TL;DR: AI agents, service accounts, API keys, OAuth grants, and other NHIs create security risk when they are not tied to a responsible human owner, according to Fischer Identity. The identity model now depends on lifecycle, ownership, and review discipline, not just provisioning and deprovisioning.
NHIMG editorial — based on content published by Fischer Identity: Managing AI Agents and Non-Human Identities, Why Ownership Matters in Modern IAM
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should security teams govern AI agents that outlive their original purpose?
A: Security teams should treat AI agents like time-bound identities.
Q: Why do non-human identities create a larger governance problem than human accounts?
A: Non-human identities scale faster, are used by systems rather than people, and often carry broad or persistent access.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
Practitioner guidance
- Define a named owner for every NHI Require a responsible employee, sponsor, or manager for each AI agent, service account, API key, and OAuth grant before production use.
- Attach lifecycle conditions to business purpose Set expiry, review, transfer, and deprovisioning rules based on the NHI's purpose and dependency, not on the creator's employment status alone.
- Rework access reviews for machine identities Treat recertification as a check on current sponsorship and current system need, especially for AI agents that can keep operating after role changes.
What's in the full article
Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:
- Policy-driven ownership escalation paths for AI agents and service accounts
- Lifecycle workflows for recertification, deprovisioning, and sponsor reassignment
- Examples of how the platform links non-human accounts to responsible human owners
- Implementation detail on how access reviews and offboarding are handled in complex identity environments
👉 Read Fischer Identity's blog on governing AI agents and non-human identities →
AI agent ownership and NHI governance: are your controls ready?
Explore further
Ownership failure is the central NHI governance gap in modern IAM. When an AI agent or service account is not tied to a responsible human, the organisation loses the only durable control relationship that can drive review, escalation, and removal. That is not a tooling issue, it is a governance design flaw. IAM teams should treat ownership as a mandatory identity attribute, not an optional administrative field.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own orphaned service accounts and AI agent identities?
A: Ownership should sit with a named business or technical custodian who can approve use, monitor activity, and trigger offboarding when the identity is no longer needed. Without accountable ownership, the identity remains live by default and becomes a governance gap rather than an operational asset.
👉 Read our full editorial: AI agent ownership is now a core IAM governance problem