Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI and NHI sprawl: what identity teams should prepare for


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Among 494 security professionals, 89% plan to implement AI agents, 82% experienced identity-driven attacks or breaches, and 93% say NHI risk is urgent, according to C1.ai's 2025 Future of Identity Security Report. The signal is clear: identity security is shifting from access management to runtime governance across human, machine, and autonomous actors.

NHIMG editorial — based on content published by C1.ai: Key Takeaways From the 2025 Future of Identity Security Report

By the numbers:

Questions worth separating out

Q: How should security teams govern AI systems that can act without human approval?

A: Security teams should govern autonomous AI the same way they govern other high-risk identities, but with runtime enforcement instead of periodic review.

Q: Why do non-human identities create more risk than many human accounts?

A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.

Q: How can teams tell whether identity governance is actually reducing risk?

A: Look for fewer unmanaged identities, faster revocation of unnecessary access, and lower reliance on standing privilege.

Practitioner guidance

  • Inventory all high-risk non-human identities Map service accounts, API keys, tokens, certificates, and workload identities to owners, systems, and business purpose.
  • Separate agent permissions from human entitlements Do not mirror user roles directly into agent or workload access.
  • Measure identity blast radius before the next review cycle Assess which identities can reach the largest number of systems, records, or administrative functions.

What's in the full report

C1.ai's full blog covers the survey detail this post intentionally leaves for the source:

  • The full respondent breakdown by industry, including where identity incidents and AI adoption were most concentrated.
  • The report's comparative year-over-year trend lines for AI agents, identity-driven attacks, and NHI urgency.
  • The original wording behind the report's framing of controlled speed and operational pressure.
  • The broader survey context around budgeting, stress, and security team priorities.

👉 Read C1.ai's 2025 Future of Identity Security Report →

Agentic AI and NHI sprawl: what identity teams should prepare for?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Agentic AI makes identity governance a runtime discipline, not a provisioning discipline. The report's adoption signal matters because 89% of respondents plan to deploy AI agents, yet those systems can decide and act within the session. That means traditional IAM assumptions about stable access windows, predictable request patterns, and human-paced approval cycles no longer hold. The field has to treat agent behaviour as an identity problem in motion, not as a variant of workflow automation.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.

A question worth separating out:

Q: Who should own risk when an AI agent triggers privileged actions?

A: Ownership should sit with the team that governs the identity, tools, and downstream systems the agent can affect. Security, IAM, platform, and application teams all share pieces of the risk, but one named owner must be accountable for the full delegation chain. Without that, audit and response become fragmented.

👉 Read our full editorial: C1.ai report shows agentic AI and NHI risk rising together



   
ReplyQuote
Share: