Contact us
Request a demo

Non-Human Identities and AI Agents: Why IAM Governance Must Expand Its Scope

Service accounts, software bots, autonomous AI agents: a new class of identities is spreading across enterprise systems, one that traditional IAM was never built to govern.

Main robotique et main humaine interagissant avec des icônes d'identité numérique, d'accès et de données, illustrant les agents IA et les identités non humaines
Decoration

33 %

of enterprise applications will include agentic AI by 2028, up from less than 1% in 2024

Source : Gartner, October 2024

Decoration

15 %

of day-to-day operational decisions will be made autonomously

Decoration

40 %

of agentic AI projects will be abandoned by the end of 2027 due to inadequate governance

Source : Gartner, June 2025

Security isn't a roadblock to AI adoption. It's what keeps AI running in production.

Non-human identities: a silent growth carried by AI agents

While security teams have been focused on governing human identities (employees, partners, customers), another population of identities has been quietly expanding across enterprise systems: service accounts, software bots, cloud workloads, API keys. These non-human identities (NHIs) are not new. What has changed is their autonomy.


AI agents take this shift to a new level. An agent reasons, calls tools, interacts with other agents and accesses sensitive data, often without any human in the loop.



A Fast-Growing Identity Population Enterprises Can No Longer Ignore

A modern AI agent doesn't just execute predefined tasks. It interprets context, hands off subtasks to other agents and reaches for resources based on dynamic logic that's hard to predict in advance.


Organizations today typically manage anywhere from dozens to hundreds of non-human identities for every human identity, a ratio that keeps climbing as agent deployments scale (CyberArk, Oasis Security, Astrix, Silverfort, KuppingerCole). NHIs are now the fastest-growing identity population in the enterprise and often the least governed.

Three Blind Spots in Traditional IAM

A lifecycle with no HR trigger

Traditional IAM runs on HR events: an identity is created when an employee joins, updated on a role change, revoked on departure. AI agents skip every one of these checkpoints.


  • An agent is spun up by a workflow, sometimes for minutes, sometimes indefinitely

  • With no assigned owner or expiration date, its credentials often outlive its task


Delegation that falls outside the JML model

When a user delegates an action to an agent, traditional IAM has no good answer for:

  • Does the agent inherit the delegating user's full permissions?

  • Does it operate under its own identity and with what audit trail?

The Joiner-Mover-Leaver (JML) model was never designed for these hybrid authorization chains, where accountability gets diluted at every hop.



Shadow AI operating outside any identity inventory

SaaS copilots, automation scripts, MCP servers connecting an LLM to internal databases: this shadow AI typically runs on its creator's credentials, invisible to any identity inventory and unconstrained by least-privilege policy.


Four Requirements for Governing NHIs and AI Agents

  • Continuous Discovery: continuously map orphan accounts, bots, AI agents, and MCP servers, and integrate them into the repository immediately

  • Unified repository: humans, machines, and AI agents governed by the same principles (least privilege, SoD, recertification, automated revocation)

  • Explicit and traceable delegation: distinct identity, rights limited to the assignment, logged actions, a requirement reinforced by NIS2, DORA, and the AI Act

  • Contextual access control in real time: authorization evaluated at each action according to dynamic attributes (identity of the delegator, risk, data sensitivity), via a decision engine (PDP) coupled with a gateway


One Foundation, Not a Second IAM Program

When AI agents are organized into networks, governance can no longer target isolated entities: the entire chain must be covered, tracked, and revoked.


Treating NHI as a separate project would mean recreating, on the machinery side, the silos that took two decades to dismantle on the human side. The NHI subject does not replace the governance of human identities, it is added to them, in the same base and under the same authority. This approach allows the CISO to absorb the growth of non-human identities without relaxing the effort on the human side, and to prove to the audit that each identity is governed according to the same principles.


This is the conviction upheld by the Identity Factory, a European platform for governing access and human and non-human identities.

Published by

Alexis de Calan, Directeur du développement

Alexis de Calan

Development Director

Alexis de Calan is a co-founder of Memority, where he drives the company's growth in France and internationally. With over 20 years of experience in IT and cybersecurity, he brings recognized expertise in IAM and a strategic and operational vision of digital security transformations within large organizations.

Recent articles

Digital identity management in healthcare facilities: How Memority supports HospiConnect compliance

Calendrier

September 8, 2026

See how Memority, an IAM platform, helps healthcare facilities and hospital groups achieve HospiConnect compliance.

AI agent as a non-human identity accessing enterprise systems
AI agents are becoming new non-human identities to govern

IAM at a turning point: toward more visible, intelligent and dynamic identity management

Calendrier

August 12, 2026

IAM must now govern all identities, including service accounts and AI agents. Discover the three key evolutions (Visible, Intelligent, Dynamic) and why IAM is converging with the SOC to address Zero Trust. Alexis de Calan explains it all in video.

Carte de France dessinée par une foule de citoyens, symbole de la souveraineté numérique des collectivités territoriales

Identity and access management: a lever for local government's digital independence

Calendrier

July 2, 2026

On June 23 and 24, Memority participated in CoTer Numérique, the conference bringing together decision-makers from French local governments.