AI Agents Are NHIs: Closing the Non-Human Identity Governance Vacuum

·11 min read·Evergreen Tools Team

When you connect an AI agent to a production system, you are adding a non-human identity (NHI) to it: something that authenticates, queries data, and takes action, and that often has no assigned owner. The security industry has started naming this gap the non-human identity governance vacuum. It is no longer abstract. It is the fastest-growing category of identity in 2026 and the one most often left unmanaged.

"Robots and identity"

"Agents are non-human identities"

1. The Scale Is No Longer Marginal

GitGuardian puts non-human identities at more than ten times the number of humans in cloud-native organizations. Behind that number are API keys, OAuth tokens, service accounts, certificates, and now AI agents and MCP servers. Many were never formally provisioned or tracked, yet hold persistent access to sensitive systems. Traditional IAM was designed around humans and cannot handle this volume or rate of growth. The problem is not that these identities exist; it is that nobody owns them, so nobody rotates them, and nobody notices when one is used from an unexpected place.

# 1) Every non-human identity gets an owner, an expiry, and a purpose.
REGISTRY = {
    "agent-42": {
        "kind": "ai-agent",
        "owner": "team-payments",
        "purpose": "reconcile refunds",
        "grants": ["read:ledger", "write:notes"],
        "expires_at": "2026-10-21",
        "vendor": None,
    },
    "mcp-inventory": {
        "kind": "mcp-server",
        "owner": "team-platform",
        "purpose": "read product stock",
        "grants": ["read:inventory"],
        "expires_at": "2026-10-21",
        "vendor": "acme",
    },
}

def orphans(registry: dict) -> list:
    return [k for k, v in registry.items() if not v.get("owner")]

2. Why AI Agents Make the Vacuum Dangerous

Because agents fuse credential and decision-making. An old script was deterministic: it did only what it was hard-coded to do. An agent reasons and composes tools, so a stolen agent credential is not just "can read one bucket" but "can autonomously decide what to read, write, and call within its boundaries." Once a credential leaks, what is at stake is not just access scope but the behavioral ceiling of the blast radius. That is why agent credentials deserve tighter lifecycles than a static service account ever did.

// 2) Least privilege at call time: scope narrows to the current task.
function scopedToken(agent, task) {
  const base = new Set(agent.grants);
  const needed = new Set(task.required);
  for (const g of needed) {
    if (!base.has(g)) throw new Error("task needs grant not held: " + g);
  }
  return {                              // short-lived, task-bound
    subject: agent.id,
    scope: [...needed],
    ttlSeconds: 300,
  };
}

const tok = scopedToken(REGISTRY["agent-42"], {
  required: ["read:ledger"],
});

3. The Time Window Is Collapsing

The 2026 Verizon Data Breach Investigations Report documents AI compressing attacker exploitation cycles from weeks to hours, and the same 2026 DBIR records a 60% year-over-year increase in supply chain breaches. That means a "leaked at midnight, exploited before morning" cadence no longer matches the rotation and revocation response times of most organizations. Slow governance against machine-speed attacks is not governance. The practical response is to shrink the window itself: rotate faster, revoke faster, and alert on the first use of a credential from a new location rather than on the tenth unusual call.

# 3) Behavioral monitoring: flag creep, anomalies, orphans.
def review(event: dict, baseline: dict) -> list:
    flags = []
    used = set(event["grants_used"])
    if used - set(baseline["grants_expected"]):
        flags.append("unexpected-grant-use")
    if event["calls_per_min"] > baseline["p99_calls_per_min"] * 3:
        flags.append("volume-anomaly")
    if not event.get("owner"):
        flags.append("orphan-identity")
    return flags

4. Bring Agents Into the NHI Registry

Governance starts with visibility. You need one registry that lists every non-human identity item by item: what it is, who owns it, which permissions it holds, when it expires, and how to revoke it. AI agents and MCP servers should be first-class entries in that list, not exceptions. The Cloud Security Alliance makes the same point in its non-human identity governance whitepaper: third-party agent deployments belong in the NHI registry, with added metadata for the vendor identity, contractual security obligations, and review cadence.

// 4) Revocation in minutes: one switch kills every live token.
const revoked = new Set();   // shared, replicated store in production

function denyIfRevoked(agentId) {
  if (revoked.has(agentId)) {
    throw new Error("identity revoked: " + agentId);
  }
}

function revokeNow(agentId, reason) {
  revoked.add(agentId);
  audit({ ts: Date.now(), agent: agentId, action: "revoke", reason });
}

5. Four Principles That Survive Production

First, least privilege: an agent gets only what the current task needs, and gives it back when done. Second, lifecycle governance: every identity has an owner, an expiry, and a rotation policy, with no "never-expires token." Third, behavioral monitoring: watch continuously for abnormal calls, privilege creep, or orphaned accounts. Fourth, revocability: be able to cut off an agent in minutes, not days. The code below sketches registry, least privilege, monitoring, and revocation. The real test of a governance program is not the policy document; it is how many minutes it takes to cut off a compromised agent at three in the morning.

# 5) Third-party agents: inventory with contract metadata.
THIRD_PARTY = {
    "agent-crm": {
        "vendor": "acme",
        "security_obligations": "SOC 2 Type II, breach notice < 24h",
        "review_cadence_days": 180,
        "last_review": "2026-08-01",
    },
}

def due_for_review(entry: dict, today: str, days_since) -> bool:
    return days_since(entry["last_review"], today) > entry["review_cadence_days"]

6. Regulatory and Audit Pressure Is Closing In

Even without dedicated agent regulation, pressure is converging from several directions. NIST has committed to publishing an AI Agent Interoperability Profile by Q4 2026 and is developing SP 800-53 control overlays for agentic systems. IANS Research found in February 2026 that roughly half of large enterprises have established dedicated AI governance committees. That means when regulation does land, whoever can produce an audit trail holds the initiative. The highest-value move is not to wait for the standard but to make three things provable now: who acts on your behalf, what it is allowed to do, and how you can demonstrate it.

"Dashboard and monitoring"

"Visibility is the starting point"

"Workspace"

"Every identity has an owner"

📌 Frequently Asked Questions

What is a non-human identity (NHI)?

An identity used by applications, machines, and automation, including API keys, OAuth tokens, service accounts, secrets, certificates, and AI agents. They vastly outnumber human identities.

Why do AI agents make NHI governance more urgent?

Because agents fuse credentials with autonomous decision-making. A stolen agent credential is not just an access-scope problem but an actor that can decide what to read, write, and call within its boundaries.

How big is the scale?

GitGuardian puts non-human identities at more than ten times the number of humans in cloud-native organizations, with AI agents and MCP servers the fastest-growing category.

Why does the time window matter?

The 2026 Verizon DBIR shows AI compressing attacker exploitation from weeks to hours and records a 60% year-over-year rise in supply chain breaches, so slow rotation and revocation cannot keep up.

Where is regulation heading?

NIST has committed to publishing an AI Agent Interoperability Profile by Q4 2026 and is developing SP 800-53 control overlays for agentic systems; organizations should treat these as inputs to their governance frameworks.