TL;DR: As machine identities now outnumber humans 109 to 1, ConductorOne says its new agentic security and intelligence layer detects ownership gaps, misclassifications, shadow accounts, and missing anomaly detection across service accounts, workloads, integrations, and AI agents. The deeper issue is that identity review cycles assume risk can be observed and remediated slowly, while these identities appear, act, and disappear at machine speed.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- organizations now manage 109 machine identities, including AI agents, for every human identity, up from 82:1 the year before.
- The 2026 Identity Security Landscape found organizations now manage 109 machine identities, including AI agents, for every human identity.
Questions worth separating out
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
Q: Why do machine identities create problems for traditional IAM reviews?
A: Machine identities often operate through credentials and delegated permissions that persist beyond a human session, so review cycles can miss active risk.
Q: What do teams get wrong about managing non-human identities?
A: They often treat NHIs as one-off credentials instead of governed identities with owners, lifecycles, and review requirements.
Practitioner guidance
- Create ownership rules for every non-human identity Require an accountable owner, service purpose, and retirement trigger for every service account, integration, workload, and AI agent before it can be treated as governed.
- Tie NHI findings to remediation workflows Route identity-risk findings into request, approval, and audit paths so revocation, right-sizing, or reassignment happens in the same system that raises the issue.
- Treat identity context as a control requirement Use access graphs, entitlement reach, and ownership state to decide whether a flagged identity is merely noisy or genuinely risky.
What's in the full announcement
ConductorOne's full post covers the operational detail this post intentionally leaves for the source:
- How the agentic security queue maps identity findings to owner assignment, right-sizing, and revocation
- How imported findings from external tools inherit the same tagging, routing, and audit trail
- How the access graph is used to assess impact before remediation
- How the platform verifies that an ownership gap has actually been cleared
👉 Read ConductorOne's post on agentic security and intelligence for identity risk →
AI agent identity risk is outpacing manual review controls?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Machine identity governance is now a detection-and-routing problem, not just an inventory problem. The article describes a control model that flags ownership gaps, misclassification, and shadow identities, then pushes remediation through governed workflows. That reflects the reality that NHIs fail in the gaps between systems, not only in the systems themselves. Practitioners should treat detection, classification, and routing as one governance loop, not three separate tools.
A few things that frame the scale:
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which explains why ownership and entitlement gaps persist.
A question worth separating out:
Q: Who should be accountable when an AI agent or service account causes access drift?
A: The accountable party should be the human or team that authorised the identity and owns the business process behind it. The agent cannot own its own lifecycle in a governance sense. Accountability must stay with a human owner who can approve, revoke, or re-scope access when usage changes.
👉 Read our full editorial: Agentic security for AI agents highlights the NHI risk gap