TL;DR: Machine identities now outnumber human identities 109:1, and Linx Security cites research showing only 44% of organisations have policies to manage AI agents even as 92% say governance is critical. The governance gap is no longer theoretical: identity data, ownership, lifecycle, and least-privilege controls have to be redesigned for human, non-human, and agentic identities together.
NHIMG editorial — based on content published by Linx Security: The Identity Landscape Changed. Your IGA Needs to Catch Up
By the numbers:
- Machine identities now outnumber human identities 109:1, according to Palo Alto Networks' 2026 Identity Security Landscape.
- Only 44% of respondents have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
Questions worth separating out
Q: What breaks when IGA is not built on a central identity view?
A: Access review loses context when identities, roles, and entitlements are scattered across systems.
Q: How can teams govern machine identities and AI agents in access reviews?
A: Teams should assign ownership, define review cadence, and include machine identities and AI agents in the same certification logic as human access, but with role-appropriate approvers.
Q: How do security teams know whether least privilege is actually working?
A: Least privilege is working when identities have narrowly scoped permissions, unused credentials are removed or quarantined, and repeated access reviews consistently shrink entitlements.
Practitioner guidance
- Correlate identity data before expanding governance automation Map identities, accounts, entitlements, ownership, and lifecycle state across HR, IdP, SaaS, cloud, and engineering sources before adding new certification or remediation workflows.
- Assign explicit owners to every non-human identity Create business ownership for service accounts, workload identities, API keys, and AI agents so access decisions and exception handling have a clear accountable party.
- Treat least privilege as a continuous control Continuously detect stale, unused, excessive, and incompatible access rather than relying only on quarterly reviews to catch privilege drift.
What's in the full article
Linx Security's full blog covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of how Linx structures identity graphs across HR, IdP, SaaS, cloud, and engineering sources.
- Examples of how the article sequences automation for terminations, expired access, and clearer policy violations.
- More detail on how Linx frames governance outcomes such as reduced excessive access and faster remediation.
- The article’s own guidance on when to expand modern IGA from workforce identities into NHIs and AI agents.
👉 Read Linx Security’s analysis of modern identity governance for human, NHI, and AI identities →
Machine identities and AI agents are outgrowing traditional IGA?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity governance is now a multi-actor discipline, not a workforce-only process. The article’s strongest point is that IGA has to cover employees, service accounts, workloads, API keys, machine identities, and AI agents inside the same governance model. That is a structural change, not a feature update, because the old workforce-centric lifecycle no longer matches how access is created, changed, and retired. Practitioners should treat governance coverage as the control boundary, not the HR directory.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations use AI for identity governance before they clean up data and policies?
A: No. AI should not be asked to decide access when identity records, entitlement labels, and policy rules are inconsistent. The better sequence is to normalise data, standardise approval criteria, and then apply AI to assist with scale, because automation amplifies the quality of the inputs it receives.
👉 Read our full editorial: Identity governance must shift for machine identities and AI agents