Blog
Jul 06, 2026 | 10 min

Why is NHI sprawl such a big problem?

Key takeaway

  • Non-human identity (NHI) sprawl expands attack surfaces by creating thousands of unmanaged identities, credentials, and permissions that security teams often cannot fully inventory.
  • Unused NHIs frequently retain access long after workloads are retired, creating opportunities for credential abuse and unauthorized access.
  • Gartner reports only 13% of organizations believe they have the right AI agent governance in place, highlighting growing visibility and control challenges.
  • Effective NHI security requires organizations to discover identities, understand permissions and risk, and enforce lifecycle and access controls continuously.

Quick facts

How NHI sprawl expands the attack surface

Risk What it means How to address it
Unused identities Retired workloads leave active credentials behind Continuous discovery and lifecycle governance
Excessive permissions Machine identities accumulate access over time Permission reviews and entitlement mapping
Shadow AI agents Agents operate outside formal oversight Inventory and govern AI identities
Secret sprawl Credentials exist in multiple locations Centralized visibility and rotation policies
Unknown blast radius Teams cannot determine impact of compromise Relationship mapping and risk analysis

Why is non-human identity sprawl growing faster than security teams can manage?

Imagine a cloud engineering team at a burgeoning organization. To streamline their workflows, someone creates a GitHub Actions service account to automate deployments into a development environment. Initially, it has only a handful of permissions.

As the organization grows, engineers connect additional workflows. The account gains access to AWS resources, Kubernetes clusters, secrets managers, CI/CD pipelines, and cloud storage. Later, an AI-powered operations assistant begins using the same credentials to automate cloud management tasks.

No one intended the account to become critical infrastructure. It simply accumulated access over time.

Two years later, the original team has moved on. The service account remains active, but nobody can clearly explain its permissions, dependencies, or reach. Removing it feels risky because so many workflows may rely on it.

This is how NHI sprawl develops. Research shows that AI tools and agentic automation caused a 44% year-over-year increase in NHIs.

NHIs include service accounts, API keys, OAuth applications, workload identities, secrets, certificates, machine identities, and AI agents. Unlike human users, they are often created automatically, granted access incrementally, and rarely removed when they are no longer needed.

Cloud adoption, automation, SaaS integration, and AI have accelerated this growth. Gartner estimates that by 2028, the average Fortune 500 enterprise will have more than 150,000 AI agents in use, yet only 13% of organizations believe they have the right AI agent governance in place.

The result is an identity ecosystem that expands faster than most security teams can discover, govern, and secure.

How non-human identity sprawl expands your attack surface

Every new NHI introduces another potential access path for bad actors. As identities accumulate permissions over time, the attack surface grows with them. Palo Alto estimates that 99% of cloud identities have excessive permissions, many of which are rarely used but remain available to attackers.

The 2024 Salesloft - Drift incident demonstrated how attackers can exploit trusted machine-to-machine relationships. By compromising OAuth-connected applications, they gained access through existing permissions and integrations, illustrating how unmanaged access and third-party trust can create significant security risk.

Every NHI exists to perform work, which requires permissions. As integrations, workflows, and automations are added, those permissions often expand while oversight remains limited.

Returning to our GitHub Actions example, the risk is not the service account itself. The risk is what it became.

This pattern is common. The OWASP Non-Human Identities Top 10 identifies improper offboarding, excessive permissions, secrets management, and unmanaged credentials among the most common NHI security risks.

When attackers compromise a machine identity, they inherit its permissions. In this case, a single service account could provide a path to source code, cloud resources, production workloads, and sensitive data. What began as a narrow deployment account now carries a much larger blast radius.

The challenge becomes even greater when organizations cannot answer basic questions:

  • Which NHIs exist?
  • Which identities are still active?
  • Which identities are unused?
  • What permissions do they have?
  • What systems can they reach?

Without those answers, enforcing least privilege becomes difficult, and hidden identity risk continues to grow.

What are the risks of ignoring non-human identity sprawl?

2026 CSA analysis of token sprawl found that more than 16% of organizations do not track the creation of AI-related identities at all. NHI sprawl creates operational, governance, compliance, and security challenges that often persist long after an identity's original purpose has ended. OWASP identifies improper offboarding as one of the most common NHI security failures because service accounts, secrets, and credentials frequently retain access after applications, projects, or workloads are retired.

As non-human identities proliferate, lifecycle governance becomes increasingly difficult. A 2026 CSA analysis of token sprawl found that more than 16% of organizations do not track the creation of AI-related identities, leaving many identities unmanaged from the moment they are provisioned. Those gaps often persist long after an identity's original purpose has ended. The OWASP Non-Human Identity Top 10 identifies improper offboarding as a leading NHI security failure because service accounts, secrets, and credentials frequently retain unnecessary access after the applications, projects, or workloads they support have been retired.

The impact extends beyond security incidents. Organizations often face:

  • Larger audit scopes
  • Poor access accountability
  • Increased cloud complexity
  • Slower incident response
  • Difficulty enforcing least privilege
  • Reduced confidence in AI adoption

Agentic AI raises the bar for governance because organizations must manage not only AI models, but also the identities, permissions, and data those agents rely on. Reflecting that complexity, a Confluent survey found that the top barriers to mature AI oversight are limited organizational readiness (69%), non-deterministic model outputs (68%), and governance, risk, and compliance (GRC) challenges (65%).

Our deployment account illustrates the problem. What began as a simple automation gradually became intertwined with cloud operations, AI-driven workflows, and connected systems. As new applications and AI agents relied on its credentials, the identity became increasingly difficult to understand, govern, or safely retire.

This illustrates why AI governance and NHI governance are becoming inseparable. The challenge is not simply knowing an AI agent exists. It is understanding the identities, permissions, and credentials that enable it to act.

Best practices for reducing non-human identity sprawl 

Effective NHI security programs follow three steps: Discover, Understand, and Enforce.

Discover

Discovery often reveals thousands of unknown identities. In our example, a simple deployment account had become connected to cloud infrastructure, secrets managers, and AI-driven workflows. 

Understand

Security teams must understand an identity's permissions, relationships, ownership, and blast radius. The Cloud Security Alliance estimates that 40% to 47% of cloud NHIs lack a defined human owner. 

For the GitHub Actions account, that means understanding what it can access, what depends on it, and the impact of compromise.

Enforce

Once risk is understood, organizations can begin reducing it. For our example GitHub Actions account, that may mean removing unnecessary permissions, retiring unused credentials, and assigning AI workflows dedicated identities.

Common controls include:

  • Least privilege
  • Automated remediation
  • Credential rotation
  • Lifecycle governance
  • Access reviews
  • Decommissioning workflows

The goal is continuous governance, not periodic cleanup. Effective programs continuously discover identities, understand risk, and enforce controls as machine identities evolve.

How Token Security approaches NHI sprawl

Successfully managing NHI sprawl requires intent-based security that continuously discovers non-human identities, analyzes permissions and trust relationships, and enforces governance throughout the identity lifecycle.

The challenge

Organizations struggle to identify machine identities, understand their permissions, and prioritize risk. In a survey, 92% of IT professionals state that traditional, legacy Identity and Access Management (IAM) systems cannot effectively manage AI and NHI security risks.Traditional IAM and PAM programs were built primarily for human users.

The approach

Token Security applies an intent-based security approach to help organizations discover, understand, and govern non-human identities.

Solving the problem would begin with identifying the GitHub Actions account and the identities connected to it across cloud, SaaS, AI, and development environments. 

It would then map the account's permissions and access relationships, analyze its potential blast radius, establish behavioral baselines to detect unusual activity, and help security teams remediate unnecessary risk. 

Lifecycle governance helps ensure identities remain governed from creation through retirement. This enables organizations to continuously discover identities, understand risk, and enforce security controls at scale. Yet operational maturity remains low. According to Palo Alto's Unit 42, only 37% of organizations can revoke an AI agent's credentials, and just 30% maintain immutable audit logs of agent activity. 

The outcome

Security teams gain visibility into previously unknown machine identities, reduce excessive permissions, improve accountability, and strengthen governance for AI agents and other NHIs.

Reducing NHI sprawl risk in the real world

Organizations applying these practices are gaining the visibility needed to reduce risk and govern NHIs at scale.

Bringing visibility to machine identity risk

As Lemonade expanded its cloud and engineering environments, gaining actionable visibility into machine identity risk became increasingly important.

"Token Security has enhanced our security by providing us accurate and relevant visibility into machine identity risks, something I have yet to see from other vendors. It's the first service I've seen that delivers on the widely made claim of finding machine identity risk. It provides us with the right amount of detail to mitigate issues without burdening us with tens of rows of useless alerts."

— Jonathan Jaffe, CISO at Lemonade

Visibility delivers the greatest value when it helps security teams prioritize remediation based on identity risk. 

Governing AI agents at scale

As AI adoption accelerated, HiBob needed visibility into custom GPTs and AI agents operating throughout the organization.

"Token Security gives us visibility we simply didn't have before. We can now automatically identify and control custom GPT agents running in our environment and ensure the required security level. Knowing that no AI agent is operating beyond our oversight means we can confidently accelerate our AI adoption."

— Tamir Ronen, Global CISO at HiBob

AI governance increasingly depends on effective NHI governance. 

Why the NHI gap keeps widening

The GitHub Actions account in our example did not become risky overnight. What began as a simple deployment identity gradually accumulated access through new integrations, automations, and AI-driven workflows.

That is how most NHI sprawl develops. Access expands faster than governance can keep pace.

As AI adoption accelerates, every new automation introduces another identity that must be governed.

Organizations that succeed will treat NHIs as first-class identities, continuously discovering them, understanding their permissions, and enforcing controls throughout their lifecycle.

Identity is becoming the control plane for AI agents, automation, and cloud infrastructure, and the foundation for governing them at scale.

FAQs

What is NHI sprawl?

NHI sprawl occurs when an organization accumulates large numbers of NHIs, such as service accounts, API keys, OAuth applications, workload identities, and AI agents, without adequate visibility or governance. As these identities grow, tracking ownership, permissions, and risk becomes increasingly difficult.

Why are unused non-human identities dangerous?

Unused non-human identities often retain access long after the application or workload they supported has been retired. Because they are rarely monitored, these forgotten identities can become attractive targets for attackers seeking unauthorized access.

How is NHI sprawl different from credential sprawl?

Credential sprawl refers to the uncontrolled growth of secrets, API keys, passwords, and tokens. NHI sprawl is broader, encompassing the identities themselves, their permissions, relationships, ownership, and lifecycle management.

Why do AI agents increase NHI sprawl?

AI agents require identities and permissions to access systems and perform tasks. As organizations deploy more agents, they create additional service accounts, OAuth grants, API tokens, and workload identities, increasing the number of identities that must be governed.

Discover other articles

Be the first to learn about Machine-First identity security