TL;DR: Enterprises will deploy 50 to 80 times more AI agents than human users, while most identity programmes still operate on human-scale approval, audit, and lifecycle cycles, according to Strata Identity. That timing mismatch makes visibility, privilege control, and accountability the governing problem, not just another automation challenge.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “Managing scale in the age of agentic AI: 14 problems to solve”.
By the numbers:
- Enterprises will deploy 50 to 80 times more AI agents than human users, according to Strata Identity.
Key questions
Q: What breaks when AI agents are governed with human IAM, IGA, and PAM models?
A: Human identity models assume a known person, a start date, a manager, and predictable access review cycles.
Q: Why do over-scoped tokens create risk for internal AI agents and microservices?
A: Over-scoped tokens increase blast radius because a compromised agent or service can reach more tools, data, and actions than it truly needs.
Q: How do security teams know if agent governance is actually working?
A: It is working only if the team can answer three questions quickly for any agent: what it can reach, what it did recently, and whether that behaviour matches intent.
Practitioner guidance
- Define an agent identity inventory Create a registry for platform-resident, ad hoc, and ephemeral agents with owner, provenance, TTL, and execution context fields.
- Replace standing access with task-scoped authority Reduce OAuth scope and secret reuse so each agent receives only the privileges required for the current task and no broader delegation.
- Bind runtime telemetry to governance decisions Ingest orchestrator, MCP endpoint, and execution logs into a control process that can score risk and detect shadow agents.
Bottom line: AI agent governance is colliding with identity operating models built for slower, human-scale decision cycles.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI exposes a governance assumption that access remains stable long enough to be reviewed. Human-centric IAM and IGA assume privilege can be observed, certified, and recertified on a predictable cadence. That assumption fails when an autonomous agent can acquire, use, and release authority inside a single runtime window. The implication is that identity governance has to shift from periodic review to runtime control for agents.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should organisations do when an AI agent leaves behind zombie credentials?
A: Treat the leftover credential as an offboarding failure, not just a secret hygiene problem. Revoke the token, verify no dependent workflows still trust it, and remove the orphaned privilege path from the registry. If the credential remains valid after the agent is inactive, accountability and access control have both failed.
👉 Read our full editorial: AI agent identity governance is colliding with IAM speed limits