Skip to main content
Article 5

Digital Security Magazine 19th Edition

Control, Trust and accountability at scale

Identity for AI Agents: The new non human perimeter

A perimeter that shifted without warning

For decades, enterprise security operated on a comfortable premise: identities belonged to people. Access controls, authentication workflows, and governance frameworks were built around the assumption that behind every credential was a human being who could be verified and held accountable.

That premise is quietly dissolving.

AI agents — autonomous software entities capable of reasoning, planning, and acting across systems — are now entering the enterprise at scale. They query databases, call APIs, read documents, and execute transactions continuously, at machine speed, often without a human approving each step. Meanwhile, non-human identities (NHIs), the broader category that includes service accounts, API keys, tokens, and certificates, already outnumber human identities by ratios that continue to climb.

Recent research from Entro Labs found the NHI-to-human ratio at 144:1 in mid-2025, up from 92:1 just twelve months prior. AI agents are not only part of this population, but they are also accelerating its growth.


The question is no longer whether organizations will operate with non-human identities at scale. It is whether they are prepared to govern them.

Are existing assumptions outdated?

The Identity and Access Management (IAM) discipline evolved to solve a human problem. Multi-factor authentication (MFA) assumes a person can respond to a prompt. Privileged access management assumes elevated credentials are used deliberately, by someone who can articulate why. These controls work because humans are, broadly speaking, slow, predictable, and observable.

For autonomous agents operating across complex, dynamic workflows, these assumptions increasingly break down. An agent can be instantiated in milliseconds, act across dozens of systems within a single workflow, and terminate without leaving a conventional audit trail. The attack surface has expanded accordingly. Where a service account faces credential theft, an AI agent faces both credential theft and prompt injection — adversarial inputs that manipulate agent behaviour by inserting malicious instructions into the data the agent processes. These are structurally new threats, not variations on familiar ones. Applying human-centric controls to non-human actors creates gaps that are structural, not incidental.

Not all agents are equal: The taxonomy and risk gradient

Before organizations can govern AI agents effectively, they need to see them clearly. Risk is not uniform across agent types. Accordingly, governance controls must be proportional, not uniform. A working taxonomy should be able to distinguish the following:

  • Packaged agents embedded in SaaS platforms, where the vendor manages the security baseline (lower governance burden, but vendor due diligence still applies)
  • Low-code and no-code agents built by business users, where risk varies with connector scope, and misconfiguration is a common source of data exposure
  • Professionally coded agents carrying full SDLC risks: development errors, maintenance debt, and vulnerabilities requiring engineering-level governance
  • Autonomous agents operating without continuous human oversight, requiring kill-switch capabilities and defined human-in-the-loop checkpoints
  • Multi-agent systems, where coordination failures and emergent behaviors in agent-to-agent interactions introduce risks that extend beyond any individual agent
  • Shadow AI agents (arguably the most dangerous category) deployed without IT involvement, carrying no inventory, no ownership, and no audit trail. The defining risk is that security teams do not even know they exist.

The governance implication is direct: classifying agents by criticality determines the oversight model, not the other way around.

The first rule in governance decision: Choose the right identity

Choosing the right identity construct for an AI agent is not a technical detail; it is the first governance decision. For years, organizations have adapted existing identity types to serve non-human workloads such as service accounts for scheduled jobs, service principals for cloud applications, and managed identities for platform-native resources. None of these were designed for an actor that reasons autonomously and may interact with other agents in unpredictable ways.

The emergence of purpose-built agent identity frameworks marks a meaningful shift in how the industry is beginning to respond. While legacy identity constructs were designed for deterministic, human-supervised workloads, newer frameworks treat agent identity as a distinct category, with lifecycle management, authorization controls, and audit logging designed specifically for autonomous systems.


The principle is consistent across implementations: agents should be provisioned with dedicated, purpose-scoped credentials, short-lived where possible, revoked automatically when the agent’s function ends, and linked to clear ownership and accountability chains.

Four shifts that are reshaping the landscape

    1. Dynamic, context-aware authorization

Traditional role-based access assigns fixed permissions that persist until changed. For agents operating across variable workflows, zero-trust principles (never assume, always verify) are better suited. Least-privilege must evolve into least privilege at runtime.

    1. Behavioral observability beyond logging

Effective monitoring for agents requires tracking not just what was accessed, but what decisions were made, and whether those decisions deviate from baseline patterns, including sequence anomalies where an NHI operates at unusual velocity within otherwise normal scope. The NIST AI Risk Management Framework and the EU AI Act emphasize traceability requirements that translate directly into demands on identity infrastructure.

    1. Federated accountability in multi-agent environments

As agents delegate to other agents and operate across vendor boundaries, accountability becomes federated. Interoperable identity standards, such as those being developed by the FIDO Alliance and the OpenID Foundation, carry accountability attributes across trust boundaries. These are essential infrastructure, not a future consideration.

    1. Identity as an enabler, not a constraint

Organizations that design identity governance into AI deployments from the start, rather than retrofitting it after the fact, gain the observability and control structures that allow them to extend trust deliberately and scale with confidence.

Critical implications that leaders and organizations need to consider

For CISOs, the immediate priority is an inventory that provides a complete picture of the AI agents operating within the environment, the credentials they hold, and the oversight mechanisms in place. Shadow agents represent a structural blind spot. Continuous NHI discovery, secrets-vault enforcement with automated rotation, and CI/CD controls that block hardcoded credentials are baseline hygiene requirements at this scale.

For CIOs and CTOs, identity infrastructure must be a first-class component of AI deployment architecture. Platforms that cannot support auditable, dynamic identity for non-human actors will accumulate technical debt as agent usage scales. For boards and policymakers, the question is accountability. Regulators across the EU, UK, and a growing number of jurisdictions are already asking how AI systems are supervised and what audit trails exist. Organizations with mature NHI governance will be better positioned to answer.

The work ahead is collective

The emergence of AI agents as first-class enterprise actors is one of the defining security transitions of this decade.


What distinguishes organizations navigating it well is not the sophistication of any single technology, but the clarity of their thinking: who (or what) is acting in their environment, what those actors are authorized to do, and how that authorization can be verified, monitored, and withdrawn.

The non-human perimeter is already here. The work of governing it thoughtfully, collaboratively, and with appropriate urgency is the work of the present.

Identity is necessary but not sufficient; runtime control, delegated authority, and observability are equally important.

A pragmatic starting point

Readiness begins with visibility. Organizations that are ahead of this challenge tend to share a common discipline. Here’s what they do:

  • Maintain a live inventory of agents and associated NHIs across their environment.
  • Classify agents by autonomy, privilege, and data exposure rather than treating them as uniform.
  • Mandate every agent to carry a dedicated identity, a named owner, and a defined lifecycle with an expiry condition.
  • Enforce short-lived credentials, secrets vaulting, and least privilege access at runtime.
  • Integrate agent activity into their broader monitoring, governance, and response workflows so that behavior can be reviewed (and access revoked) when needed.

AI agents are becoming part of how enterprises operate, but trust in their actions will depend on how well their identities are governed. The organizations that move fastest will not be those that give agents the broadest freedom, but those that define clear ownership, enforce contextual access, monitor behavior continuously, and retain the ability to revoke authority instantly. In the age of autonomous systems, identity governance is no longer just an IAM discipline; it is the foundation for accountable, secure, and scalable AI adoption.

Are you certain of which non-human identities operate in your environment, what they are authorized to do, and how that access can be monitored as these systems evolve? If not, you need to mobilize a scalable identity governance strategy that can help you assess your position and get you started on your adoption journey today.

Connect with us and learn how you can get started on your NHI governance strategy today.

Share this article

X IconLinked-in Icon

George Gardon

Global Portfolio Manager

View detailsof George Gardon >
  • Follow George Gardon on LinkedIn
 

Raul Salagean

Global Deputy Product Director for Cloud & Application Security, Atos

View detailsof Raul Salagean >
  • Follow Raul Salagean on LinkedIn
 

Valentin Pop

Cybersecurity IAM Architect

View detailsof Valentin Pop >
  • Follow Valentin Pop on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Control, Trust and Accountability at Scale

Agentic AI threat modeling: When AI starts acting

Cyber at machine speed: can your security program keep up?

Digital sovereignty in the age of AI: Control over decisions, not just data

Move from prediction to resilience: Navigating the new cyber equilibrium

Rethinking the AI supply chain security: Models, data, agents, tools, and the new skills layer

Securing AI workloads across the hybrid and multi‑cloud AI supply chain

Trustworthy AI is lost without security: Turning principles into enforceable controls