An explosion of identities that are difficult to categorize
Non-human identities (NHIs) include service accounts, application secrets, certificates, API keys, RPA bots, AI agents, connected devices, and cloud workloads—all of which are associated with very real access rights. With the widespread adoption of cloud-native architectures, microservices, and—above all—the emergence of autonomous AI agents, which can themselves generate new NHIs, these identities now far outnumber human identities: in cloud-native environments, the measured ratio stands at 144 to 1, up from 92 to 1 a year earlier. Largely invisible to application, IAM, and security teams, they form a “dark mass” where excessive and persistent permissions create an ideal breeding ground for attackers.
Underestimated systemic risks
Machine identities often have elevated privileges for the sake of convenience—the opposite of the principle of least privilege (“with full access, I’m sure it works”)—without regular review or an identified owner. Technical accounts left active after a migration, API tokens with excessively long lifespans, and hard-coded service passwords: these are all subtle yet critical entry points. The paradox is clear when viewed through the lens of Zero Trust: controls are tightening around humans while machines continue to enjoy implicit trust. A compromised OAuth token, an API key exposed in a Git repository, or an overprivileged principal service can bypass the security mechanisms applied to users—exploiting these has become a central step in recent cloud compromises. Added to this is an unexpected deadline: the maximum lifespan of TLS certificates—reduced to 200 days as of March 2026—will drop to 100 days in March 2027, making any manual management unsustainable.
AI agents are changing the nature of the problem
The advent of autonomous agents introduces a new category of identities and, at the same time, challenges the frameworks designed to govern them. Behavioral supervision assumes a stable expected behavior, which a non-deterministic agent does not exhibit; periodic discovery-based inventory assumes a fleet that is slower than the scan cycle, whereas an agent can instantiate its own identifiers at runtime. Above all, in the majority of observed deployments, the agent does not act under its own identity but by delegation of an employee’s identity: the boundary between human and non-human identities—on which most current IAM systems rely—is blurring. The gap between usage and control is well documented: by 2026, more than nine out of ten organizations will be using AI agents, yet only one in ten will have a mature strategy for managing them. New approaches no longer view NHIs as mere variants of user accounts. They combine continuous discovery, owner assignment, lifecycle management, least privilege, secret hygiene, conclusive traceability, and the ability to interrupt operations. The last two levers are the least well-equipped and the ones least resistant to agents.
Traceability: A Prerequisite for Accountability
When an agent initiates a transfer, modifies an access right, or deploys a patch to production, the application log shows an action authorized by a valid token, without indicating who initiated it, under whose authority, or who is responsible for it. Three levels must be recorded: the technical identity (credential), the execution identity—the agent or workload performing the action—and the originator identity—the person or process that authorized the action. A log that records only the first level has no accountability value. Moreover, mere recording is not enough: a modifiable, unsealed log does not constitute evidence. Qualified timestamping, cryptographic chaining, write-once capability, and actual usability at the time of the incident form the minimum foundation, which the European AI Regulation, NIS2, and DORA each require within their respective scopes, without distinguishing between human and machine actors.
The emergency shutdown (kill switch), to be designed before the incident occurs
Deactivating a user account terminates all sessions. Revoking an agent’s credential does not stop any processes already in progress: the issued access tokens remain valid until they expire if the consuming resources do not check for revocation with each call, and the subprocesses to which the agent has delegated its rights continue to operate after the agent is deactivated. The ability to shut down operations therefore depends on the tokens’ lifespan and knowledge of the delegation chain. An effective mechanism is phased, ranging from suspending new calls to freezing writes and then to complete revocation, with each level associated with a documented business impact. It must be triggerable by monitoring without hierarchical approval and tested periodically: a system that is never tested is not a system that is available.
A Strategic Issue
The rise of AI, RPA, and multi-cloud will only accelerate this proliferation. Organizations that delay integrating these identities into their IAM governance are building their cybersecurity on a foundation riddled with critical accounts that slip under the radar. The challenge is no longer simply to manage identities, nor even to secure all entities capable of acting within the information system, whether human or artificial. It is to be able to stop deviant behavior as early as possible and to establish, at any time and in a legally enforceable manner, who did what, under whose authority, and who is accountable.
