TL;DR: The median enterprise now has 3.6 working AI agents for every technical employee, 84% of measured environments have agents outnumbering staff, and agent populations are growing 29% a month across live environments, according to Clutch Security research. That shifts identity governance from user provisioning to runtime control of agent-held credentials and production access.
NHIMG editorial — based on content published by Clutch Security: One Laptop, Four Agents, 88 Credentials
By the numbers:
- In 84% of the environments we measured, agents outnumber the technical staff they work alongside.
- The population grows 29% a month, doubling roughly every ten weeks.
Questions worth separating out
Q: How should security teams govern AI agents that rely on shared runtime credentials?
A: Security teams should treat every AI agent as a workload identity with a defined task boundary, then issue only the minimum access required for that task.
Q: Why do AI agents create new risk in non-human identity management?
A: AI agents create risk because they operate as software identities with delegated authority, but many organisations do not track them with the same discipline applied to users or service accounts.
Q: What breaks when joiner-mover-leaver processes are applied to AI agents?
A: The human assumption behind JML breaks down.
Practitioner guidance
- Run an agent census before the planning cycle ends. Inventory every working agent, the machine it runs on, the credentials it holds, and the production systems it can reach.
- Treat agent production access as privileged access. Define a policy for what agents may touch in production and enforce it in the agent runtime, not in documentation.
- Bring agents into your identity lifecycle. Extend provisioning, recertification, monitoring, and offboarding to agents that use credentials in production.
What's in the full report
Clutch Security's full report covers the operational detail this post intentionally leaves for the source:
- Per-environment census methodology showing how working agents were counted across live enterprise estates
- The one-laptop case study that breaks down the 88 credentials and 29 credentialed tools involved
- Observed production access patterns across databases, cloud IAM roles, source control, and SaaS platforms
- The full guidance on how Clutch suggests teams build an honest agent inventory from real behaviour rather than approved lists
👉 Read Clutch Security's full report on one laptop, four agents, and 88 credentials →
AI agent identity sprawl: what it means for IAM teams?
Explore further
AI agent identity is becoming a separate governance class, not a variant of workload identity. The article’s central finding is that working agents are already behaving like identity-bearing actors with real production reach, not like passive automation. That means traditional workload controls are no longer enough on their own. Identity teams need to classify agents as governable identities with their own lifecycle, entitlement, and monitoring expectations.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: Who should own AI governance when agents connect to production systems?
A: Ownership should sit with the team responsible for the data, tools, and transactions the agent can touch, with IAM and security architecture enforcing the boundaries. If nobody can explain who approved the access, who can revoke it, and who reviews the actions, the agent is over-scoped by default.
👉 Read our full editorial: AI agents are outnumbering technical staff and bypassing IAM