TL;DR: AI agents, service accounts, APIs, tokens, and workloads now move through enterprise systems continuously, expanding the identity attack surface far beyond human users, according to BigID. The core issue is that identity governance, access visibility, and data context were built for human-paced control loops, and that model no longer matches AI-driven operations.
NHIMG editorial — based on content published by BigID: non-human identity security and AI governance
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do non-human identities create more risk than many human accounts?
A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.
Q: What breaks when service accounts are not centrally governed?
A: When service accounts are created and maintained outside a central identity process, ownership, purpose, and retirement become unclear.
Practitioner guidance
- Map every AI agent to a named identity owner Assign accountable ownership for each agent, service account, token, and API integration, and require a business purpose plus a revocation condition before production use.
- Correlate identity access with sensitive data exposure Connect access logs, activity telemetry, and data discovery so reviews can answer which identities reached sensitive data, when they did it, and whether that access matched the intended scope.
- Remove standing privilege from machine identities Replace broad persistent access with task-scoped permissions, and retire credentials that remain valid after the associated workflow, project, or integration no longer needs them.
What's in the full article
BigID's full article covers the operational detail this post intentionally leaves for the source:
- Specific examples of how AI agents, service accounts, and tokens expand the attack surface across cloud, SaaS, and AI workflows
- A practical breakdown of the visibility questions teams should be able to answer about access, authentication, and sensitive-data reach
- Examples of the identity and data controls BigID says organisations need to move from static governance to continuous monitoring
- The article's own framing of why AI-driven identity intelligence matters for reducing overexposure and policy drift
👉 Read BigID's analysis of non-human identity security for AI systems →
Non-human identity security and AI agents: are your controls keeping up?
Explore further
AI agents are turning non-human identity governance from a back-office control into a primary security boundary. Once agents can retrieve data, call APIs, and trigger workflows independently, the identity layer becomes the main enforcement point between safe automation and uncontrolled access. That is why NHI governance now sits at the centre of AI security, not alongside it. Practitioners should treat every new agent as an access programme issue, not just an automation project.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
A question worth separating out:
Q: How do organisations know if NHI governance is actually working?
A: They can answer three questions consistently: what each identity is for, who owns it, and when it should be removed or re-authorised. If any NHI cannot be inventoried, classified, and tied to a current purpose, the governance programme is only partially effective. Auditability should be visible in the evidence, not assumed from policy language.
👉 Read our full editorial: Non-human identity security is now central to AI governance