Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI identity security and NHI sprawl: what IAM teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: AI is pushing identity security beyond human users, as enterprises now manage machine identities, AI agents, APIs, workloads, and service accounts that authenticate autonomously and expand the attack surface, according to BigID. The core shift is that governance must connect identity, activity, and data access, because static IAM controls were built for interactive human behaviour, not continuous machine execution.

NHIMG editorial — based on content published by BigID: AI is changing the identity landscape faster than most organisations realise

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that use service accounts and MCP tools?

A: Start with ownership, then add runtime attribution and containment.

Q: Why do non-human identities create more risk than many human accounts?

A: NHIs often outnumber human users, have broader permissions, and operate with less day-to-day review.

Q: What breaks when organisations cannot see their non-human identities?

A: When NHIs are invisible, least privilege, credential rotation, and access review all become incomplete.

Practitioner guidance

  • Inventory every non-human identity Build a complete register of service accounts, API keys, tokens, certificates, workloads, bots, and AI agents.
  • Link identity to data exposure Classify the sensitive data each machine identity can reach and map that access to actual workflows.
  • Enforce least privilege for machine execution Review every permission set for overbroad inheritance, duplicated entitlements, and dormant access.

What's in the full article

BigID's full article covers the operational detail this post intentionally leaves for the source:

  • A practical breakdown of how BigID positions identity-to-data governance across cloud, SaaS, and AI workflows.
  • Examples of the exact identity categories it groups together, including workloads, bots, service accounts, and AI agents.
  • The article's own identity security assessment questions for checking whether your machine identity posture is mature enough.
  • A vendor-specific description of how BigID says it helps with discovery, monitoring, and remediation.

👉 Read BigID's analysis of human versus non-human identity security →

AI identity security and NHI sprawl: what IAM teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI identity security is now an NHI governance problem, not a human IAM extension. The article is right to shift the frame away from user logins and toward machine identities that act continuously across cloud and SaaS. That change matters because service accounts, tokens, and AI agents are governed differently from employees, yet many programmes still treat them as edge cases. The practitioner conclusion is simple: the governance model must match the actor type.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, which turns identity lifecycle gaps into persistent exposure.

A question worth separating out:

Q: How do teams know if NHI governance is actually working?

A: Look for complete inventory coverage, clear ownership, enforced rotation, and reliable decommissioning. If new credentials appear faster than they are classified, or if stale secrets stay valid after workload changes, the programme is not governing machine identities effectively.

👉 Read our full editorial: AI identity security requires governance beyond human users



   
ReplyQuote
Share: