TL;DR: RSA 2025 made one pattern clear: AI is moving into security workflows while third-party risk and non-human identity sprawl are moving to the centre of identity governance, according to Oasis Security’s conference takeaways. The practical shift is that IAM, NHI, and AI security controls now have to be designed together, not as separate programmes.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “RSA 2025: 5 Takeaways on AI, Third‑Party Risk & the Future of Identity”.
Key questions
Q: What breaks when AI-assisted security workflows rely on unmanaged machine identities?
A: The control plane becomes opaque.
Q: Why do third-party integrations increase identity risk so quickly?
A: Third-party integrations increase identity risk because they extend trust through credentials, tokens, and delegated access rather than through direct human oversight.
Q: How should security teams govern AI-assisted actions in the SOC?
A: Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.
Practitioner guidance
- Map AI-adjacent access paths Inventory the service accounts, API keys, tokens, and delegated permissions used by AI-assisted security workflows, then assign clear ownership and expiration rules.
- Reclassify third-party trust relationships Treat vendor integrations as governed identity relationships, not just contractual dependencies, and subject them to the same review and revocation discipline as internal access.
- Set approval boundaries for security copilots Define which investigations, summaries, or response steps AI can perform independently and which must remain human-approved before execution.
Bottom line: RSA 2025 reinforced that identity, not tooling, is the control layer that now connects AI-assisted security, third-party risk, and NHI governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity governance is becoming the operating layer for AI-enabled security. RSA 2025’s signal is not that AI is replacing security operations, but that identity is now the mechanism that decides what AI can see, touch, and trigger. When copilots move into production, entitlement scope and ownership become more important than model novelty. Practitioners should treat security AI as an access problem first and an automation problem second.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How can organisations tell whether their NHI controls are keeping up with AI agents?
A: Look for controls that can prove who requested access, which tool was used, what scope was granted, and whether the identity could be revoked cleanly. If those answers require manual reconstruction across logs, the programme is behind the behaviour it is trying to govern.
👉 Read our full editorial: RSA 2025 showed identity becoming the control plane for AI and NHIs