Identity is the New Perimeter - Solving the Non-Human Identity Sprawl
Non-human identities now outnumber humans 50 to 1 in enterprise environments. Most are unmanaged, unmonitored, and outside the scope of traditional IAM programmes. This article explains what that risk looks like in practice — and how security teams can build the governance capability to address it.

The Identity Problem Nobody Is Talking About
Ask any IAM leader how many identities they govern, and they will tell you their headcount. Ask them how many machine identities operate in the same environment, and most will pause.
The answer is almost always a number that surprises them.
According to research from the Identity Defined Security Alliance, non-human identities (NHIs) outnumber human users by 50 to 1 in enterprise environments. For a 300-person organisation, that could translate to more than 15,000 machine credentials — service accounts, API keys, OAuth tokens, AI agent access grants, and certificates — most of them unmanaged, unmonitored, and completely outside the scope of traditional identity governance programmes.
This is not a future problem. Two thirds of enterprises have already suffered a breach via a compromised NHI. And in 2026, with AI agents embedded in nearly every enterprise SaaS platform, the ratio is accelerating faster than most IAM teams can track.
What Exactly Is a Non-Human Identity?
Before diving into why this matters, it helps to be specific about what we are actually dealing with.
A non-human identity is any digital credential that allows a machine, application, script, or automated process to authenticate to a system — without a human being directly involved in the transaction. This includes:
Service accounts used by applications to access databases or internal APIs
OAuth tokens created when employees connect SaaS tools to business systems
API keys used by developers, third-party integrations, and increasingly by AI agents
SSH keys and certificates used to authenticate infrastructure
AI agent credentials — the newest and fastest-growing category
The critical point is that none of these behave like human identities. They bypass MFA by design. They don't follow normal working hours. They don't have a manager who can certify their access annually. And they don't get offboarded when a project ends — they simply accumulate, quietly, in the background.
Why Token Theft Has Replaced Password Cracking
In 2026, sophisticated attackers are not trying to guess passwords. They are targeting the authentication layer — specifically the OAuth tokens, API keys, and session cookies that non-human identities use to move between systems.
The reason is straightforward: a stolen token is far more valuable than a stolen password. A token typically carries the full permissions of the account it represents, doesn't trigger MFA challenges, and can be used to authenticate across multiple connected systems without raising obvious alerts. Because machine-to-machine traffic looks like normal system activity, these attacks frequently go undetected for months.
The numbers from 2026 research illustrate the scale of the problem:
28.65 million hardcoded secrets were added to public GitHub repositories in 2025 alone — a 34% year-over-year increase (GitGuardian)
AI-related credentials specifically grew 81% year-over-year, the fastest growth in any single credential category
6.2 million exposed credentials or authentication cookies tied to AI tools were uncovered by SpyCloud researchers in 2025
Only 12% of organisations report high confidence in their ability to prevent NHI-based attacks (Cloud Security Alliance)
The pattern is consistent: as AI adoption accelerates, every new tool connection creates a new OAuth token or API key. Most of these are created outside IT workflows, carry broad permissions, and are never revoked.
The Four Governance Failures That Create the Risk
When we work with IAM teams at Trainova, the same four failure modes appear repeatedly — regardless of organisation size, industry, or the sophistication of their existing tooling.
Failure 1: No inventory. More than 16% of organisations do not track the creation of AI-related identities at all (CSA, 2026). You cannot govern what you cannot see. Without a centralised, continuously updated inventory of every NHI across cloud, SaaS, and on-premise environments, everything else is guesswork.
Failure 2: No owner. Research from Rubrik Zero Labs found that 8% of enterprise identities have no owner in HR systems — the credential was created by someone who has since left the organisation, but the account, and all its access, remains active. In the context of AI agents, the problem is worse: agents are often spun up by a business unit, not IT, and ownership is never formally assigned.
Failure 3: No rotation. 47% of NHIs are more than one year old with no credential rotation. The operational discipline of rotating keys, tokens, and certificates — which every security framework mandates — simply does not happen at scale in most enterprises because the tooling and the team capability aren't there to support it.
Failure 4: No off boarding. Only 20% of organisations have formal processes for offboarding and revoking API keys (CSA). When a project ends, an integration is deprecated, or a vendor relationship closes, the credentials it used typically remain active indefinitely. These are the ghost identities that attackers find and exploit months or years later.
The IAM Capability Gap at the Heart of This
Here is where this becomes a learning and development problem, not just a technology problem.
Most IAM practitioners were trained in a human-centric identity model. They understand provisioning and deprovisioning users, running access certification campaigns, and configuring Okta or Microsoft Entra policies. These are valuable skills. They are also increasingly insufficient.
The IAM capability model that organisations need in 2026 extends well beyond human identity governance. Practitioners need to understand the full NHI lifecycle — from discovery and scoping, through rotation and anomaly detection, to revocation and audit. They need to be able to evaluate MCP server authentication configurations, identify overprivileged AI agent tokens, and build policy frameworks that apply IAM principles consistently across human and machine identities.
Less than a quarter of organisations have documented and formally adopted policies for creating or removing AI identities (CSA, 2026). That gap is not a technology failure — it is a capability failure. The tools exist. The frameworks exist. What is missing is practitioners who know how to apply them to this specific problem.
This is precisely the shift Trainova's IAM-focused programmes are designed to support: moving teams from human-centric identity management to a unified governance model that covers the full identity estate — human and non-human alike.
What Mature NHI Governance Actually Looks Like
For IAM leaders building towards a mature capability, the roadmap is clear — even if the execution is hard.
Start with discovery. Before any governance is possible, teams need a complete, continuously-updated inventory of every NHI across all environments: cloud (AWS IAM, Azure Entra, GCP), SaaS, CI/CD pipelines, and AI agent deployments. Modern NHI security platforms can make this agentless and automated. The prerequisite skill is knowing what to look for and how to scope the discovery properly.
Apply least privilege rigorously. Every NHI should be scoped to the minimum permissions it needs to function. This sounds obvious — it is also almost universally violated in practice. AI agents in particular tend to inherit broad permissions because restricting them early feels like a friction problem. It is actually a security imperative.
Automate rotation and revocation. Manual rotation processes fail at scale. The credential lifecycle — creation, scoping, rotation, and revocation — must be automated, with policy-based triggers rather than calendar reminders. This requires practitioners who can configure and validate these workflows, not just understand the concept.
Extend your audit framework. SOC 2, ISO 27001, PCI DSS, and NIST 800-53 all carry access governance requirements that apply to NHIs as much as human accounts. Auditors in 2026 are increasingly asking specific questions about machine identity governance. Organisations that cannot demonstrate lifecycle governance and least-privilege enforcement for NHIs are accumulating compliance exposure on top of security exposure.
The Perimeter Moved. Has Your Team?
The security perimeter is no longer a firewall at the edge of the network. It is the identity layer — and the identity layer now includes tens of thousands of non-human credentials that most organisations cannot name, locate, or govern.
That shift has happened faster than training programmes have kept pace. IAM practitioners who were excellent three years ago may find their skills misaligned with the problem in front of them. That is not a reflection of their capability — it is a reflection of how quickly the landscape has moved.
Trainova works with IAM teams to close that gap: assessing where capability breaks down in real work environments, and designing targeted learning interventions that build the specific skills needed to govern the full identity estate in 2026.
The perimeter has moved. The question is whether your team has moved with it.
Want to assess your team's IAM capability against the 2026 threat landscape? Start a conversation with Trainova →
About Trainova Learning Solutions
Trainova bridges the gap between learning and real-world execution through consulting-led capability building. Specialising in cybersecurity and IAM domains, we assess your business environment, identify where execution breaks down, and build learning programmes aligned to actual work — not generic content. Our Practitioner Network connects organisations with experienced professionals matched to their exact domain requirements.
© 2026 Trainova Learning Solutions. Blog post for www.trainovalearning.com