Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent identity sprawl: what the rule of 17 means for teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: Organisations now have roughly one AI agent for every 17 identities, alongside 54% of enterprise apps containing AI functionality and 490% year-over-year growth in AI-related attacks, according to Grip Security. The finding shows that identity governance is now being stretched by AI-enabled access patterns that traditional human-centric IAM cannot fully see or control.

NHIMG editorial — based on content published by Grip Security: The Rule of 17: What AI Agent Growth Means for Security Teams

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do AI agents create more identity risk than ordinary SaaS integrations?

A: AI agents can operate continuously, chain multiple tools, and act on delegated permissions with little human oversight.

Q: What breaks when access review does not cover non-human identities used by AI agents?

A: When access review ignores the NHIs behind AI agents, organisations lose visibility into stale privileges, inherited rights, and abandoned credentials that still allow action.

Practitioner guidance

  • Inventory AI-enabled identities across SaaS Build a consolidated register of AI agents, embedded AI features, delegated apps, and service accounts that can initiate or continue workflow actions.
  • Map delegation chains end to end Trace how access is inherited from users to applications to back-end identities, then identify where AI functionality sits inside that chain.
  • Classify AI access by downstream blast radius Prioritise AI-enabled identities based on the data sets and systems they can reach, not on application labels alone.

What's in the full article

Grip Security's full webinar covers the operational detail this post intentionally leaves for the source:

  • Breakdown of the Rule of 17 methodology and how the ratio was derived from SaaS and AI identity data
  • Examples of how AI agents inherit permissions through OAuth grants, connected applications, and service accounts
  • Operational guidance on discovering AI-enabled applications and mapping access relationships across SaaS estates
  • Webinar-specific examples of how security teams can monitor AI activity continuously in live environments

👉 Watch Grip Security's webinar on the Rule of 17 and AI agent growth →

AI agent identity sprawl: what the rule of 17 means for teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

AI agents have crossed from feature-level automation into governed identity territory. Once an AI system can touch applications, data, and workflows, it is no longer just a capability flag inside SaaS. It becomes a non-human identity with access scope, lifecycle risk, and review obligations. That shifts the question from whether AI exists in the stack to which identities are being created by it. Practitioners should treat every AI-enabled workflow as an identity governance event.

A few things that frame the scale:

A question worth separating out:

Q: Who should be accountable for AI agent actions in enterprise systems?

A: Accountability should sit with the team that owns the agent, its policies, and the connected tools, not only with the person who typed the original prompt. When a software actor can send messages, update records, and move data across systems, responsibility must follow the governed identity and its enforcement layer.

👉 Read our full editorial: The rule of 17 shows AI agent growth is outpacing IAM controls



   
ReplyQuote
Share: