TL;DR: AI identity governance begins with inventory, because organisations cannot govern AI systems they cannot identify, track, or monitor, according to BigID. As Gartner projects 40% of enterprise applications will include task-specific AI agents by 2026, the real problem is inherited access, ownership gaps, and data exposure across expanding AI identities.
NHIMG editorial — based on content published by BigID: Building an AI Identity Inventory
By the numbers:
- 40% of enterprise applications will include task-specific AI agents by 2026, according to Gartner.
- 33% of enterprise software applications will contain agentic AI by 2028, according to Gartner.
- 45 machine identities for every human identity was the median ratio reported in Cloud Security Alliance research.
Questions worth separating out
Q: How should security teams inventory hidden machine and AI identities?
A: Start by aggregating identity data from cloud platforms, SaaS tools, directories, CI/CD systems, and secrets stores into one operational view.
Q: Why do agentic AI systems complicate IAM and IGA programmes?
A: They complicate IAM and IGA because the actor can exercise access dynamically rather than through a stable, human-paced workflow.
Q: What breaks when AI inventory stops at discovery?
A: Security teams can see that AI tools exist, but they cannot tell which ones create risk, who owns them, or what data they can access.
Practitioner guidance
- Inventory AI identities, not just AI tools Create a living register that ties each AI system to an identity record, an accountable owner, inherited permissions, and the data it can reach.
- Trace inherited access end to end Follow each AI identity back through service accounts, APIs, certificates, and role assignments to find the original permission source.
- Prioritise AI identities by data sensitivity Rank AI systems by the sensitivity of the information they can reach, then remediate the ones with customer, regulated, or business-critical exposure first.
What's in the full article
BigID's full blog post covers the operational detail this post intentionally leaves for the source:
- Step-by-step AI identity discovery workflow across cloud, SaaS, and hybrid environments
- The exact fields included in a mature AI identity inventory, including ownership, access paths, and data exposure
- How BigID describes permission analysis and sensitive-data mapping for AI identities
- Implementation guidance for building a centralised inventory process across multiple AI deployment patterns
👉 Read BigID's analysis of building an AI identity inventory →
AI identity inventory: what IAM teams need to govern now?
Explore further
AI identity inventory is now a governance prerequisite, not a discovery exercise. Organisations already know they need to find AI tools, but the real security question is whether they can map those tools to identity, ownership, and data exposure. Discovery without context produces a catalogue, not a control surface. The implication is that AI inventory must be treated as an IAM and IGA foundation, not a side project.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, which shows how uneven governance maturity remains.
A question worth separating out:
Q: How should organisations govern agentic AI and NHI access in the same programme?
A: Treat both as non-human identities that need ownership, scope, lifecycle, and usage controls. Agentic AI adds runtime decision-making, so you also need to evaluate whether access is still appropriate during execution, not only at provisioning. One programme should cover both, but the controls must reflect the actor’s behaviour.
👉 Read our full editorial: AI identity inventory is becoming the baseline for governance