惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible
Non-human identity sprawl is agentic AI's real risk
Nick Nikols · 2026-05-01 · via informationweek

Enterprises have long depended on non-human identities such as service accounts, API keys, OAuth tokens and other credentials that allow services to interoperate inside digital environments. In modern cloud architectures and continuous development pipelines, these identities consistently outnumber human users, yet their governance rarely reflects the scale and authority they now hold.

A recent NIST request is telling. Just weeks into 2026, the organization issued a request for public input on how organizations should securely develop and deploy AI agent systems. The notice comes at a moment when many enterprises are beginning to operationalize agentic AI, embedding systems designed to not just generate outputs, but also interpret instructions, make determinations and carry out actions across applications and infrastructure.

Agentic systems are beginning to be used in production, while the security and governance models intended to provide their guardrails are still being defined. In too many cases, controls are added to these systems after the authority to use them has already been granted, creating an avoidable yet immense risk as agentic AI is adopted within organizations.

Related:AI and connected systems are forcing CIOs and COOs to rethink OT security

Traditional identity programs were built around people. They incorporate structured onboarding, defined roles, periodic reviews and clear accountability to manage human users through the cycle of their access and responsibilities within the enterprise.

But non-human identities (NHIs) are often overlooked by these governance processes. They persist quietly in the background, often are provisioned as part of administrative activities to keep systems running, and are often granted long-term credentials with elevated permissions -- providing rich targets for attackers. As with human identities, there are best practices, such as least-privilege permission assignments and frequent credential rotation, that can help better secure the use of these NHIs. Applying appropriate governance processes to the creation, daily use and ongoing maintenance of NHIs can help ensure secure automation and more effective control.

When automation within enterprises was limited and tightly scoped, this gap may have carried less consequence. Today, it holds far more weight as AI agents are instantiated, execute processes and interact across systems, coordinating workflows and advancing tasks without an integral human role.

When NHIs act, weak controls scale fast

Agentic systems are designed to take action, retrieve data, interact with internal systems and move workstreams forward within the permissions they are granted. A recent report from Deloitte found that nearly three-quarters of 3,325 leaders surveyed plan to deploy agentic AI within two years. As those systems interact across applications and data sets, the scope of their authority matters even more.

When permissions are overly broad or poorly governed, AI agents amplify those weaknesses at machine speed. Sensitive data may have greater exposure than intended, workflows may extend beyond their original design assumptions, and minor configuration gaps can cascade into larger operational risk. The issue is not simply the risk of breach; it's the scale at which unintended outcomes may occur.

The measures needed to secure AI agents are not conceptually new. Many of the principles applied to human users -- least privilege, defined ownership, periodic review -- remain directly applicable to NHIs. What changes is the consistency and coordination required when those principles are extended to non-human actors operating continuously and at scale.

In practice, that includes:

  • Define: Assigning each agent a unique identifier and establishing tightly scoped, purpose-driven permissions for both human and non-human actors supporting agent workflows.

  • Assess: Assigning clear ownership and ongoing review processes for NHIs to prevent orphaned identities, stale credentials and permission sprawl.

  • Enforce: Protecting sensitive data through encryption and persistent policy controls that remain enforced, regardless of how or where the data is accessed.

  • Detect: Monitoring access patterns and behavioral access changes to surface unusual activity or drift from expected norms.

  • Automate: Enabling automated response capabilities that can restrict access or suspend credentials when risk thresholds are met, without disrupting essential operations.

For security leaders, this is less about inventing new frameworks and more about extending existing governance disciplines to a class of actors that operates continuously at scale. Identity defines what an agent is allowed to do, making disciplined permissions and constant visibility into these identities essential to maintaining control as automation expands.

Security that doesn't tax velocity

Enterprises are investing in agentic systems to streamline operations, reduce manual effort and accelerate decision-making. The objective of identity and access management strategies for agents is not to slow that momentum, but to ensure that expansion happens in a controlled and sustainable way to not scale risk.

When agents are securely developed, provisioned with clearly bounded authority and monitored alongside the data they access, organizations gain confidence to expand deployment and scale automation innovation with their business. Risk doesn't disappear, but it becomes more visible and governable, rather than compounding quietly over time until it becomes too significant to easily contain.

NIST's request for input reflects an industry still formalizing standards around agentic systems, but organizations can't afford to wait for finalized frameworks before acting. Agentic AI is already advancing into core business processes. How successfully it scales will depend on whether governance evolves in parallel -- ensuring agents operate within defined identity boundaries, with data protection intentionally integrated at every stage.

About the Author

Nick Nikols

OpenText Cybersecurity

Nick Nikols is vice president of identity and access management products at OpenText Cybersecurity. He has more than 25 years of experience in the software industry, both in developing industry-leading identity and cybersecurity solutions and as an industry analyst conducting research and helping clients with issues ranging from consumer identity and securing cloud environments to access governance and secure DevOps.

Nick has held leadership positions at companies including CA Technologies, Quest Software and Novell. He also served as a research director at Gartner and held research roles at TechVision Research and Burton Group.