There is a governance discipline that most mid-market companies apply reasonably well to human identities. When someone joins the company, IT creates an account. When they leave, the account is disabled. Access is granted based on role. Privileged access is reviewed periodically.
This discipline — imperfect as it often is in practice — represents decades of learned behavior about what happens when human identities are not managed carefully.
The same discipline does not yet exist for non-human identities. And AI adoption is making that gap significantly larger, significantly faster.
What a non-human identity is
A non-human identity (NHI) is any credential that allows a system, application, or automated process to authenticate and access resources. The API key your CRM uses to write to your ERP. The OAuth token your BI tool uses to query your data warehouse. The service account your backup software uses to access file shares.
These credentials have been accumulating in your environment for years. Every integration, every automation, every third-party tool that connects to your systems creates at least one. A mid-market company with a reasonably modern technology stack typically has five to ten times as many non-human identities as human ones.
Most of them were created by someone who may no longer be at the company, for a purpose that may no longer exist, with permissions that were set to "whatever it takes to make this work" and never revisited.
What AI tools are adding to this problem
AI tools — copilots, agents, workflow automation platforms — are being adopted faster than any previous category of enterprise software. They are also, almost universally, identity-hungry.
To do anything useful, an AI agent needs access: to your email, your calendar, your CRM, your documents, your communication platforms. That access is granted through OAuth tokens and API credentials. Those credentials are non-human identities.
The difference between an AI agent and a traditional integration is scope. A traditional integration does one thing: the CRM writes to the ERP. An AI agent may have read access to dozens of systems simultaneously, because it needs context from all of them to be useful. The blast radius of a compromised AI agent credential is correspondingly larger.
There is also a governance gap specific to AI adoption. When a department head connects an AI tool to the company's Microsoft 365 tenant, they are potentially granting that tool access to every document, email, and calendar in the organization — depending on how the OAuth consent was configured. They did not intend to do that. They clicked through the authorization screen to get the tool working. The access persists indefinitely unless someone explicitly revokes it.
The inventory problem
The first step in addressing NHI risk is knowing what you have. This is harder than it sounds.
Non-human identities are scattered across every system in your environment. Some are in your identity provider. Some are in individual applications. Some are in code repositories as hardcoded credentials — a practice that should not exist but does, in almost every company I have worked with.
A proper NHI inventory captures: what the credential is, what system it authenticates to, what permissions it has, what it is used for, who owns it, when it was last used, and when it expires — if it expires at all. Most companies have none of this documented.
The window you have right now
Most mid-market companies are in the early stages of AI adoption. The tools are being evaluated, piloted, and selectively deployed. The NHI footprint is growing, but it has not yet reached the scale where remediation becomes a multi-year project.
The companies that build NHI governance into their AI adoption process now — that treat credential management as a prerequisite for deployment rather than a cleanup task for later — will be in a fundamentally different security posture in three years than the ones that do not.
Practically, this means three things. Require an access review before any AI tool goes into production: what systems will it connect to, what permissions does it need, who owns the credential, and what is the process for revoking it when the tool is retired. Audit your existing OAuth consents — in Microsoft 365 this is visible in the Azure portal under Enterprise Applications. Apply least-privilege to non-human identities the same way you apply it to human ones.
None of this requires a new security platform. It requires applying the same discipline to machine identities that you apply — or aspire to apply — to human ones.
If you're in the early stages of AI adoption and want to think through the governance implications before they become a problem, a discovery call with CTO360 is a practical starting point. This is exactly the kind of work fractional CTO engagement is built for.
Written by
David Rosenberg
Fractional CTO with 35 years of enterprise technology leadership across manufacturing, distribution, and professional services.
Schedule a Discovery Call