Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent identities and hardware-backed trust: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Identity programmes now have to govern both human authentication and machine trust assumptions, not treat them as separate problems, according to Yubico. The company says it is expanding from hardware-backed authentication into a digital identity platform that protects user and AI agent identities end to end, while also reporting its largest fixed-currency quarterly bookings and accelerated subscription growth.

NHIMG editorial — based on content published by Yubico: an update on its identity strategy, AI agent focus, and 2026 priorities

By the numbers:

Questions worth separating out

Q: How should security teams govern human, machine, and AI agent identities in one programme?

A: Start by separating identity behaviour, then unify reporting and policy intent only where the controls genuinely overlap.

Q: Why do hardware-backed authenticators not solve identity governance by themselves?

A: Hardware-backed authenticators reduce phishing and credential theft, but they do not govern downstream access, delegation, or lifecycle risk.

Q: What breaks when AI agents are managed like ordinary machine identities?

A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review.

Practitioner guidance

  • Define ownership for every non-human and agent identity Assign a named business owner, technical custodian, and revocation trigger for each service account, token, or AI agent before granting access to production systems.
  • Rework lifecycle controls around issuance and revocation Test whether enrolment, replacement, recovery, and offboarding workflows work at enterprise scale without manual exceptions or shared admin accounts.
  • Separate authentication strength from governance maturity Review whether strong login methods are masking weak entitlement review, weak secret handling, or weak offboarding across human and machine identities.

What's in the full article

Yubico's full article covers the operational detail this post intentionally leaves for the source:

  • The reported fixed-currency booking trend and subscription momentum behind the business shift.
  • The five strategic priorities described for digital identity, including service delivery and platform expansion.
  • The market-facing framing around AI risk, customer trust, and enterprise deployment simplicity.
  • The investor-day context that explains how the vendor is positioning its identity roadmap.

👉 Read Yubico's discussion of AI identity strategy and trust-driven growth →

AI agent identities and hardware-backed trust: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Hardware-backed authentication is no longer just a phishing-control conversation. As identity stacks expand into AI agent governance, the control problem moves from proving a person is present to proving that every actor in the chain is owned, scoped, and revocable. That widens the identity perimeter and makes lifecycle governance more important than the factor itself. Practitioners should judge these models by what they let the organisation govern after authentication, not only by how they authenticate.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.

A question worth separating out:

Q: What should organisations prioritise when moving to service-based authentication models?

A: Organisations should prioritise enrolment, replacement, recovery, and revocation workflows before expanding the service model. If those lifecycle points are weak, convenience grows faster than control and the result is more exceptions, not better security. Good service design must preserve auditability and consistent policy enforcement.

👉 Read our full editorial: Yubico's AI identity strategy raises new trust questions for IAM



   
ReplyQuote
Share: