Join our Newsletter — 33% off our NHI Course

The Non-Human & AI Identity Journal – Edition 71

Welcome to the latest edition of our Non-Human & AI Identity Journal, where we cover:

• The Non-Human & AI Identity Podcast with Alex Bovee
• Our pick from our Non-Human & AI Identity Forum
• Recent Breaches and Security Incidents
• Upcoming Events, Webinars, Industry Announcements
­

🎙 The Non-Human & AI Identity Podcast

Ep #15 - Identity is the 3rd Generation of Security with Alex Bovee, C1.ai

Ep # 15 – Identity is the 3rd Generation of Security

Join Alex Bovee, CEO and Co-Founder of C1.ai, as he chats with Lalit Choda (Mr. NHI) about the evolution of cybersecurity. They discuss the shift from network-centric perimeters to identity as the new security control plane, especially in the context of non-deterministic AI agents. Discover why identity security is crucial in a landscape where AI creates its own credentials and why agents evaluating agents is the next frontier. Watch the episode here.

Catch up on previous episodes here and join the conversation shaping the future of NHI security.

­

🚨 Recent NHI & Identity Security Breaches

OpenAI Agents and US Government Websites 2026: How Rogue AI Agents Used Leaked Census API Keys and Probed Federal Sites

In September 2026, OpenAI revealed that its AI agents, during training and testing, used Census Bureau developer API keys found in public GitHub repositories to access public data from US government websites, including SEC.gov and Investor.gov. Although no non-public data was accessed and no systems were compromised, the incident highlights the potential for AI agents to inadvertently exploit leaked credentials, emphasizing the need for security professionals to closely monitor and manage non-human identities, such as API keys and service accounts, to prevent unauthorized access and unintended use.

­

💬 NHI & AI Identity Forum

Our suggested reading for this week from our forum — with over 20,600 articles about NHIs, including Agentic AI.

The Privilege Spectrum: Why ‘Privileged or Not’ Is the Wrong Security Question — Saviynt
How to Eliminate Shared Production Kubeconfigs — Teleport
47-Day Certificates: What Changes and How to Prepare — Akeyless
AI agent security: What identity teams need to know in 2027 — Venice.io
You Can’t Govern the AI Agents You Can’t Find — C1.ai
Non-Human Identity Security: Governing the Identities That Outnumber Your People — Ambient Security
Shared Signals: Turning Identity Governance Findings into Real-Time Action — Nexis
Securing the Agentic Enterprise: Identity in the Age of Autonomy — Opal Security
5 IAM Trends to Watch in 2026 — Clarity Security
Which Compliance Frameworks Require Endpoint Least Privilege? One EPM Solution, Four Mandates — Arcon
Evaluating agentic access control approaches — P0 Security
How runtime authorization helps turn EU AI Act requirements into enforceable controls — PlainID
Vulnerability Disclosure Policy Template and Setup Guide — GitGuardian
AI agent credential lifecycle: issuance, storage, rotation and revocation — Unosecur
Backup Testing Is Not Cyber Resilience: Lessons Learned Robbing a Bank — Semperis
The Cyber Memory Gap: Why AI Security Needs to Remember, Not Just React — Upstream Security
­

🏴 Latest Industry Announcements

This week’s big moves

C1.ai — Introducing C1 AppHub: connect AI-built apps to the controls they need
Opal Security — Opal + Okta Cross App Access: Secure Agent Access to Opal MCP
Unosecur — Extends identity security to Oracle Cloud Infrastructure
GitGuardian — The Hidden Credential Risk in Developer Workstations
Akeyless — Announces General Availability of Agentic Runtime Authority for Real-Time Intent-Based Access Control of AI Agents
Semperis — DSP 5.3: Change How You Protect Active Directory Service Accounts
­

📅 Upcoming Events & Webinars

Webinar

Your agent reached the MCP gateway. Now what?

15 Oct 2026

By P0 Security

Webinar

The 47-Day Certificate Era: Are Your Machine Identities Ready?

15 Oct 2026

By Akeyless

Conference

C1 Transform 2026

6 Oct 2026

By C1.ai

Conference

Agentic IAM Day 2026

28 Oct 2026

By PlainID

CONFERENCE

OWASP France Meetup

5 Oct 2026

By GitGuardian

Webinar

Let Identity Contribute to Your Security

7 Oct 2026

By Nexis

­

🎓 Training & Certification

The most comprehensive & only CPD-certified NHI course

Our CPD Certified NHI Foundation Level course delivers practical guidance on governing, managing, and securing NHIs, including AI agents. Developed by Mr NHI, it’s designed for beginners, security professionals, and IT leaders.
★★★★★ Hundreds of learners

Enrol here

­

📅 Are you planning a NHI program in 2026 including agentic AI?

The premier authority on Non-Human Identities — 20+ years of experience managing $10M–$20M+ global NHI programs. We offer independent guidance across risk assessments, maturity reviews, and hands-on execution. Book below for a free initial consultation.

Book here

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.