets, and offboarding remain weak, an attacker or overprivileged user can still abuse valid access after sign-in. The control only strengthens proof of authentication, not the full identity lifecycle.
Q: What breaks when AI agents are managed like ordinary machine identities?
A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review. Ordinary machine identities are repeatable; agents are not. If teams only review entitlements, they miss context shifts, delegated actions, and credential creation inside the session.
Q: What should organisations prioritise when moving to service-based authentication models?
A: Organisations should prioritise enrolment, replacement, recovery, and revocation workflows before expanding the service model. If those lifecycle points are weak, convenience grows faster than control and the result is more exceptions, not better security. Good service design must preserve auditability and consistent policy enforcement.
Technical breakdown
Why hardware-backed identity still matters in AI-driven environments
Hardware-backed authentication binds a cryptographic credential to a physical authenticator, which raises the cost of phishing, replay, and token theft. In enterprise identity programmes, that matters because the strongest login proof is only one layer. If downstream entitlements, secrets, and delegated access remain poorly governed, the authentication strength does not prevent abuse after sign-in. As AI-enabled workflows grow, the same trust anchor may need to support both human users and service-driven identity flows, but only if the lifecycle around it is controlled.
Practical implication: treat hardware-backed login as one trust layer and review whether entitlement, secrets, and offboarding controls are equally mature.
AI agent identities and the problem of end-to-end trust
An AI agent identity is not just an account with a passwordless factor. It is a runtime identity that may request tools, access data, and act across systems on behalf of an organisation. That makes trust end to end, from provisioning and scoping through revocation and auditability. The governance challenge is that existing IAM models were built around stable human actors or predictable service accounts, while agent behaviour can be more dynamic. If ownership, purpose, and permitted actions are unclear, trust breaks at the delegation layer.
Practical implication: map AI agent ownership, tool access, and revocation criteria before those agents are allowed to touch production systems.
Service models for identity change operational control points
A service-based identity offering changes more than commercial packaging. It can shift control points from one-time device issue to ongoing lifecycle management, distribution, recovery, and policy enforcement across devices and locations. For practitioners, that matters because the operational burden moves from a discrete authentication event to continual governance of who can enrol, replace, recover, and reissue credentials. In large environments, that lifecycle discipline is what determines whether strong authentication actually scales without creating support-driven exceptions.
Practical implication: validate enrolment, replacement, and recovery workflows before moving authentication at scale into a service model.
NHI Mgmt Group analysis
Hardware-backed authentication is no longer just a phishing-control conversation. As identity stacks expand into AI agent governance, the control problem moves from proving a person is present to proving that every actor in the chain is owned, scoped, and revocable. That widens the identity perimeter and makes lifecycle governance more important than the factor itself. Practitioners should judge these models by what they let the organisation govern after authentication, not only by how they authenticate.
AI agent identity protection collapses the old separation between human IAM and NHI governance. Once agent identities are part of the same trust story, the programme has to answer who owns the agent, what tools it can call, and how access is withdrawn when purpose changes. That is not a branding exercise, it is a governance boundary question. Security teams should treat agent identity as a lifecycle problem that sits between IAM, NHI, and access policy.
Service-based identity models favour operational scale, but scale without governance just expands the exception queue. Self-service ordering, replacement, and deployment can reduce friction, yet every convenience path becomes a potential control gap if issuance, recovery, and revocation are not tightly defined. This is where identity programmes either become usable at enterprise scale or accumulate unmanaged workarounds. Practitioners should align service convenience with explicit lifecycle controls.
Trust architecture is shifting from authentication assurance to identity assurance. The market is moving toward systems that can follow an identity through issuance, use, delegation, and retirement. That is the right direction, but it also means organisations need to measure whether their current programmes can still explain accountability when the actor is a user, a service, or an AI system. Practitioners should expect identity governance to become more cross-domain, not less.
From our research:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- For the broader lifecycle context, Ultimate Guide to NHIs , 2025 Outlook and Predictions shows why identity trust is shifting toward agentic and machine-scale controls.
What this signals
Identity programmes will increasingly be judged on whether they can govern actors after authentication, not just prove them at the door. The practical test is whether ownership, scope, and revocation remain clear when the actor is a user, a service account, or an AI system. The strongest models will connect human IAM, NHI governance, and agent oversight into one control story.
AI agent identity is becoming a new governance boundary, not a niche technical exception. Teams that already struggle with service account visibility will find that agentic systems amplify the same problems of ownership, entitlement drift, and auditability. The sooner that identity lifecycle is mapped across all actor types, the less exception debt accumulates.
Trust debt: when an organisation can authenticate an actor but cannot promptly explain, limit, or revoke what that actor can do. That debt grows when convenience layers outpace governance layers, which is why lifecycle controls and secret hygiene must be measured together.
For practitioners
- Define ownership for every non-human and agent identity Assign a named business owner, technical custodian, and revocation trigger for each service account, token, or AI agent before granting access to production systems.
- Rework lifecycle controls around issuance and revocation Test whether enrolment, replacement, recovery, and offboarding workflows work at enterprise scale without manual exceptions or shared admin accounts.
- Separate authentication strength from governance maturity Review whether strong login methods are masking weak entitlement review, weak secret handling, or weak offboarding across human and machine identities.
- Inventory AI agent access paths now Document every tool, API, and data source an AI agent can reach, then link that inventory to approval, monitoring, and withdrawal processes.
- Measure service friction against control drift Track where self-service provisioning or replacement creates gaps in approval, audit evidence, or post-issue policy enforcement.
Key takeaways
- The core issue is not authentication strength alone, but whether identity governance can follow every actor through its full lifecycle.
- The evidence points to a persistent control gap between notification and revocation, which is exactly where abuse continues to happen.
- Practitioners should use this shift to recheck ownership, scope, and offboarding for human, machine, and AI agent identities together.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | The article touches agent and service identity governance, which maps to core NHI identity controls. |
| NIST CSF 2.0 | PR.AC-4 | The post is about controlling access and trust across identity types, which aligns with access management. |
| NIST Zero Trust (SP 800-207) | The trust discussion fits Zero Trust principles around continuous verification and reduced implicit trust. |
Map identity issuance and revocation processes to PR.AC-4 and verify access is reviewed across all actors.
Key terms
- AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
- Hardware-Backed Security: Hardware-backed security uses device components such as secure enclaves or trusted execution features to protect keys and sensitive operations. It matters because software-only testing environments cannot fully reproduce the behaviour or exposure conditions of a production device.
- Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- The reported fixed-currency booking trend and subscription momentum behind the business shift.
- The five strategic priorities described for digital identity, including service delivery and platform expansion.
- The market-facing framing around AI risk, customer trust, and enterprise deployment simplicity.
- The investor-day context that explains how the vendor is positioning its identity roadmap.
👉 The full Yubico article covers the strategy roadmap, operating priorities, and 2026 focus areas.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org