The recent developments in machine identity and non-human identity (NHI) security underscore a critical shift in how organisations approach identity governance. As AI agents and automated systems proliferate across enterprise environments, traditional identity frameworks designed for human users are proving inadequate.

The fundamental challenge is scale and complexity. Machine identities — service accounts, API keys, certificates, and tokens — now outnumber human identities in most organisations by 40:1 or higher. Yet most enterprises lack comprehensive visibility into their machine identity inventory.

Agentic AI and Machine Identity Lead Agenda as Gartner Tokyo Security Summit Opens represents a critical milestone in acknowledging this governance gap. The emergence of dedicated solutions and industry standards signals that NHI security is transitioning to mainstream discipline.

The rise of agentic AI compounds urgency. Autonomous AI systems interact with enterprise infrastructure through machine identities. Without proper NHI governance, each deployed AI agent introduces unmanaged privileged access.

For security teams, the path forward requires three capabilities: comprehensive discovery of machine identities, intelligent governance with least-privilege access, and continuous monitoring for anomalous behaviour.

The stakes are high. Attackers increasingly target machine identities as the path of least resistance. Recent research shows stolen credentials are leveraged in lateral movement and privilege escalation at scale.

Organisations treating machine identity governance as an afterthought do so at their peril. Cloud adoption, containerisation, and AI deployment mean machine identities are central to security posture.

Looking forward, NHI governance will become as fundamental as human IAM. Early-adopting organisations will have significant security advantage.