AI/ML, Identity

Non-human identities pose critical new cybersecurity threat

A robotic hand interacts with a laptop, surrounded by digital icons representing networks and artificial intelligence, showcasing future technology and innovation

The Hacker News reports that the proliferation of non-human identities, including AI agents, service accounts, and automation scripts, is creating a critical new attack surface that organizations must urgently address, as these entities often operate outside traditional security controls.

According to ConductorOne's 2025 Future of Identity Security Report, 51% of respondents now view NHI security as equally important as human account security, yet these identities typically lack proper oversight, with over-permissioned standing access and static credentials. This oversight creates significant risk, as NHIs frequently hold broad, unreviewed access to sensitive systems and are rarely monitored, allowing compromised credentials to go undetected for months.

To mitigate this, experts recommend enforcing zero-trust principles for all identities, applying least-privilege access, implementing Just-in-Time credentialing, and automating secrets management. Solutions like KeeperPAM are cited as examples of unified platforms that can centralize control over both human and non-human privileged access.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds