Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity security maturity in the AI era: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20383
Topic starter  

TL;DR: Compromised credentials drive 80% of enterprise breaches and non-human identities now outnumber employees by 80 to 1, according to Oleria Security’s analysis of identity security maturity in the AI era. Static RBAC, quarterly reviews, and legacy IAM assumptions break down as AI agents inherit broad privileges and act with non-deterministic behaviour.

NHIMG editorial — based on content published by Oleria Security: Identity Security Maturity in the Era report

By the numbers:

Questions worth separating out

Q: What fails when AI agents inherit broad access through delegated identity paths?

A: The failure is the assumption that delegated access stays understandable and reviewable after assignment.

Q: Why do legacy access reviews create blind spots for AI agents and NHIs?

A: Because they assume access persists long enough to be observed at a review point.

Q: How should security teams prioritise identity work when NHIs outnumber humans at scale?

A: Start with identities that can reach sensitive systems, inherit privilege, or create lateral movement potential.

Practitioner guidance

  • Audit delegated access paths Inventory every workload, service account, API token, vendor identity, and AI integration that can inherit permissions across cloud and SaaS systems.
  • Replace standing privilege with JIT access Use ephemeral, task-scoped access for high-risk administrator and autonomous service account activity so excess privilege does not persist between tasks.
  • Build a human-on-the-loop escalation rule Require explicit human approval for privilege escalation and sensitive data actions even when routine agent tasks execute autonomously.

What's in the full report

Oleria Security's full report covers the operational detail this post intentionally leaves for the source:

  • The full 12-domain maturity model grid for benchmarking identity security maturity across teams and environments.
  • The BRiCE prioritisation methodology for comparing identity investments by business value, risk impact, cost, and effectiveness.
  • Stage-by-stage guidance for moving from fragmented identity stores to continuous discovery and autonomous guardrails.
  • The report's strategic roadmap for high-risk controls such as JIT access, ITDR, and AI guardrails.

👉 Read Oleria Security's identity security maturity analysis for the AI era →

Identity security maturity in the AI era: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19974
 

Identity governance assumptions built for human work patterns collapse when agents execute in machine time. Quarterly review cycles assume access remains stable long enough to be observed, certified, and removed. AI agents can inherit, chain, and discard authority within a single operational flow, so the governance model no longer matches the behaviour it is supposed to control. The implication is not simply more review, but a different premise for how access exists at runtime.

A few things that frame the scale:

  • AI agents have already performed actions beyond their intended scope in 80% of organisations, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a compliance and investigation blind spot.

A question worth separating out:

Q: What is the difference between JIT access and static RBAC for agentic systems?

A: Static RBAC assigns enduring permissions to a role, while JIT access grants time-bound authority for a specific task. For agentic systems, that difference matters because task scope can shift during execution, and long-lived role grants can outlast the work they were meant to support.

👉 Read our full editorial: Identity security maturity in the AI era demands new controls



   
ReplyQuote
Share: