TL;DR: Identity security now sits at the centre of strategy for more than 95 percent of leaders, while non-human identities and AI agents can outnumber human accounts by more than 100 to 1, according to Omada Identity's State of Identity Governance 2026 discussion. The governance gap is no longer about awareness; it is about risk-based control, continuous evaluation, and ownership.
Editorial analysis by NHI Mgmt Group, based on content published by Omada Identity: “Non-Human Identities and Agentic AI: The New Frontier in Identity Security”.
By the numbers:
- More than 95 percent of leaders now treat identity security as core to their strategy.
- Non-human identities and AI agents can outnumber human accounts by more than 100 to 1.
Key questions
Q: What breaks when organisations govern non-human identities with human-centric review models?
A: Human-centric review models assume identities move through predictable joiner-mover-leaver stages and remain stable long enough to be certified.
Q: Why do non-human identities change the way IAM teams should think about risk?
A: NHIs multiply faster than human accounts and often have broader or less visible access paths.
Practitioner guidance
- Define risk-based identity metrics Replace activity counts on executive dashboards with metrics that show entitlement risk, ownership completeness, and stale access across non-human identities.
- Inventory and assign owners to every non-human identity Create a complete register of service accounts, tokens, certificates, and AI agent identities, then assign a named business and technical owner to each one.
- Apply continuous access evaluation Use Zero Trust policy checks to reassess machine and agent access as context changes, instead of relying only on periodic recertification.
Bottom line: Identity governance is shifting because non-human identities and AI agents are now large enough in number to change how access must be controlled.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Activity-based governance is no longer enough once non-human identities become the dominant identity class. The article points to a structural mismatch: teams still report on actions completed, while the real risk sits in who or what retains access, for how long, and to which systems. That is a governance problem, not a visibility problem. The implication is that identity programmes must treat entitlement risk as the primary metric, not administrative throughput.
A few things that frame the scale:
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should teams do first when machine identities outnumber human accounts?
A: Start with an inventory of all machine identities, then rank them by business criticality and credential lifetime. That gives you a practical way to target the highest-risk secrets and certificates first, instead of trying to remediate the entire estate at once.
👉 Read our full editorial: Identity governance is shifting as non-human identities outnumber humans