verifiedagents.ai
All posts

5 min readAI Agents · Cybersecurity

Are AI Agents the Same as Non-Human Identities?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: Are AI Agents the Same as Non-Human Identities?

TL;DR: By definition, yes: an AI agent uses non-human credentials, so it's a non-human identity (NHI). By control model, no: NHIs are static and scoped once at provisioning, while agents adapt their access at runtime. Silverfort, Strata, and the NHI Management Group all warn that running agents through legacy NHI controls creates risk instead of containing it.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai as the decision-maker's version: the definitions, the four mechanical differences, the missing controls, and what it means for your stack.

What is a non-human identity (NHI)?

An NHI is any credential that lets software, not a person, reach systems or data: service accounts, API keys, workload credentials, OAuth client secrets. Microsoft Security describes them as the credentials that authenticate one piece of software to another.

The category has exploded. Enterprises now manage about 144 machine identities per human identity, and the ratio is growing 44 percent a year, per 2026 Microsoft Security and CyberArk research. Agents accelerate it further by spawning sub-agents and short-lived credentials at runtime.

So are AI agents NHIs or not?

Technically yes. An agent isn't a person and it authenticates with non-human credentials, so it sits in the category. Most identity vendors reinforced the grouping by adding agent governance to their NHI feature sets in 2025 and 2026.

Practically no, and the counter-position is now on the record. Silverfort published the clearest version in May 2026: grouping AI agents under the NHI umbrella isn't just inaccurate, it can create security risk. Strata's identity playbook makes the same case. A static NHI policy fails the moment an agent makes a tool call you never authorized at provisioning time, because provisioning time is the only moment a legacy NHI model ever looks.

What are the four mechanical differences?

Dimension

Classic NHI

AI agent

Provisioning

Scoped once, at creation

Scope has to adjust per task, at runtime

Behavior

Fixed operations on a schedule

Reasons and picks actions on the fly

Trust boundary

Lives inside one trust zone

Crosses trust zones in normal operation

Audit trail

A flat API log

A reasoning trace that must be reconstructable

A service account that runs the same nightly job for three years is a known quantity. An agent that decided this morning to call a new tool isn't. The controls have to match the second thing. Why legacy stacks can't see that difference is the subject of the AI agent identity problem.

What controls do agents need that NHI platforms don't provide?

Map the missing work to the five ATF elements, published by CSA in February 2026.

  1. Identity Management, the dynamic half.

    Per-task scope adjustment, not a single grant at creation. NHI platforms do the static half well.

  2. Behavioral Monitoring.

    A baseline of normal per agent, with anomaly alerts on tool-call sequences. The method is in

    how to monitor an AI agent's behavior

    .

  3. Data Governance at the action level.

    Inspecting what goes into and out of each action. Static NHI tools don't read prompts.

  4. Segmentation.

    Hard limits on how far one wrong action can spread.

  5. Incident Response per agent.

    Revocation that cuts in-flight tasks fast, with an audit trail good enough to reconstruct what happened.

If your NHI platform doesn't do these, you have an NHI platform. That's fine. It just doesn't extend to agents on its own.

What does this mean for your identity stack?

Put agents adjacent to your NHI platform, not inside it. Three patterns showed up across 2026. Some teams run a dedicated agent identity provider that issues per-task credentials. Some use an NHI platform with a true agent module. Most enterprises settled into a hybrid by Q3 2026, with a policy engine in the middle.

The real decision isn't NHI versus agent identity. It's whether you accept that agents need a dynamic enforcement layer that static tooling doesn't provide. Vendors will tell you the module covers it. Ask them the four questions in the table above and watch which ones get a slide instead of an answer.

Frequently asked questions

Can I use my existing NHI platform for AI agents?

For provisioning and credential storage, yes. For behavioral baselining and per-action authorization, you'll need agent-specific tooling on top. That hybrid is where most enterprises ended up.

Will a SOC 2 auditor accept treating agents as NHIs?

Increasingly no. SOC 2 CC6 reviews now call out shared service-account identity across agents, which breaks attribution, and missing deprovisioning workflows, which create zombie agents.

What's the 144-to-1 ratio?

About 144 machine identities per human identity in the enterprise, growing 44 percent a year. Agents push it higher by creating ephemeral credentials as they work.

How does the ATF relate to NHI frameworks?

NHI tools answer the identity question and part of the segmentation question. The ATF's five elements cover the rest: behavior, data flow, segmentation boundaries, and response. They complement each other rather than compete.

Key takeaways

  • Agents are NHIs by definition and not by control model. Both halves are true.

  • The split is static versus dynamic: scoped once at creation versus adjusting at runtime.

  • Silverfort and Strata both warn that the legacy grouping creates risk.

  • Run agents adjacent to the NHI platform with a dynamic enforcement layer.

  • Auditors are already distinguishing the two. Your stack should too.

Find out which half your stack covers

The free ATF assessment shows where your agent controls stop and your NHI controls were never meant to continue. Ten minutes.

Your service accounts earned their reputation by doing the same thing every night. Your agents haven't, and won't.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.