TL;DR: AI agents, service accounts, API keys, and other non-human identities now outnumber human identities by 1:82 in modern enterprises, while IBM X-Force 2026 and IBM’s 2025 breach research both point to identity-related incidents and compromised credentials as recurring attack vectors. The governance model has shifted from periodic review to continuous identity posture management because autonomous and machine identities can widen exposure faster than traditional IAM controls can observe.
NHIMG editorial — based on content published by Saviynt: Every AI Agent Is an Identity. Are You Governing Them?
By the numbers:
- The ratio of human to non-human identities in modern enterprises has reached a staggering 1:82.
- According to IBM X-Force 2026, identity-related incidents have been one of the most common attack vectors for three consecutive years.
- The IBM Cost of a Data Breach Report 2025 found that compromised credentials remain among the top three initial attack vectors.
Questions worth separating out
Q: How should organisations govern AI agents that can keep gaining access over time?
A: Treat every AI agent as a time-bound identity with a defined purpose, explicit scope, and a removal trigger.
Q: Why do AI agents increase non-human identity risk in existing IAM programmes?
A: AI agents increase non-human identity risk because they create more autonomous actors that can hold credentials, access systems, and perform tasks without direct human supervision.
Q: What do organisations get wrong about non-human identity governance?
A: They often treat service accounts and other machine identities as secondary to human access, which leaves ownership and lifecycle control unclear.
Practitioner guidance
- Build a complete AI agent inventory Catalog every AI agent, service account, API key, and token that can act independently, then assign an accountable owner and business purpose for each identity.
- Replace periodic reviews with continuous posture checks Track entitlement drift, dormant access, and revocation effectiveness continuously so that AI agent permissions are measured while they are still active, not only at the next certification cycle.
- Separate agent access from human role assumptions Do not mirror human entitlements into AI agents by default.
What's in the full article
Saviynt's full blog covers the operational detail this post intentionally leaves for the source:
- Identity Watch assessment workflow across AWS, Saviynt, and IBM components for teams that need implementation detail.
- Breakdown of the specific identity risk categories surfaced by the assessment, including dormant accounts and toxic entitlements.
- Board-facing reporting examples that show how posture findings are translated into risk and compliance language.
- The article's own view of how ISPM fits alongside IAM, PAM, and SIEM in an enterprise control stack.
👉 Read Saviynt's analysis of AI agent identity governance and Identity Watch →
AI agent identity governance is now the control plane question?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI agent identity governance is now a control-plane problem, not an access-admin problem. The article correctly frames identity as the operating foundation for AI adoption because agents inherit and combine access across systems in ways that traditional point controls do not track well. That means IAM, IGA, and PAM have to be treated as a single governance fabric across human and non-human actors. Practitioners should stop asking where the agent was created and start asking what control plane owns its behaviour.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
A question worth separating out:
Q: Who is accountable when a service account or AI agent is over-privileged?
A: The accountable human owner and the identity governance process are both in scope. Teams need a named owner, a clear purpose, and a review trail that shows when access was approved, certified, or revoked. Without that, responsibility becomes diffuse and remediation slows down.
👉 Read our full editorial: AI agent governance becomes the new identity control plane