TL;DR: C1 says its new agentic security and intelligence layer inventories humans, non-human identities, and AI agents, creates findings for ownership and access issues, and routes remediation through approval workflows with audit trails, while Palo Alto Networks’ 2026 Identity Security Landscape says organisations now manage 109 machine identities for every human identity. The governance problem is not discovery alone; it is proving resolution across identity types.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- Palo Alto Networks' 2026 Identity Security Landscape found organizations now manage 109 machine identities, including AI agents, for every human identity, up from 82:1 the year before.
Questions worth separating out
Q: What do IAM teams get wrong about service accounts and AI agent permissions?
A: They often assume the user token or service account scope fully describes the agent’s risk.
Q: Why do AI agents make non-human identity governance harder?
A: AI agents make governance harder because they can request tools, act autonomously, and change behaviour across sessions while still relying on machine credentials.
Q: What breaks when identity findings are tracked in one tool and remediated in another?
A: You lose the evidence chain.
Practitioner guidance
- Define one identity ownership record per subject Tie every human, service account, and AI agent to a named owner, business purpose, and escalation path before allowing access to be operationalised.
- Route identity findings through a closed-loop workflow Make every finding resolve through the same approval, exception, or automation path, with an audit trail attached at closure.
- Classify agent accounts separately from human users Do not let AI agents inherit user-style governance assumptions by default.
What's in the full announcement
ConductorOne's full post covers the operational detail this post intentionally leaves for the source:
- How the identity intelligence graph maps humans, NHIs, and AI agents to connected systems and access paths
- The remediation workflow options for owner reassignment, access right-sizing, certification, and exception handling
- How findings can be routed into ServiceNow, Jira, PagerDuty, webhooks, and automations with audit evidence attached
- Examples of the signal types that trigger a finding, including decoy credential use and misclassified accounts
👉 Read ConductorOne’s analysis of agentic security and intelligence for identity risk →
AI agents, humans, and NHIs: what does governed remediation change?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity governance is shifting from entitlement management to accountability management. The launch reflects a broader market truth: finding an identity risk is no longer the hard part, but proving that the risk was resolved is still where most programmes break down. When humans, service accounts, and AI agents are all in the same estate, the control problem is whether ownership, approval, and evidence can survive across systems. Practitioners should treat accountability as the primary design goal, not a reporting afterthought.
A few things that frame the scale:
- 73% of vaults are misconfigured, leading to unauthorised access and exposure of sensitive data, according to the Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?
A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.
👉 Read our full editorial: Agentic security and intelligence reframes identity risk governance