TL;DR: Most organisations still cannot tell how many service accounts they have, what those accounts do, or when one has been compromised, and the article argues that AI agents are now entering the environment as non-human identities with privileges and autonomous action, according to Netwrix. The security problem is no longer just hidden machine accounts, but a broader identity blind spot that spans legacy service accounts and agentic identities.
Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “Service Account Security in the Age of AI: From Legacy Accounts to Agentic Identities”.
Key questions
Q: What breaks when organisations cannot inventory tokens and service accounts in SaaS apps?
A: Containment breaks first, because responders cannot tell which identities are still valid, where they are used, or which integrations inherit their access.
Q: How should teams govern non-human identities in AI-heavy environments?
A: Teams should govern non-human identities the same way they govern other privileged assets: assign ownership, minimise scope, rotate credentials regularly, and monitor for abnormal use.
Practitioner guidance
- Establish a full service account inventory Map every service account to an owner, purpose, dependency, and last-known use so hidden identities can be reviewed and retired safely.
- Classify AI agents as governed identities Create a distinct process for agent IDs that records purpose, authority, and operational owner instead of treating them as generic application accounts.
- Apply lifecycle expiry to non-human identities Set review and expiry rules for service accounts, tokens, and agent identities so unused access does not persist indefinitely.
Bottom line: The central problem is a non-human identity blind spot that combines legacy service account opacity with the rise of agentic identities.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Service account invisibility is now a governance failure, not just an inventory problem: If an organisation cannot say how many service accounts it has or what they do, it cannot govern privilege, ownership, or offboarding with confidence. That blind spot has always weakened NHI control, but it becomes more dangerous as more business processes depend on machine identities. The practitioner conclusion is simple: identity governance for NHIs begins with knowing what exists.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 59% of organisations say they lack viable alternatives to standing privileged access for NHIs and AI agents, according to Delinea research.
A question worth separating out:
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
👉 Read our full editorial: Service account security and agentic identities are redefining NHI risk