TL;DR: Workloads, service accounts and AI agents still rely on static secrets even as machine identities outnumber humans by 82 to 1 in the average enterprise, according to CyberArk and Aembit’s analysis, leaving traditional zero trust controls unable to govern runtime access. Static credential assumptions break once agents choose resources and timing autonomously, so identity-first, ephemeral and continuous controls become the baseline.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “Zero Trust for Nonhuman Workload Access: A Primer”.
By the numbers:
- Machine identities outnumber human identities by 82 to 1 in the average enterprise, according to Aembit’s cited CyberArk research.
Key questions
Q: How should security teams govern workload access when static secrets are still in use?
A: Start by treating static secrets as transitional, not acceptable end-state controls.
Q: Why do static NHI credentials increase third-party breach impact?
A: Static NHI credentials increase third-party breach impact because they persist beyond the moment of use.
Q: How should security teams implement zero trust for workloads and AI agents?
A: Start by giving each workload or agent a verifiable runtime identity, then enforce request-level policy and issue short-lived credentials only after the identity and context checks pass.
Practitioner guidance
- Verify workload identity at runtime Use attestation, signed tokens or platform-issued identity so the workload proves who it is on each request instead of relying on a stored bootstrap secret.
- Replace static credentials with ephemeral issuance Scope access to a single task or session and expire the credential immediately after use so intercepted secrets cannot be reused.
- Enforce policy at the resource boundary Evaluate identity, posture and context before every access grant across cloud, SaaS and on-premises targets instead of trusting network location.
Bottom line: Workload and agent access still leans on static secrets, which means the security model often trusts stored credentials more than runtime identity.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Zero trust for workloads fails when identity is reduced to secret possession. The article shows that workloads and agents are still authenticated with API keys, service account passwords and certificates that only prove someone stored a credential. That assumption was designed for static machine access, not for runtime-executing identities that can be copied, reused or intercepted. The implication is that workload identity has to be governed as a live proof problem, not a storage problem.
A few things that frame the scale:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
- 69% of organisations still authenticate machine identities with long-lived API keys, according to the 2026 State of AI Agent Identity Security Report.
A question worth separating out:
Q: What should teams do when an AI agent can choose resources and timing on its own?
A: Move governance from pre-approved access bundles to request-by-request evaluation. Autonomous behaviour means least privilege cannot be assumed safe at deployment time because the agent may discover new paths during execution. Teams should constrain runtime access, re-evaluate context continuously and avoid granting broad standing permissions.
👉 Read our full editorial: Zero trust for workloads and AI agents needs new controls