Join our Newsletter — 33% off our NHI Course
NHI Mgmt Group Blogs

Non-Human & AI Identity Blogs

Hand-picked posts on non-human identity, IAM and agentic AI security from NHI Mgmt Group and our partners.

Showing 203 blogs
Saviynt

The Privilege Spectrum: Why 'Privileged or Not' Is the Wrong Security Question

Blog post
C1.ai

Introducing C1 AppHub: connect AI-built apps to the controls they need

Announcement
P0 Security

Your agent reached the MCP gateway. Now what?

Event
Teleport

How to Eliminate Shared Production Kubeconfigs

Blog post
Akeyless

The 47-Day Certificate Era: Are Your Machine Identities Ready?

Event
Akeyless

47-Day Certificates: What Changes and How to Prepare

Blog post
Unosecur

Unosecur extends identity security to Oracle Cloud Infrastructure

Announcement
C1.ai

Transform 26 CONFERENCE 2026 26

Event
Venice.io

AI agent security: What identity teams need to know in 2027

Blog post
GitGuardian

The Hidden Credential Risk in Developer Workstations

Announcement
PlainID

Agentic IAM Day 2026

Event
C1.ai

You Can't Govern the AI Agents You Can't Find

Blog post
GitGuardian

OWASP France Meetup

Event
Ambient Security

Non-Human Identity Security: Governing the Identities That Outnumber Your People

Blog post
Nexis

Let Identity Contribute to Your Security

Event
Nexis

Shared Signals: Turning Identity Governance Findings into Real-Time Action

Blog post
Opal Security

Securing the Agentic Enterprise: Identity in the Age of Autonomy

Blog post
Clarity Security

5 IAM Trends to Watch in 2026

Blog post
Arcon

Which Compliance Frameworks Require Endpoint Least Privilege? One EPM Solution, Four Mandates

Blog post
P0 Security

Evaluating agentic access control approaches

Blog post
PlainID

How runtime authorization helps turn EU AI Act requirements into enforceable controls

Blog post
GitGuardian

Vulnerability Disclosure Policy Template and Setup Guide

Blog post
Unosecur

AI agent credential lifecycle: issuance, storage, rotation and revocation

Blog post
GitGuardian

Black Hat SecTor 2026

Event
Nexis

IVIP in 2026: Why Visibility Alone Is No Longer Enough

Blog post
Opal Security

Introducing Opal Zero: Q&A with CPO Sameer Mehta

Announcement
Opal Security

10 Recent Breaches that Could Have been Prevented with Modern IGA

Blog post
C1.ai

Anatomy of a decoy: what happens when someone uses a stolen credential

Blog post
C1.ai

C1.ai is now available in Europe

Announcement
Unosecur

AI agent authentication: Api keys, OAUTH tokens, certificates or workload identities?

Blog post
Teleport

Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

Announcement
Teleport

What PCI DSS 4.0 Requires for Infrastructure Identity and Access Evidence

Blog post
Venice.io

Venice integrates with the Claude Compliance API to bring every Claude identity under just-in-time access

Announcement
Clarity Security

Why the PocketOS Incident Is an Identity Security Problem

Blog post
P0 Security

Nobody built MCP servers to hold identity. They do anyway.

Blog post
Saviynt

AI Is Raising the Stakes for Modern PAM

Blog post
Akeyless

The Complete Guide to Multi-Vault Secrets Governance

Blog post
Ambient Security

Hidden Privileged Access: The Risk Your Access Reviews Miss

Blog post
Arcon

The Rising Sophistication of Endpoint Security Threat Patterns: Why CISOs Must Rethink Privilege Control

Blog post
GitGuardian

Les Assises de la Cybersécurité 2026

Event
Nexis

Documented Is Not Proven: The Case for Continuous Compliance Monitoring

Blog post
Saviynt

How Privileged Can Your AI Become? More Than You Might Think

Blog post
Opal Security

Paladin, Opal’s access agent, is now available in on-prem, self-hosted deployments

Announcement
Clarity Security

Beyond Human: What Lalit Choda and Alexis Moyse Are Telling Security Teams About Non-Human Identity and AI Agent Security

Blog post
C1.ai

Security Isn't the Brake on Your Agentic Migration. It's the Engine.

Blog post
P0 Security

The three types of JIT (And why only one actually kills standing access)

Blog post
Opal Security

Supercharging Identity with Opal and Databricks

Blog post
PlainID

How to Get Started with Authorization Strategy

Blog post
Unosecur

AI Agent Security Tools for Enterprise: 12 Capabilities to Evaluate

Blog post
Teleport

Navigating SAMA, ADGM & DFSA Requirements with Teleport

Blog post
GitGuardian

The Business Case for Secrets Security

Blog post
Akeyless

Why Secrets Sprawl Grows in Large Enterprises

Blog post
P0 Security

Agent provenance is ambitious, so let’s get the hard parts right

Blog post
Arcon

What Is Endpoint Privilege Management – and How Is It Different from PAM?

Blog post
Saviynt

The AI Bell Has Been Rung. A CISO’s Next Steps.

Blog post
Unosecur

AI Agent Discovery: Complete Inventory, Absolute Visibility

Blog post
Nexis

The ECB Action Plan Against AI Cyberattacks: What Banks Must Submit by 31 October 2026

Blog post
C1.ai

Your Engineers Are Building the Same Agent Twelve Times. Here's How to Stop It.

Blog post
Akeyless

Mastering Multi-Cloud Secrets: Your Guide to Overcoming Security Challenges

Blog post
Opal Security

Building What's Next: A Conversation with CPO Sameer Mehta

Blog post
GitGuardian

The Future Of GitHub Actions Security And What You Can Do Right Now

Blog post
Teleport

How to Prevent RBAC Role Explosion with Nested Access Lists

Blog post
Clarity Security

What ISACA GRC 2026 Made Clear About the Future of Governance, Risk, & Compliance

Blog post
Newcore

Your Identity Platform Is a Generation Behind. It's Time for a Smarter Upgrade.

Blog post
NHI Mgmt Group

Governing the Invisible: Closing the NHI Governance Gap in the Age of Agentic AI

Blog post
P0 Security

From MCP Tool Filtering to Runtime Access Control

Blog post
GitGuardian

Innovate Fall 2026 - Scottsdale

Event
GitGuardian

Securing Coding Agents Across Your Team

Blog post
Opal Security

New in Opal: Paladin, Access Campaigns, and OpalScript hit GA

Announcement
Saviynt

What Cross-Application Risk Actually Looks Like

Blog post
C1.ai

Launch Week Roundup: The Agentic Control Plane

Announcement
C1.ai

The Most Important AI Meeting You'll Have This Quarter Costs Nothing

Blog post
Opal Security

From Slack Request to Governed Grant: How Opal and Risotto Make Access Self-Serve

Blog post
Unosecur

Identity security in civil aviation: The attack surface hiding behind trusted access

Blog post
Teleport

We Had 13 Engineers Spend Three Months Finding Vulnerabilities with LLMs

Blog post
Arcon

Operational Technology Cybersecurity Controls (OTCC)

Blog post
Akeyless

Not All Just-in-Time Access Is Created Equal: Why JIT Architecture Matters

Blog post
Clarity Security

The Ultimate IT Offboarding Checklist and Template

Blog post
Nexis

Nexis Included in the New KuppingerCole Analysts Leadership Compass for Identity and Access Governance 2026

Blog post
Newcore

Why Legacy IAM Fails

Blog post
Venice.io

How 30 Years of Privileged Identity is About to Change

Blog post
Opnova

Leaver for AI Agents: You Fired the AI. Did It Actually Leave?

Blog post
Nexis

Zero Trust Depends on the Access Beneath It

Blog post
Opal Security

OAuth for Opal MCP: give agents access, not a standing key

Announcement
C1.ai

The OpenAI–Hugging Face Attack and the Third Generation of Authorization

Blog post
Clarity Security

The Three Stages of Identity Security Maturity and Why Most Programs Were Built for the Wrong Problem

Research report
Saviynt

Introducing Zuma: The Enterprise AI Identity Security Platform

Announcement
Saviynt

Every AI Agent Is an Identity. Are You Governing Them?

Blog post
Akeyless

Akeyless Integrates With Claude’s Compliance API to Secure AI Agent Access

Announcement
GitGuardian

AI Agents Authentication: How Autonomous Systems Prove Identity

Blog post
Akeyless

OWASP Secrets Management Cheat Sheet: Reducing Static Secrets in Practice

Blog post
Unosecur

Identity system misconfigurations: How small access mistakes become attack paths

Blog post
P0 Security

When your coding agent can commit everything you can commit

Blog post
Teleport

How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go’s SSH Library

Blog post
PlainID

AI Agent Authorization: Why Static Roles Break

Blog post
Opnova

The Business Case for Governing AI Agents

Blog post
Newcore

Building a Secure Core for Your Identity

Blog post
GitGuardian

No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours

News story
C1.ai

Introducing agentic security and intelligence: close identity risk with C1

Announcement
P0 Security

​Why Authentication Is Not Enough For Agents

Blog post
Akeyless

Akeyless Brings Secretless Access to OpenAI Codex

Announcement
GitGuardian

GitGuardian Platform Demo - November 18, 2026

Event
Nexis

NEXIS Impulse July

News story
Unosecur

The OpenAI and Hugging Face Incident: A Briefing for Boards and Security Leaders

Blog post
P0 Security

Agents are redefining sensitive access and P0 is leveraging AI to extend coverage just as fast

Announcement
Opal Security

Authn and Authz: Two Sides of the IAM Coin

Blog post
Opal Security

New in Opal: Access Comparison, Find and Fix Outlier Access Fast

Announcement
Clarity Security

What Is Adaptive Trust and Why Your Identity Program Probably Hasn’t Reached It Yet

Blog post
C1.ai

Why AI Transformation Stalls

Blog post
PlainID

PlainID and Cisco Duo: Real-Time Authorization at SSO Sign-In

Announcement
Akeyless

Doppler Alternative: Secrets Management vs. Identity Security

Blog post
Saviynt

Onboarding as Code: How Saviynt's Terraform Provider Solves Identity Governance's Hardest Problem

Blog post
Teleport

Guide: Certificate-Based Authentication for Payment & Banking Infrastructure

Blog post
C1.ai

C1 Launches Agentic Security and Intelligence to Close Identity Risk

Announcement
Teleport

Kubernetes for Agentic AI: Best Practices for Identity and Access

Blog post
Unosecur

Authorize the task, not the intent

Blog post
Opal Security

What's new in Opal's MCP servers: self-hosted, scoped, and approval-ready

Announcement
Akeyless

The Hugging Face Breach Comes Down to a Credential Problem

Blog post
P0 Security

The OpenAI agent did not go rogue. It ran out of authorization boundaries.

Blog post
C1.ai

Introducing agent runtime governance: intent-based access control for AI agents

Blog post
Opal Security

How to Automate On-Call Access Management with Opal and PagerDuty

Blog post
PlainID

PlainID Brings Google BigQuery’s Native Data Controls Into One Control Plane

Announcement
Arcon

DORA Compliance: Building IT Operational Resilience of EU Organizations

Blog post
Saviynt

Zero Standing Privilege for AI Agents: Privilege as Spectrum

Blog post
Nexis

From IGA Complexity to IVIP

Blog post
PlainID

Five Factors for Choosing a Modern Authorization Solution

Blog post
Unosecur

You Cannot Govern What You Don't See: A Study on the GitLost Incident

Blog post
Akeyless

Your AI Agent Just Logged In. Now What?

Blog post
Akeyless

Named in Two Gartner Reports, Akeyless Anchors the New Workload IAM Architecture

Announcement
Clarity Security

Automating User Access Reviews: A Practical Guide to Reducing Manual Work

Blog post
GitGuardian

SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top

Blog post
Unosecur

Unosecur’s Office 365 Connector Unifies Identity Security

Announcement
Saviynt

Building Trust for AI Agents: From Accountability to Audit

Blog post
P0 Security

OAuth scopes don’t equal secure MCP authorization

Blog post
Teleport

How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

Blog post
C1.ai

C1 Deploy: Introducing C1 Bridge

Announcement
C1.ai

Four Things Your Identity Stack Needs Before Agents Hit Production

Blog post
Nexis

NEXIS in EMEA: What Gartner Peer Insights™ Industry Data Reveals

Announcement
Opal Security

Privileged Access Management: Gatekeeping for the Greater Good

Blog post
Nexis

From Patchwork to Governance: The Role of IVIP in Modern Identity Fabrics

Blog post
Akeyless

What KuppingerCole Reveals About the Convergence of Secrets Management and NHIM Security

Blog post
Clarity Security

User Lifecycle Management Tools: Automating Onboarding, Offboarding, and Everything in Between

Blog post
Akeyless

Former CyberArk and Cisco Leader Joins Akeyless as It Scales Identity Security for the Agentic Era

Announcement
Unosecur

Why SOC 2 Matters and How Unosecur Achieved Compliance with Vanta

Blog post
Unosecur

AI Agent Security Dashboard: See Every Agent's Risk

Announcement
Clarity Security

Clarity Security Launches Aperture, Moving Identity Security Beyond Governance

Announcement
P0 Security

Every era has its “worked great” tech. Then the environment changes.

Blog post
Teleport

Your AI Agent Needs to Know Who You Are

Blog post
C1.ai

Security Needs a Second Floor

Blog post
PlainID

Intent-Based Access Control for AI Agents

Blog post
Opal Security

Collecting the right signals for intelligent authorization

Blog post
Clarity Security

Who Governs AI? Why Identity Governance Should Come Before AI Adoption

Blog post
Teleport

Automating Identity and Access for FedRAMP 20x KSIs with Teleport

Blog post
Akeyless

Akeyless vs. CyberArk

Announcement
Unosecur

Six Identity Security Risks in M&A and How to Prevent Them

Announcement
Unosecur

From Package Poisoning to Cloud Admin — Identity-Driven Analysis

Blog post
P0 Security

The day “access” stopped meaning “login” and started meaning “authorization”

Blog post
GitGuardian

Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide

Blog post
Saviynt

Rethinking Application Access Governance for the AI Era

Blog post
Akeyless

The Billion-Dollar Question: Are Financial Institutions Safe from Their Own Secrets?

Blog post
PlainID

BigID & Plainid Partner on Enterprise Data Protection

Announcement
PlainID

Identity-First Security in the Evolving Threat Landscape

Blog post
C1.ai

Custom Connectors: Simplifying Integrations Without Code

Blog post
Akeyless

Akeyless Platform Adds New Desktop Password Manager and Web Console

Announcement
Saviynt

The Identity Control Plane: Why Saviynt Is an Overall Leader of Privileged Access Management

Announcement
Unosecur

Cisco & EU Breaches 2026: How Stolen Credentials Compromised Entire Systems

Blog post
Unosecur

Secure On-Premise Identity Visibility Without Opening Your Network

Announcement
Teleport

How to Make Trading Infrastructure Audit-Ready Across SSH, Kubernetes, Databases, and RDP

Blog post
Akeyless

Six Months, Three GovCloud Accounts, Zero Excuses: Lessons from the CISA GitHub Leak

Blog post
Saviynt

The Intelligence as a Service Era: How Agentic AI Reshapes Enterprise Software

Blog post
GitGuardian

@bitwarden/cli - GitGuardian Views on helloworm00

News story
C1.ai

The Identity Stack Was Built for Humans. Agents Don't Care.

Blog post
Akeyless

Akeyless Achieves FIPS 140-3 Validation: What It Is and Why It Matters

Announcement
GitGuardian

What the Mythos-Ready Briefing Says About Credentials

Blog post
Akeyless

AI Agents and Machines Can’t Keep Secrets

Blog post
Unosecur

Vercel Breach: How an AI Tool OAuth Grant Exposed Env Vars

Blog post
Akeyless

The Vercel Breach and the Case for Ephemeral Secrets

Blog post
GitGuardian

The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords

Research report
P0 Security

When your Snowflake AI agent can query everything you can query

Blog post
Saviynt

AI Agents Aren’t Trustworthy (But We’re Deploying Them Anyway)

Blog post
Saviynt

Identity Security That Pays Off: Saviynt Customers Achieve 269% ROI

Announcement
Akeyless

Top 5 Non-Human Identity Management Tools for 2026

Blog post
Teleport

How Claude Helped Build a Proxmox Environment (and What I Learned Along the Way)

Blog post
Akeyless

Akeyless Launches Runtime Authority for AI Agents, Introducing Intent-Aware Security for Autonomous Systems

Announcement
Unosecur

CI/CD Identity Security: Lessons from the TeamPCP Attack

Blog post
Saviynt

Shadow AI Is Creating the Largest Identity Blind Spot in Enterprise Security

Blog post
Teleport

EU AI Act Compliance: Requirements, Risks, and What to Document

Blog post
NHI Mgmt Group

Anthropic Launches Claude Code Security: A New Era of AI-Powered Code Protection

Blog post
NHI Mgmt Group

NHI Foundation Level Training Course Launch

Blog post
NHI Mgmt Group

Complete Guide to the 2026 OWASP Top 10 Risks For Agentic Applications

Blog post
NHI Mgmt Group

Mr. NHIs Top 20 Identity & Access Management (IAM) Evangelists & Voices

Blog post
NHI Mgmt Group

Detailed Write-Up of the NHI Workshop at Identiverse

Blog post
NHI Mgmt Group

52 Non-Human Identity Breaches

Blog post
NHI Mgmt Group

AI Agents And Their Intersection with Non-Human Identities

Blog post
NHI Mgmt Group

GDPR Fines Hit EUR 1.2Bn in 2024 - 363 Data Breaches Per Day

Blog post
NHI Mgmt Group

Cloud API Keys For Sale

Blog post
NHI Mgmt Group

The Holy Grail of Non-Human Identities - Databases

Blog post
NHI Mgmt Group

Non-Human Identity or Machine Identity?

Blog post
NHI Mgmt Group

Exploring SPIFFE / SPIRE

Blog post
NHI Mgmt Group

40 Non-Human Identity Breaches

Blog post
NHI Mgmt Group

The 1st Non-Human Identity Security Conference

Blog post
NHI Mgmt Group

Why do Hackers go after Non-Human Identities?

Blog post
NHI Mgmt Group

Challenges of Rotating Non-Human Identities

Blog post
No blogs match these filters.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.