Join our Newsletter — 33% off our NHI Course

Hybrid identities: what IAM teams are missing between AI and users

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents now hold credentials and act with delegated human authority, so a phished employee and a hijacked agent can produce the same attack shape inside the enterprise, according to Abnormal AI. The governance assumption that human identity and machine identity can be managed in separate lanes is collapsing, because the real exposure sits in the hybrid identity gap.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Identity Security and AI Security Are Two Names for One Problem”.

Key questions

Q: What breaks when AI agents hold delegated human authority but sit outside IAM ownership?

A: The break is accountability and lifecycle control.

Q: Why do non-human identities increase identity security risk in hybrid environments?

A: Non-human identities often persist longer than the workflows that created them, and their access is frequently less visible than human access.

Q: How do security teams detect misuse of non-human identities in aviation?

A: They need ownership, purpose, and historical baselines for each service account, API key, workload identity, and certificate.

Practitioner guidance

  • Define hybrid identities explicitly Create an inventory of AI applications and agents that hold credentials or act on behalf of people, then assign each one a lifecycle owner and a revocation path.
  • Baseline identities individually Use per-identity behavioral baselines for both human and non-human accounts so alerts reflect deviation from normal access patterns rather than generic rule violations.
  • Review delegated authority chains Trace where human approval turns into machine execution, and document which access rights persist after the original request is complete.

Bottom line: Hybrid identities blur the line between human IAM and AI security because delegated authority can outlive the original actor model.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21487
 

Hybrid identity is now its own governance category, not a side effect of AI adoption. Once AI agents hold credentials and act with delegated authority, the old boundary between user identity and machine identity stops being useful as an operating model. The central control problem becomes who owns the privilege lifecycle when the actor is partly human-origin and partly machine-executed. Practitioners should treat hybrid identity as a first-class governance object, not a workflow exception.

A few things that frame the scale:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: How should organisations govern AI systems that need credentials?

A: Organisations should place AI systems inside the non-human identity inventory and assign each one a clear owner, scope, and offboarding path. If an AI feature can authenticate, call tools, or hold tokens, it needs lifecycle governance. Without that, hidden access paths can outlive visibility and accountability.

👉 Read our full editorial: Hybrid identities expose the seam between AI and IAM controls


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.