TL;DR: Clarity Security says non-human identities now outnumber human identities by more than 100 to 1 in many enterprise environments, while most organisations still lack systematic governance for service accounts, API keys, OAuth tokens, and AI agents. Access that compounds over time is turning NHI oversight into a structural identity problem, not a niche operations issue.
Editorial analysis by NHI Mgmt Group, based on content published by Clarity Security: “Beyond Human: NHI and AI Identity Governance with Lalit Choda”.
By the numbers:
- Non-human identities now outnumber human ones by more than 100 to one in many enterprise environments.
Key questions
Q: Why do IAM controls fail when non-human identities outnumber human users?
A: IAM controls fail when NHIs dominate because the governance model was built around stable human accounts with predictable owners, review cycles, and sign-in behaviour.
Q: When does AI agent access become harder to govern than service account access?
A: AI agent access becomes harder to govern when the agent can decide which tools to call during runtime, rather than following a fixed automation script.
Practitioner guidance
- Inventory every non-human identity Create a complete register for service accounts, API keys, OAuth tokens, certificates, and agent identities with ownership, purpose, and system dependency recorded for each entry.
- Tie issuance to expiry by default Set explicit expiration and renewal rules for machine credentials so access cannot persist indefinitely when teams lose track of the original business need.
- Separate human and NHI review workflows Use distinct governance paths for human users and machine identities so access reviews do not blur lifecycle, ownership, and offboarding requirements.
Bottom line: NHI sprawl is no longer a niche hygiene issue. It is a governance problem that overwhelms human-centric IAM assumptions once machine identities dominate the access landscape.
What to expect at the briefing
Clarity Security's full webinar covers the operational detail this post intentionally leaves for the source:
- Direct guidance from Lalit Choda on where NHI governance breaks down in real enterprise environments
- Discussion of the biggest misconceptions security teams still hold about non-human identities
- A closer look at how AI agents change identity governance and regulatory scrutiny
- Two-to-three year outlook on where NHI and AI identity governance are headed
👉 Read Clarity Security's webinar preview on AI agent and NHI governance →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Non-human identity governance has become a core IAM discipline, not an edge case. Service accounts, API keys, and OAuth tokens now represent a large share of enterprise access, and the article’s more than 100 to 1 ratio shows why human-centric IAM models are insufficient. Governance that treats these identities as exceptions will continue to miss ownership, lifecycle, and revocation gaps. The practitioner conclusion is simple: NHI must be governed as a primary identity class, not a side channel.
A few things that frame the scale:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should security teams implement NHI governance before AI agents scale further?
A: Start with continuous discovery, then add ownership, lifecycle triggers, certification, and escalation. Security teams should not treat those as separate projects. They form one control loop that tells you what exists, who is responsible, when access should change, and when the identity should be removed.
👉 Read our full editorial: AI agent and NHI governance is outpacing IAM controls