Identity

Non-human identity is the new perimeter

← All InsightsBy Dr. Derek A. Smith5 min read

The network perimeter dissolved years ago, and identity quietly became the thing you defend. The uncomfortable update: the identities that now matter most aren’t human. They’re the service accounts, tokens, keys, pipelines, and AI agents running your business — and they outnumber your people by more than 80 to 1.

Non-human identities (NHIs) are everything that authenticates without a person behind it in the moment: service accounts, API keys, OAuth tokens, certificates, CI/CD pipelines, bots, and increasingly, autonomous AI agents. They do essential work. They are also, in most organizations, the softest target in the building.

Why NHIs are the weak point

The identity controls we trust for people mostly don’t apply to machines. NHIs are routinely over-privileged, secured with long-lived secrets, exempt from MFA, missing an owner, rarely rotated, and invisible to IAM tooling designed around human logins. That is why so many modern breaches don’t start with malware — they start with a leaked token or a secret committed to code. Attackers don’t break in; they authenticate.

You did the work to secure how humans log in. The machines never got the same treatment — and there are eighty of them for every person.

Extend Zero Trust to the machines

The principles that reshaped human access — Zero Trust and privileged access management — have to reach non-human identities now, not eventually:

  • Discover and inventory every non-human identity and the secrets it holds.
  • Assign ownership so each NHI has an accountable human.
  • Enforce least privilege — scope tightly, remove standing access.
  • Use short-lived, just-in-time credentials instead of long-lived secrets.
  • Manage and rotate secrets through a vault, never in code or config.
  • Monitor behavior for anomalies the way you watch privileged users.

AI agents make this urgent rather than aspirational: they multiply non-human identities and act autonomously, so an ungoverned NHI estate is now an ungoverned AI estate. Treat machine identities as first-class citizens of your identity program — because your attackers already do.

Dr. Derek A. Smith is founder of DAS Advisory Group and author of The Defensible AI Program. He advises federal agencies and enterprises on governing and securing AI.

Want this applied to your organization?

A 30-minute conversation on where you are and what governing your AI actually takes.

Book a Consultation

Get new briefs in your inbox

Practical AI governance and security notes, sent when there's something worth reading. No spam.