TL;DR: 2025 exposed a basic identity security failure: human-centric access models could not govern autonomous AI agents or the rapid growth of non-human identities, according to Oasis Security. The real shift is that identity now has to govern action, intent, and accountability, not just authentication and role assignment.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “How 2025 Changed the Way We Think About Identity Security”.
Key questions
Q: What breaks when access review processes are used for autonomous agent governance?
A: Access review processes break when the system under review changes access and action paths within the same operating session.
Q: When should organisations prioritise action governance over role-based access for NHIs?
A: They should prioritise action governance when the identity can execute tasks independently, reuse secrets across systems, or trigger downstream changes without direct human approval.
Q: What are the signs that NHI governance is failing in an enterprise?
A: Common warning signs include unclear ownership for service accounts, secrets stored in code or configuration instead of managed vaults, infrequent rotation, and weak offboarding of API keys.
Practitioner guidance
- Map identities to action, not just access Inventory which service accounts, API keys, and AI agents can initiate actions independently, then classify them by the business tasks they are allowed to execute.
- Assign ownership at identity creation Require a named owner, purpose, and revocation path for every non-human identity before it is allowed into production systems.
- Move policy enforcement to runtime Use continuous policy checks for agentic and machine identities so action approval happens at the moment of execution, not after the fact.
Bottom line: 2025 forced identity programmes to confront a basic mismatch between human-designed controls and machine-speed execution by AI agents and NHIs.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity security is now a control problem about action, not just access. Human-centric IAM models assumed that authentication, roles, and review cycles were enough to govern behaviour. That assumption no longer holds when digital workers can initiate work, select actions, and complete tasks at machine speed. The practitioner conclusion is that identity governance must be evaluated by what an identity can do, not only by what it can log into.
A few things that frame the scale:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
A question worth separating out:
Q: What is the difference between human and machine access governance?
A: Human governance relies on periodic judgment by managers and administrators. Machine governance requires telemetry, ownership mapping, and automated enforcement because access changes too fast for manual review. The key difference is that machine access must be governed continuously, not episodically.
👉 Read our full editorial: Identity security in 2025 moved from access to governed action