TL;DR: AI and non-human identities dominated Identiverse 2025, and Saviynt used the event to argue that identity programmes must evolve for autonomous AI agents, cross-functional governance, and converged control across human and machine identities. The central assumption breaking down is that identity is stable, enumerable, and governed by human-paced review cycles.
NHIMG editorial — based on content published by Saviynt: Saviynt Brings Innovation and Expertise to Identiverse 2025, focusing on identity security for AI and NHIs
Questions worth separating out
Q: How should security teams govern AI agents and NHIs differently?
A: Security teams should govern NHIs as predictable machine identities and AI agents as runtime actors that can alter behaviour after authentication.
Q: Why do AI agents complicate traditional access reviews?
A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.
Q: What do IAM teams get wrong when they treat AI agents like service accounts?
A: They assume an agent is just another fixed non-human identity, when its behaviour may be runtime-driven and tool-selecting.
Practitioner guidance
- Define identity classes explicitly Create a shared taxonomy for human identities, NHIs, and autonomous agents, then map ownership, review cadence, and control requirements to each class.
- Converge entitlement and audit data Unify logs, approvals, and entitlement records into one evidence model so teams can trace what was approved, what was actually used, and which identity used it.
- Rework access reviews for runtime actors Do not use review processes that assume access remains stable long enough to be periodically certified.
What's in the full article
Saviynt's full post covers the event-specific examples and product positioning this analysis intentionally leaves aside:
- Session-level context from Identiverse 2025 conversations and panels that shaped the discussion on AI and NHIs
- Product and platform detail on how the Identity Cloud is described for converged governance across identity types
- Customer example material from the GE HealthCare discussion and the ISPM framing used in the article
- Additional commentary from Saviynt speakers on the evolving identity workforce and IAM operating model
👉 Read Saviynt's Identiverse 2025 commentary on AI agents and NHI governance →
AI agent identity governance at Identiverse 2025: what changed?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI agent governance is becoming the new test of whether an identity programme is actually lifecycle-aware. The article shows that identity teams can no longer stop at human users and service accounts. Once autonomous AI enters the environment, lifecycle, access, and accountability must cover systems that can act, select tools, and change behaviour at runtime.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: How can organisations tell whether NHI governance is actually working?
A: NHI governance is working when every machine identity has an owner, a purpose, a minimum-necessary entitlement, and evidence of rotation and review. If teams can produce that chain without manual reconstruction, the programme is mature enough to withstand audit pressure. If they cannot, the governance model is still fragmented.
👉 Read our full editorial: AI agent identity governance is now central to identity security