TL;DR: Machine identities now outnumber humans by more than 80 to 1 and 68% of organisations still lack proper identity security controls for AI, according to Oasis Security, as agentic AI multiplies service accounts, tokens, API keys, and certificates faster than teams can govern them. ISPM is becoming the control plane for discovery, rotation, least privilege, and monitoring across machine identity sprawl.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Taming the Machine Mayhem: 5 Steps to Kickstart Your ISPM Program”.
By the numbers:
- Machine identities now outnumber humans by more than 80 to 1 in enterprise environments.
- 68% of organisations lack proper identity security controls for AI.
Key questions
Q: What breaks when machine identity inventory is incomplete?
A: Rotation, revocation, and decommissioning all break down when you cannot see the full population of credentials.
Q: Why do long-lived secrets create more risk for workloads and agentic AI systems?
A: Long-lived secrets increase blast radius because any exposed key can be reused until it is rotated or revoked.
Q: How should teams reduce standing privilege for service accounts?
A: Teams should bind each service account to one workload, one purpose, and one minimal entitlement set.
Practitioner guidance
- Map every machine identity to an owner and purpose Create a single inventory for service accounts, API keys, tokens, and certificates across cloud, on-prem, and hybrid estates.
- Enforce rotation and expiry on high-risk secrets Prioritise unrotated secrets, dormant credentials, and shared keys first, then set hard rotation rules for the credentials that support production workloads or agentic AI systems.
- Remove standing privilege from machine identities Strip excessive permissions from service accounts and replace broad, persistent access with task-scoped rights that match the exact workload or workflow.
Bottom line: Machine identity sprawl is now a governance problem because service accounts, API keys, tokens, and certificates multiply faster than manual inventory and review processes can track.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Machine identity sprawl is now a lifecycle governance problem, not a secrets-management side issue. The estate now includes service accounts, API keys, tokens, and certificates that are created faster than teams can inventory them. Once ownership, purpose, and expiry are unclear, the control model has already failed. Practitioners should treat ISPM as the operating model for non-human identity governance, not as an add-on to vaulting.
A few things that frame the scale:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Why do machine identities and agentic AI complicate traditional identity security programmes?
A: They complicate programmes because the number of non-human actors grows faster than manual governance processes can track. Access may be ephemeral, delegated, or embedded in workflows, which weakens assumptions built around human users. Security teams need policies for lifecycle control, privilege boundaries, and continuous verification across both human and machine identities.
👉 Read our full editorial: ISPM for machine identity sprawl in the age of agentic AI