TL;DR: 91% of production identities are non-human, but the harder problem is that AI agents can operate under human credentials and inherit legitimate sessions that identity providers and SIEMs cannot distinguish from human use, according to ClearVector. That collapses attribution, scope, and incident response unless teams track runtime activity per identity, not just authentication events.
NHIMG editorial: based on content published by ClearVector: Is this identity still human? AI agents running under human credentials
By the numbers:
- 91% of identities in production are non-human, according to ClearVector Identity Intelligence Report 2026.
- ClearVector observed AI agents in production at multiple customers in the fourth quarter of 2025.
Questions worth separating out
Q: What breaks when an AI agent uses a human production credential?
A: The control that breaks is actor attribution.
Q: When do AI agent credentials create more risk than they reduce?
A: They create more risk when they are long-lived, over-scoped, hard to revoke, or copied into code and prompts.
Q: How do security teams know whether an agent is using credentials within scope?
A: They need to compare the credential’s expected purpose with the sequence of actions that follows authentication.
Practitioner guidance
- Implement runtime identity attribution Map each credential to the actions it performed in production, not just the login event, so you can answer what ran, when, and under whose authority.
- Separate human authentication from non-human execution Flag sessions where a human-issued credential is used by scripts or AI agents, then route those sessions into a distinct review and containment path.
- Build a pattern of life baseline Record normal activity per identity across production so deviations in order, timing, rate, and systems touched can be detected quickly.
What's in the full article
ClearVector's full perspective covers the operational detail this post intentionally leaves for the source:
- How to trace runtime activity per credential across production systems and downstream pipelines
- How to distinguish human authentication from non-human execution inside the same session
- How to narrow rotation and notification to only the credentials actually exercised during an incident
- How to build an operating model for pattern-of-life analysis across humans, NHIs, and third parties
👉 Read ClearVector’s perspective on AI agents running under human credentials →
AI agents under human credentials: what identity teams are missing?
Explore further
Identity attribution is now a control boundary, not a logging convenience: when a credential can be used by a person, a script, or an AI agent, authentication no longer answers the governance question. The real issue is runtime attribution, because access approval does not explain who exercised that access. Programmes that stop at sign-in records are already blind to delegated non-human behaviour.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations treat AI agents like human users in IAM?
A: No. Human IAM assumes a person logs in, works within a session, and can be reviewed later as a stable identity holder. Agents can act at machine speed, across multiple systems, and with changing runtime context, so they need identity governance built around execution and delegation rather than human authentication patterns.
👉 Read our full editorial: Human credentials no longer prove human action in production