Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI era identity security: what is the governance gap now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20374
Topic starter  

TL;DR: As AI adoption reshapes access, resilience, and governance priorities, a survey of 1,100 IT and security professionals across eight countries examines how organizations are managing identity security, according to Semperis. The central issue is not AI novelty but whether identity controls can still govern systems, accounts, and lifecycle processes at the speed modern operations require.

NHIMG editorial — based on content published by Semperis: The State of Identity Security in the AI Era

By the numbers:

Questions worth separating out

Q: How should security teams govern access across human, NHI, and AI identities?

A: Security teams should govern all three through a shared lifecycle and policy layer, but with different operating rules for each actor type.

Q: Why do AI-accelerated platforms increase identity and access risk?

A: They increase risk because the platform concentrates sensitive data, compute, and decision-making in one place.

Q: What are the signs that AI governance controls are not keeping pace with adoption?

A: Common warning signs include unclear ownership for AI use cases, inconsistent approval processes, limited visibility into where sensitive data enters models, and weak evidence for audits or assessments.

Practitioner guidance

  • Map AI-adjacent identity paths Identify every service account, token, API key, and delegated workflow that AI features can touch, then record the owner, purpose, and revocation path for each.
  • Unify lifecycle ownership Define one cross-functional owner for joiner-mover-leaver, recertification, and offboarding decisions that affect human and non-human identities.
  • Measure revocation latency Track the time between access no longer being needed and access actually being removed, then escalate identities that remain active outside policy windows.

What's in the full report

Semperis' full report covers the survey detail this post intentionally leaves for the source:

  • Breakdowns of how 1,100 IT and security professionals answered across eight countries
  • The study's AI and identity resilience findings by respondent group and geography
  • The underlying survey framing that connects identity security to cyber resilience
  • The report context behind the statistics and conclusions summarized here

👉 Read Semperis’ report on identity security in the AI era →

AI era identity security: what is the governance gap now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19965
 

AI-era identity security is really a governance stress test, not a technology category shift. Once AI touches access, the problem stops being confined to authentication and becomes a question of identity lifecycle, delegation, and revocation across systems. Organizations that keep treating AI as a separate security silo will miss the fact that the same access model now has to govern humans, NHIs, and AI-enabled workflows together.

A few things that frame the scale:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the same report.

A question worth separating out:

Q: Should organisations treat AI coding agents as part of IAM and PAM governance?

A: Yes, when those agents can act on code, data, or tools in ways that affect production risk. Their permissions should be scoped, reviewed, and audited like other privileged systems, especially when they interact with sensitive routes, secrets, or regulated data. The governance question is who can let the agent act, and under what policy.

👉 Read our full editorial: Identity security in the AI era needs stronger governance



   
ReplyQuote
Share: