TL;DR: IAM maturity models still assume identities are comparatively stable, reviewable, and lifecycle-managed, but AI agents and other non-human identities expose gaps in provisioning, access review, and governance that human-centric programmes often leave uneven, according to Zluri research. Maturity now depends on governing identities that act at runtime, not just ones that can be reviewed later.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Identity & Access Management Maturity Model - A Guide For 2026”.
Key questions
Q: What breaks when identity maturity models exclude NHIs and AI agents?
A: They misstate the real control boundary.
Q: Why do AI agents change existing IAM assumptions?
A: AI agents change IAM assumptions because access is no longer a stable state that can be granted, reviewed, and trusted over a session.
Q: How can security teams tell whether IAM maturity is real for machine identities?
A: Look for evidence that the programme can trace ownership, purpose, scope, and retirement for every non-human identity.
Practitioner guidance
- Rework maturity scoring for non-human access Assess whether your IAM maturity model measures runtime control, entitlement scope, and revocation speed for NHIs and AI agents, not just policy presence and review completion.
- Inventory machine identities as governed assets Create an ownership, purpose, and retirement record for each service account, API key, token, certificate, or AI agent identity so lifecycle decisions are explicit.
- Separate human review cadence from machine control Do not rely on periodic access certification to govern identities that can act and disappear inside one workflow.
Bottom line: The article shows that IAM maturity models can overstate control strength when they are built around human review cycles rather than machine-paced identity behaviour.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Maturity models built for human access cannot measure machine-paced identity behaviour: The article shows that IAM maturity still tends to reward policy completeness, review cadence, and process consistency. Those are useful indicators for human users, but they understate the control gap when AI agents and NHIs can operate across systems faster than review cycles can react. The implication is that maturity has to include runtime governance, not just lifecycle formality.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: Should organisations use the same access model for humans and AI agents?
A: No. Human access models are built around stable roles and review cycles, while AI agents often need contextual, task-specific permissions that change quickly. Treating them the same usually leads to over-permissioning or constant exceptions. Organisations should separate identity proof from authorization design and apply resource-level controls for agents.
👉 Read our full editorial: IAM maturity models miss the identity shift AI agents create