TL;DR: C1.ai says 93% of respondents now view non-human identity risk as urgent, while 42% rank NHI security above human user security and 78% claim high or full visibility even as privilege and rotation problems persist. Visibility is no longer the core issue; scope, lifecycle, and oversight at machine scale are.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Managing Non-Human Identity Risk in 2025”.
By the numbers:
- 93% of respondents said the risks associated with NHIs are urgent, with 24% calling them extremely urgent.
- 42% of respondents say NHI security is now a higher priority than securing human users.
- 78% of respondents said they have high or full visibility into NHIs across their environment.
Key questions
Q: How should security teams reduce risk from overprivileged non-human identities?
A: Start by identifying every non-human identity and the exact permissions it uses in production.
Q: Why does high visibility not mean NHI governance is under control?
A: Because inventory and control are different outcomes.
Q: What breaks when AI agents are reviewed like human users?
A: Human review assumes access is stable long enough to be observed, approved, and recertified.
Practitioner guidance
- Map your NHI estate to actual business function Classify service accounts, tokens, certificates, APIs, and AI agents by owner, purpose, and system dependency before trying to rationalise access.
- Replace broad default grants with scoped entitlements Rework machine access so each identity has the minimum permissions required for its task, environment, and runtime boundary.
- Automate rotation and revocation for machine credentials Build lifecycle controls for secrets and tokens so access expires, rotates, or is revoked without waiting for a manual review cycle.
Bottom line: The article’s central warning is that NHI sprawl is now amplified by agentic AI, which increases the number and dynamism of non-human access paths.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- The survey framing behind the 93% urgency finding and how respondents split on NHI priority versus human identity security
- The specific governance challenges named in the report, including over-provisioning, credential rotation, third-party risk, and sheer volume
- The article’s discussion of how agentic AI changes the access model for tokens, service accounts, secrets, and APIs
- The full set of recommended controls for automated access reviews, scoped permissions, audit trails, and usage monitoring
👉 Read C1.ai's analysis of managing non-human identity risk as agentic AI expands →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
NHI governance has become a machine-scale access problem, not a visibility problem. The article shows that many organisations can see their NHIs but still cannot govern them effectively. That distinction matters because discovery does not reduce privilege, rotate secrets, or revoke stale access. The discipline now sits at the intersection of IGA, PAM, and cloud identity governance, where lifecycle control matters more than inventory counts.
A few things that frame the scale:
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between human identity controls and NHI controls?
A: Human identity controls rely on interactive authentication, user challenge, and behavioural oversight. NHI controls must manage secrets, certificates, tokens, service accounts, and workload permissions at machine speed. The difference is operational: machine identities need lifecycle governance and runtime visibility, not just login protection.
👉 Read our full editorial: Managing non-human identity risk as agentic AI expands