The Non-Human Insider: AI Agents as an Identity Risk
AI agents are the newest, fastest-growing non-human identity. See the OWASP NHI Top 10, the lifecycle gap, and why agents rarely get offboarded.
AI agents are the newest, fastest-growing non-human identity. See the OWASP NHI Top 10, the lifecycle gap, and why agents rarely get offboarded.
An AI agent is not a new category of risk. It is the newest, fastest-growing member of a population most organizations already fail to govern: non-human identities, the service accounts, API keys, IAM roles, and bots that vastly outnumber human logins and get a fraction of the oversight. Treating an agent like an insider means applying the same identity discipline used for people, provisioning, review, monitoring, retirement, to a population that currently gets almost none of it.
Table of Contents
ToggleNon-human identity is not a new term invented for the AI moment. Security teams have used it for years to describe every credential that isn’t a person: a service account that lets one system talk to another, an API key embedded in an integration, a certificate that authenticates a workload. What has changed is the ratio and the trajectory.
CyberArk’s 2025 Identity Security Landscape report put the ratio of machine identities to human identities at 82 to 1. Palo Alto Networks’ 2026 edition of the same kind of research measured it at 109 to 1, up again in a single year. AI agents are not the whole of that population, but they are its fastest-growing slice, arriving with more autonomy and broader access than the service accounts and API integrations that came before them, and inheriting every governance gap that already existed for that older population.
A traditional service account is also static in a way an agent is not: once configured, it keeps doing the one thing it was set up to do until someone changes it. An AI agent can request new tool access mid-task, connect to a system nobody anticipated when it was first authorized, or generate its own working credentials for a sub-task, all without a human back in the provisioning workflow to approve any of it. That is what makes an agent a worse version of an already under-governed problem rather than simply a bigger one: the population is growing, and each new member can also expand its own footprint after the fact.
Most AI security writing reaches for OWASP’s LLM or Agentic Top 10 lists, and both are genuinely useful. What gets skipped almost every time is the list built specifically for this exact problem: the OWASP Non-Human Identities Top 10, published in 2025 by practitioners who were already fighting this battle over service accounts and API keys years before agents entered the picture.
Four of its ten categories map directly onto how an AI agent actually fails:
A composite example, built from patterns across the risks above rather than any single case: a team spins up an AI agent to help triage support tickets, authenticates it with an existing service account because requesting a new one takes a week, and pastes the account’s API key into the agent’s configuration file, which a teammate later copies into a second, unrelated agent to save time. Eight months later, the original support project ends. The service account is never revisited, because nobody owns that decision, and two AI agents nobody is actively managing are still running on a credential with far broader access than either task ever needed. Every failure in that chain traces to a named OWASP NHI risk, and none of them required a sophisticated attacker to matter.
This is not a coincidence of naming. An AI agent is architecturally a non-human identity with a goal attached, which means the risks that have plagued service accounts for a decade apply to it by default, before any AI-specific risk from an AI risk management framework is even added on top.
Discover how Threatcop protects your workforce from modern cyber threats.
Every organization already has a process for the human identity lifecycle: HR systems trigger provisioning on day one, access reviews happen on a schedule, and an exit date triggers deprovisioning automatically, no matter who forgets. The equivalent process for machine identities is, in most organizations, informal at best.
The gap shows up at every stage. A human identity is created by an HR workflow; a non-human identity is usually created on demand by a developer or a script, with no equivalent trigger to track it. Human access gets quarterly certification in most compliance programs; machine credentials rarely receive a formal review at all, so permissions accumulate silently. And a human identity has a natural termination point, the day someone leaves. A machine credential has none. When the project it supported ends, the credential usually just keeps working, becoming what practitioners in this space call a zombie credential: dead in purpose, alive in access.
An AI agent inherits this exact gap, with one difference that makes it worse. A dormant service account is inert until something reactivates it. A dormant AI agent with standing access and a scheduled trigger can still be acting, on a stale mandate, for a project that no longer exists, without anyone noticing until an audit or an incident forces the question, the same blind spot that measuring human risk continuously rather than annually already exists to catch on the people side.
The framing is not a metaphor to gesture at. It implies specific, checkable practices, the same ones insider threat programs already apply to people with legitimate, trusted access:
None of this is exotic. It is the same information security risk management discipline already applied to human accounts under human risk management programs, extended to a population that has been quietly growing past human headcount for years and only now, because of AI, is getting any attention at all. The cost of leaving this ungoverned only grows the longer the gap stays open.
The next serious breach in an organization with AI agents is unlikely to start with someone breaking in. It is more likely to start with a non-human identity that was let in on purpose, granted broad access at setup, never reviewed again, and still trusted by every system it touches. Fixing that is not a new discipline. It is the people security management discipline security teams already know, applied to a population that has been overdue for it since long before AI agents made the gap impossible to ignore. The organizations that get ahead of this will be the ones that stopped treating machine credentials as a provisioning afterthought and started treating every one of them, agent included, as an identity with an owner, a purpose, and an expiration date.
A non-human identity is any credential that isn’t tied to a person: service accounts, API keys, certificates, IAM roles, bots, and increasingly, AI agents. They authenticate and act the same way a human account does, but they rarely get the same provisioning, review, and offboarding discipline that a human account takes for granted.
Recent industry research puts the ratio of machine identities to human identities well over 100 to 1 in some measurements, up from roughly 82 to 1 the year before. AI agents are the fastest-growing slice of that population, not the majority of it yet, but the trend is accelerating.
A zombie credential is access that has outlived its purpose: a service account, API key, or AI agent whose project ended, whose owner left, or whose task was completed, but whose access was never revoked. It sits active and usable with nobody accountable for it, which is exactly the condition attackers look for.
No, and conflating them is a common gap. The Agentic Top 10 addresses risks in how an agent behaves and makes decisions. The Non-Human Identities Top 10 addresses risks in how the agent’s underlying credential is provisioned, scoped, and retired. An AI agent needs both frameworks applied, not just one.
Because most organizations have no equivalent to an HR-triggered exit process for machine identities. A human’s access ends automatically on their last day. An agent’s access has no natural end point unless someone deliberately builds one in, which is why so many agents keep working long after the task they were created for is finished.
Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.
Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.
Zero cyber insurance losses trace to AI-native attacks so far. 85% trace to social engineering instead. See what the...
The grammar heuristic is dead. See the real tells of AI-written phishing: leftover prompts, hidden CSS, and domain reputation...
Loading an open-source AI model can silently run code nobody asked for. See the real pickle exploits security researchers...
Table of Contents
×