Join our Newsletter — 33% off our NHI Course

Agentic AI and NHI growth: what IAM teams need to rethink

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Enterprises are moving from roughly 45 non-human identities per human in 2023 to an 82:1 ratio in 2025, while early adopters report 300% to 500% annual NHI growth as AI agents combine multiple credentials across systems, according to Clutch Security. The identity problem is no longer scale alone; autonomous tool use breaks static provisioning assumptions and makes traditional IAM visibility insufficient.

Editorial analysis by NHI Mgmt Group, based on content published by Clutch Security: “The Enterprise Agentic AI Security Crisis No One Is Ready For”.

By the numbers:

  • Enterprises typically managed about 45 NHIs per human identity in 2023, according to Clutch Security.
  • Early adopters are seeing 300% to 500% annual NHI growth as agentic AI spreads, according to Clutch Security.
  • In 2025, an 82:1 ratio is the new reality for NHIs to human identities, according to Clutch Security.

Key questions

Q: What breaks when agentic AI is allowed to act with embedded credentials?

A: The control problem changes from isolated secret protection to governed runtime access.

Q: Why do read-only AI agents still create serious security risk?

A: Read-only agents can still expose secrets, topology, environment variables, and other sensitive operational data.

Q: How do security teams know whether an agent identity is actually governed?

A: An agent identity is governed only when teams can identify the owner, locate the credentials, define the allowed scope, and revoke access without hunting across endpoints or backup files.

Practitioner guidance

  • Inventory every agent and its credentials Build a current register of sanctioned and unsanctioned agents, then map each one to the tokens, service accounts, and API keys it can use.
  • Separate read and write access paths Give agents read-only access by default and require stronger approval and tighter scope for any write-capable workflow that can change state.
  • Tie each NHI to an owner and an offboarding path Require explicit ownership, lifecycle dates, and revocation procedures for every agent credential so shadow deployments cannot persist indefinitely.

Bottom line: Agentic AI is accelerating NHI sprawl by making one runtime actor consume multiple credentials across systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Agentic AI creates an identity problem before it creates an AI governance problem. The article shows that autonomous tool use increases the number of credentials in circulation and changes how those credentials are consumed at runtime. That means the immediate governance issue is not model quality, but whether IAM can still enumerate, scope, and revoke identities that do not behave like users or scripts.

A few things that frame the scale:

A question worth separating out:

Q: What do IAM teams get wrong when they treat AI agents like service accounts?

A: They assume an agent is just another fixed non-human identity, when its behaviour may be runtime-driven and tool-selecting. That can lead to under-scoped oversight, misplaced trust in static entitlements, and review processes that do not match how the actor actually operates.

👉 Read our full editorial: Enterprise agentic AI is driving NHI growth beyond IAM control


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.