Join our Newsletter — 33% off our NHI Course

Zero trust for workloads and AI agents: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Workloads, service accounts and AI agents still rely on static secrets even as machine identities outnumber humans by 82 to 1 in the average enterprise, according to CyberArk and Aembit’s analysis, leaving traditional zero trust controls unable to govern runtime access. Static credential assumptions break once agents choose resources and timing autonomously, so identity-first, ephemeral and continuous controls become the baseline.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Zero Trust for Nonhuman Workload Access: A Primer”.

By the numbers:

  • Machine identities outnumber human identities by 82 to 1 in the average enterprise, according to Aembit’s cited CyberArk research.

Key questions

Q: How should security teams govern workload access when static secrets are still in use?

A: Start by treating static secrets as transitional, not acceptable end-state controls.

Q: Why do static NHI credentials increase third-party breach impact?

A: Static NHI credentials increase third-party breach impact because they persist beyond the moment of use.

Q: How should security teams implement zero trust for workloads and AI agents?

A: Start by giving each workload or agent a verifiable runtime identity, then enforce request-level policy and issue short-lived credentials only after the identity and context checks pass.

Practitioner guidance

  • Verify workload identity at runtime Use attestation, signed tokens or platform-issued identity so the workload proves who it is on each request instead of relying on a stored bootstrap secret.
  • Replace static credentials with ephemeral issuance Scope access to a single task or session and expire the credential immediately after use so intercepted secrets cannot be reused.
  • Enforce policy at the resource boundary Evaluate identity, posture and context before every access grant across cloud, SaaS and on-premises targets instead of trusting network location.

Bottom line: Workload and agent access still leans on static secrets, which means the security model often trusts stored credentials more than runtime identity.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 20 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20760
 

Zero trust for workloads fails when identity is reduced to secret possession. The article shows that workloads and agents are still authenticated with API keys, service account passwords and certificates that only prove someone stored a credential. That assumption was designed for static machine access, not for runtime-executing identities that can be copied, reused or intercepted. The implication is that workload identity has to be governed as a live proof problem, not a storage problem.

A few things that frame the scale:

A question worth separating out:

Q: What should teams do when an AI agent can choose resources and timing on its own?

A: Move governance from pre-approved access bundles to request-by-request evaluation. Autonomous behaviour means least privilege cannot be assumed safe at deployment time because the agent may discover new paths during execution. Teams should constrain runtime access, re-evaluate context continuously and avoid granting broad standing permissions.

👉 Read our full editorial: Zero trust for workloads and AI agents needs new controls


This post was modified 20 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.