AI/ML, Identity

Firms lack confidence securing non-human identities

(Adobe Stock)

A new Cloud Security Alliance survey highlights a critical lack of confidence among IT and security professionals in securing non-human identities as AI adoption accelerates, reports Security Brief Asia.

The report, "The State of Non-Human Identity and AI Security," found that 79% of respondents have low or moderate confidence in preventing attacks via these identities, while 78% lack documented policies for managing AI identities. Governance is a primary concern, with 51% citing unclear ownership and over-permissioned access as major pain points. The rapid proliferation of AI agents and automated workflows is straining legacy identity and access management systems, with 92% not confident these tools can manage associated risks. Manual processes exacerbate the problem; only 14% fully automate the creation and removal of AI identities. Furthermore, response times are slow, with 24% of organizations taking over a day to rotate a potentially exposed credential.

Hillary Baron of CSA stressed that "establishing strong identity foundations now is critical to reducing risk," as identity becomes a high-velocity system requiring automated lifecycle management and clear policy ownership.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds