Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Zero trust for AI systems and NHIs: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20377
Topic starter  

TL;DR: Zero Trust data security now has to evaluate access for users, service accounts, workloads, and AI systems across cloud, SaaS, and on-premises environments, according to BigID. The model only works when identity, context, data sensitivity, and continuous monitoring replace perimeter trust assumptions, and that means NHI governance can no longer sit outside IAM design.

NHIMG editorial — based on content published by BigID: Zero Trust Data Security: Protect Sensitive Data in a Connected World

By the numbers:

Questions worth separating out

Q: How should security teams implement Zero Trust for NHIs and AI systems?

A: Start by mapping effective access to sensitive data, not just configured permissions.

Q: Why do NHIs complicate zero trust and least privilege efforts?

A: NHIs complicate zero trust because they are numerous, persistent, and often tightly integrated into applications and pipelines.

Q: What breaks when data classification is missing from access governance?

A: Least privilege becomes too coarse to be useful.

Practitioner guidance

What's in the full article

BigID's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step breakdown of how BigID connects sensitive data to identities, permissions, and activity.
  • Practical implementation examples for classifying data and mapping effective access across cloud, SaaS, and on-premises systems.
  • Operational workflow detail for prioritising excessive access and triggering remediation actions.
  • Use-case guidance for applying data-aware controls to AI systems and non-human identities.

👉 Read BigID's analysis of zero trust data security for identities and sensitive data →

Zero trust for AI systems and NHIs: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19968
 

Zero Trust data security is now an identity governance problem, not only a network design problem. The article is right to move the discussion from perimeter trust to resource-level decisions, but the deeper point is that identity teams now own the data exposure boundary. If users, service accounts, workloads, and AI systems are all reaching the same data stores, then access governance has to treat them as one control plane. Practitioners should stop separating network trust from identity trust when sensitive data is the asset being protected.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when a third-party identity causes data exposure?

A: Accountability sits with the organisation that trusted the identity without sufficient boundaries, not just with the vendor that used it. If a third-party account was over-scoped, persistently trusted, or insufficiently monitored, the governance failure is internal. Frameworks such as NIST CSF and zero trust both expect explicit control over external access.

👉 Read our full editorial: Zero trust data security now has to govern AI systems and NHIs



   
ReplyQuote
Share: