TL;DR: 61% of organisations lack a complete, central inventory of privileged entitlements, 55% struggle to govern non-human accounts, and 82% do not feel fully prepared to govern new AI agent identities, according to SailPoint’s survey. The governance gap is no longer about access volume alone, but about whether privilege can still be discovered, classified, and contained.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “New research report: The state of privileged access in the AI era”.
By the numbers:
- 61% of organizations lack a complete, centralized inventory of their privileged entitlements.
- 55% report non-human accounts are among their most difficult to govern.
- 62% already see new AI agent identities in their environments.
Key questions
Q: What breaks when privileged access is not continuously governed?
A: When privileged access is not continuously governed, standing privilege persists, dormant accounts remain usable, and the attack surface expands across human and machine identities.
Q: Why do service accounts and bots create more governance risk than many human accounts?
A: Service accounts and bots create more governance risk because they are often granted privileges for speed and left in place after the original use case changes.
Q: How should IAM teams govern AI agent identities differently from static service accounts?
A: IAM teams should treat AI agent identities as a separate privileged class because access can be exercised through changing tasks, tools, and contexts.
Practitioner guidance
- Implement continuous privileged entitlement discovery Use automated inventory collection across directories, cloud platforms, SaaS applications, and orchestration layers so privileged accounts and entitlements are visible as they are created or changed.
- Establish named ownership for non-human privilege Assign accountable owners to every service account, cloud entitlement, token, and automation identity, and block persistence when ownership or purpose cannot be demonstrated.
- Classify AI agent identities as a separate privileged population Define AI agents as their own identity class in governance models so tool access, scope, and recertification rules are not copied from human user patterns.
Bottom line: The article shows that privileged access risk is increasingly a visibility problem, not only a volume problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privilege visibility is now the controlling variable in identity security. The article shows that the problem is not simply too much access, but too much access that cannot be fully discovered and classified. Once inventory fragments across humans, service accounts, cloud entitlements, and AI agents, least privilege becomes an aspiration rather than an enforceable state. Practitioners should treat visibility as the precondition for every downstream privilege control.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should organisations prioritise first: access reviews or privilege reduction?
A: Prioritise privilege reduction first when you already know there is excess access, then use reviews to keep it from coming back. Reviews verify the current state, but they do not eliminate broad entitlements on their own. If the environment is heavily over-permissioned, reducing standing access creates the biggest immediate risk drop.
👉 Read our full editorial: Privileged access in the AI era exposes a visibility gap