33 %
of enterprise applications will include agentic AI by 2028, up from less than 1% in 2024
Source : Gartner, October 2024
15 %
of day-to-day operational decisions will be made autonomously
40 %
of agentic AI projects will be abandoned by the end of 2027 due to inadequate governance
Source : Gartner, June 2025
Security isn't a roadblock to AI adoption. It's what keeps AI running in production.
Non-human identities: a silent growth carried by AI agents
While security teams have been focused on governing human identities (employees, partners, customers), another population of identities has been quietly expanding across enterprise systems: service accounts, software bots, cloud workloads, API keys. These non-human identities (NHIs) are not new. What has changed is their autonomy.
AI agents take this shift to a new level. An agent reasons, calls tools, interacts with other agents and accesses sensitive data, often without any human in the loop.
A Fast-Growing Identity Population Enterprises Can No Longer Ignore
A modern AI agent doesn't just execute predefined tasks. It interprets context, hands off subtasks to other agents and reaches for resources based on dynamic logic that's hard to predict in advance.
Organizations today typically manage anywhere from dozens to hundreds of non-human identities for every human identity, a ratio that keeps climbing as agent deployments scale (CyberArk, Oasis Security, Astrix, Silverfort, KuppingerCole). NHIs are now the fastest-growing identity population in the enterprise and often the least governed.
Three Blind Spots in Traditional IAM
A lifecycle with no HR trigger
Traditional IAM runs on HR events: an identity is created when an employee joins, updated on a role change, revoked on departure. AI agents skip every one of these checkpoints.
- An agent is spun up by a workflow, sometimes for minutes, sometimes indefinitely
- With no assigned owner or expiration date, its credentials often outlive its task
Delegation that falls outside the JML model
When a user delegates an action to an agent, traditional IAM has no good answer for:
- Does the agent inherit the delegating user's full permissions?
- Does it operate under its own identity and with what audit trail?
The Joiner-Mover-Leaver (JML) model was never designed for these hybrid authorization chains, where accountability gets diluted at every hop.
Shadow AI operating outside any identity inventory
SaaS copilots, automation scripts, MCP servers connecting an LLM to internal databases: this shadow AI typically runs on its creator's credentials, invisible to any identity inventory and unconstrained by least-privilege policy.
Four Requirements for Governing NHIs and AI Agents
- Continuous Discovery: continuously map orphan accounts, bots, AI agents, and MCP servers, and integrate them into the repository immediately
- Unified repository: humans, machines, and AI agents governed by the same principles (least privilege, SoD, recertification, automated revocation)
- Explicit and traceable delegation: distinct identity, rights limited to the assignment, logged actions, a requirement reinforced by NIS2, DORA, and the AI Act
- Contextual access control in real time: authorization evaluated at each action according to dynamic attributes (identity of the delegator, risk, data sensitivity), via a decision engine (PDP) coupled with a gateway
One Foundation, Not a Second IAM Program
When AI agents are organized into networks, governance can no longer target isolated entities: the entire chain must be covered, tracked, and revoked.
Treating NHI as a separate project would mean recreating, on the machinery side, the silos that took two decades to dismantle on the human side. The NHI subject does not replace the governance of human identities, it is added to them, in the same base and under the same authority. This approach allows the CISO to absorb the growth of non-human identities without relaxing the effort on the human side, and to prove to the audit that each identity is governed according to the same principles.
This is the conviction upheld by the Identity Factory, a European platform for governing access and human and non-human identities.




