Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk OWASP NHI Top 10
Governance, Ownership & Risk

OWASP NHI Top 10

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Governance, Ownership & Risk

A community-driven list of the most important security risks affecting non-human identities such as service accounts, API keys, OAuth apps, and AI agents. It gives security teams a common language for prioritising controls, comparing weaknesses, and building a structured NHI programme around the risks most likely to drive real exposure.

Expanded Definition

The OWASP NHI Top 10 is a risk-focused taxonomy for the most common and consequential failure patterns affecting non-human identities, including service accounts, API keys, OAuth applications, machine identities, and AI agents with execution authority. It is not a control standard in itself; rather, it is a prioritisation lens that helps security teams decide which NHI weaknesses deserve immediate attention. OWASP’s own OWASP Non-Human Identity Top 10 frames the topic around practical exposure rather than abstract identity theory, which is useful because NHI risk often emerges from how credentials are created, stored, reused, and revoked.

Definitions vary across vendors about whether AI agent tool permissions, workload identities, and ephemeral tokens belong in the same category, but the industry is converging on the idea that any identity used by software to act, authenticate, or access tools should be assessed through an NHI lens. NHI Management Group treats the Top 10 as an operational map for recurring control gaps, not a checklist to be satisfied once. The most common misapplication is treating it as a generic IAM overview, which occurs when teams apply human-identity policies to machine credentials without considering rotation, sprawl, overuse, and offboarding failure.

Examples and Use Cases

Implementing the OWASP NHI Top 10 rigorously often introduces classification and ownership overhead, requiring organisations to weigh faster delivery against the cost of inventory, review, and remediation discipline.

  • A platform team maps exposed API keys in code repositories to the relevant Top 10 risk category, then uses that mapping to drive secret scanning and rotation workflows, reducing reliance on ad hoc incident response.
  • An AI operations team reviews an agent’s tool access, prompt-invoked credentials, and fallback tokens against the OWASP Agentic AI Top 10 to separate agent misuse risk from ordinary application risk.
  • A security programme uses the Top 10 NHI Issues to prioritise fixes for weak secret storage, shared credentials, and forgotten service accounts across cloud workloads.
  • An organisation performs a quarterly review of OAuth apps and service accounts to identify overprivileged identities, then assigns each finding to a Top 10 issue category for remediation tracking and governance reporting.
  • A merger integration team applies the model to inherited infrastructure to find duplicated secrets, orphaned tokens, and non-expiring machine credentials before expanding access into production systems.

OWASP’s guidance is useful because it keeps the conversation grounded in observable failure modes instead of theoretical identity architecture. For supporting context on how often NHI weaknesses persist in real environments, see NHI Management Group’s Ultimate Guide to NHIs, which documents the operational patterns behind these risks.

Why It Matters in NHI Security

The OWASP NHI Top 10 matters because NHI incidents are often fast-moving, high-blast-radius events: once a token, key, or service account is exposed, the same identity may be reused across applications, environments, and automation paths. NHI Management Group research shows that 91% of former employee tokens remain active after offboarding, which illustrates how identity hygiene failures linger long after a personnel event. That same research also reports that 97% of NHIs carry excessive privileges, making risk categorisation and prioritisation essential rather than optional.

Used properly, the Top 10 helps security teams move from vague concern to concrete remediation by asking which identities are exposed, overused, unreconciled, or invisible to governance. It also supports Zero Trust thinking by forcing organisations to challenge standing access and weak trust assumptions around machine identities. The most important operational value is not the list itself, but the discipline it creates around ownership and response. Organisations typically encounter the true impact only after a token leak, service outage, or lateral movement event, at which point the OWASP NHI Top 10 becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01This framework is the source taxonomy for NHI risk patterns and priorities.
OWASP Agentic AI Top 10A-03Agent tool access and credential misuse overlap with agentic AI risk categories.
NIST CSF 2.0PR.AA-1Identity proofing and access management principles support control over machine identities.
NIST Zero Trust (SP 800-207)PA-7Zero Trust requires continuous verification of identities and their access context.
NIST AI RMFGOVERNAI governance covers access, accountability, and risk management for autonomous systems.

Classify machine-identity weaknesses against NHI-01 and build remediation queues around the highest-risk patterns.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org