Zero Trust Modernisation for Non-Human Identities & AI Agents
Originally reported viaNIST SP 800-207 Zero Trust Architecture · Gartner Market Guide for Non-Human Identity Security 2025 · CyberArk Identity Security Threat Landscape 2026CyberArk's 2026 Identity Security Threat Landscape report finds that non-human identities — service accounts, API keys, OAuth tokens, CI/CD pipeline credentials, and AI agent service principals — now outnumber human identities 45:1 in the typical enterprise environment. Yet Gartner's 2025 survey found that 82% of Zero Trust programmes focus exclusively on human identity controls, leaving the machine identity estate almost entirely unprotected.
Why non-human identities are the new frontier
Non-human identities are attractive targets for three reasons: they typically hold persistent access (no expiry, no MFA requirement), they are rarely reviewed or rotated, and they operate at machine speed — an attacker who compromises a CI/CD service account can enumerate the entire cloud environment in seconds. The 2025 CircleCI breach, the Codecov supply chain attack, and multiple Okta compromises all involved non-human credential abuse as the primary vector.
AI agents as identity management challenge
AI agents introduce a new class of non-human identity: entities that hold OAuth grants, make API calls, read and write files, and interact with SaaS platforms — but whose credential lifecycle is not managed by any existing PAM or secrets management process. An AI agent granted access to Salesforce, Slack, and a corporate GitHub repository represents a significant blast radius if compromised or misbehaving. The absence of session recording, access review, or rotation policies for agent identities is a critical governance gap.
- Conduct an NHI inventory: export all service accounts, API keys, OAuth grants, and CI/CD credentials across cloud, SaaS, and on-premises environments.
- Classify NHIs by access scope and sensitivity. Identify any holding administrative or privileged access without rotation schedules.
- Implement secrets rotation (automated, policy-driven) for all CI/CD pipeline credentials and cloud service account keys.
- Apply Zero Trust principles to AI agent credentials: least-privilege OAuth scopes, time-bound grants, and session logging.
- Integrate NHI discovery into your quarterly access review cycle — NHIs accumulate faster than any manual review process can track.
- Disable or delete NHIs belonging to decommissioned applications immediately upon service retirement.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.