TL;DR: Non-human identities now outnumber human identities by 20 to 40 times, and Oasis Security says AI adoption is widening machine-identity risk through LLMjacking and regulated-industry scrutiny under PCI DSS 4.0. The governing assumption is breaking: access models built for slower human review cycles cannot keep pace with high-volume NHI estates.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Reflecting on our journey at Oasis and looking ahead”.
By the numbers:
- Non-human identities now outnumber human identities by 20 to 40 times.
Key questions
Q: How should security teams govern non-human identities alongside human accounts?
A: Security teams should govern non-human identities as a separate lifecycle category with their own inventory, ownership, rotation, and offboarding controls.
Q: Why do machine identities create more risk than human identities in some environments?
A: Machine identities are often numerous, long-lived, and embedded in code or infrastructure.
Q: What breaks when NHI ownership is missing?
A: When NHI ownership is missing, access reviews lose context, incident response slows, and stale identities persist longer than they should.
Practitioner guidance
- Build a complete NHI inventory Catalogue service accounts, tokens, API keys, and other machine identities with explicit owners, system context, and business purpose.
- Constrain LLM-connected access paths Restrict machine identities that can reach LLM services to narrowly defined workloads, with monitored scope and rapid revocation.
- Map privileged NHIs to audit evidence Document least-privilege intent, approval history, and account usage for system and application accounts that carry elevated rights.
Bottom line: NHI proliferation is changing identity governance from a review problem into a lifecycle-scale control problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Machine identity scale is now a governance problem, not an inventory nicety. When NHIs outnumber human identities by 20 to 40 times, the control question changes from who approved access to whether the organisation can still see and govern it at all. Discovery, ownership, and policy enforcement have to operate as a single lifecycle, otherwise the estate grows faster than certification and review can absorb. The practitioner conclusion is that NHI governance must be designed for volume first, not manually curated exceptions.
A question worth separating out:
Q: How does PCI DSS 4.0 change the way teams think about privileged machine accounts?
A: It pushes privileged system and application accounts into the same governance conversation as other high-risk access. Teams need evidence that these accounts are limited to business need, mapped to explicit ownership, and monitored for misuse. The practical shift is from treating machine accounts as infrastructure detail to treating them as auditable access paths.
👉 Read our full editorial: NHI proliferation and LLMjacking are reshaping identity governance