AI agents are rapidly changing the enterprise identity estate. A reported 76% increase in non-human identities shows that security teams can no longer treat this as a future architecture concern. Every service account, workload identity, token, API key and autonomous agent represents a machine identity with the ability to act continuously and at machine speed.
The problem is not simply volume. Organizations still govern NHIs with processes designed for employees: periodic reviews, manual ownership and controls that assume a person is visible at the point of access. An agent may create sessions, call tools, delegate work and obtain short-lived credentials across several systems, leaving a fragmented record of what happened.
Establishing accountable machine identities
Security teams need a continuously updated map of machine identities, owners, privileges, credentials, dependencies and observed behavior. Discovery must extend to cloud workloads, secrets in code, automation platforms, SaaS integrations and agent frameworks.
Applying context-aware least privilege
Risk context matters. An unused credential and an actively delegated agent identity should not be assessed alike. Signals should include privilege, environment, data sensitivity, authentication method, behavioral deviation and business purpose.
Monitoring identity behavior
Governance must become operational: short-lived credentials, just-in-time permissions, explicit agent boundaries and automated remediation. The 76% increase is a measurement challenge as much as a warning: without NHI security telemetry, organizations cannot know whether controls match their deployed identities.
Source: Infosecurity Magazine