Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Non-human identities and AI agents: are your PAM controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Machine identities now outnumber human identities by as much as 144 to 1, and AI service credential leaks rose 81% in a year, according to SSH Communications Security and cited industry research. Standing privileges and long-lived secrets are no longer adequate when workloads and AI agents authenticate continuously.

NHIMG editorial — based on content published by SSH Communications Security: What AI Agents and Non-Human Identities Mean for PAM

By the numbers:

Questions worth separating out

Q: How should security teams govern non-human identities that have persistent access?

A: Security teams should treat every non-human identity as a managed asset with an owner, an explicit purpose, a scoped privilege set, and a defined offboarding path.

Q: Why do non-human identities create more risk than many human accounts?

A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.

Q: What breaks when organisations keep using standing privileges for machine identities?

A: Standing privilege turns NHIs into persistent trust anchors.

Practitioner guidance

  • Inventory every non-human identity class Build a current register of service accounts, API keys, certificates, workload identities, automation platforms, and AI agents, then map each one to an owner, purpose, and expiry or review rule.
  • Replace standing privilege with short-lived access Move privileged machine access toward just-in-time or identity-bound sessions so credentials are valid only for the task window.
  • Re-certify effective machine permissions Review what each NHI can actually reach across cloud, Kubernetes, and SaaS systems, not just what was originally assigned.

What's in the full article

SSH Communications Security's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Practical discussion of runtime identity control and how it differs from traditional PAM
  • Detailed examples of how AI agents change authorisation decisions during active execution
  • Operational framing for short-lived identities, policy-based access, and continuous monitoring
  • The source article's broader whitepaper context for teams moving from concept to implementation

👉 Read SSH Communications Security's whitepaper on what AI agents and non-human identities mean for PAM →

Non-human identities and AI agents: are your PAM controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Runtime identity control is now the right frame for PAM because static privilege assumptions no longer match machine behaviour. The article shows that workloads, APIs, automation systems, and AI agents authenticate continuously rather than episodically. That means PAM is no longer just about preventing misuse by people. It is about governing identities that operate constantly, often without a human operator in the loop. Security teams should treat runtime evaluation as the governing model for privileged machine access.

A few things that frame the scale:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
  • 59.8% of organisations see value in a solution that simplifies non-human access management and introduces dynamic ephemeral credentials.

A question worth separating out:

Q: Who is accountable when an AI agent or workflow executes privileged actions under a forged identity?

A: Accountability sits with the organisation that allowed authority to flow without revalidation. If the identity proof is stale, delegated, or implicit, then the governance failure is architectural, not operational. Frameworks such as Zero Trust and NHI governance both point to the same issue: trust must be continuously asserted, not assumed.

👉 Read our full editorial: Runtime identity control for non-human identities in the machine-driven enterprise



   
ReplyQuote
Share: