{"id":45283,"date":"2026-04-10T01:37:14","date_gmt":"2026-04-09T17:37:14","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/10\/governance-gaps-emerge-as-ai-agents-drive-76-increase-in-nhis-infosecurity-magazine\/"},"modified":"2026-04-10T01:37:14","modified_gmt":"2026-04-09T17:37:14","slug":"governance-gaps-emerge-as-ai-agents-drive-76-increase-in-nhis-infosecurity-magazine","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/10\/governance-gaps-emerge-as-ai-agents-drive-76-increase-in-nhis-infosecurity-magazine\/","title":{"rendered":"Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs &#8211; Infosecurity Magazine"},"content":{"rendered":"<p>The SANS Institute has warned that the race to incorporate AI into enterprise workflows threatens to outpace security efforts, after revealing widespread credential hygiene failings.<\/p>\n<p>The security training and research organization presented the findings as part of its <em>2026 SANS State of Identity Threats &amp; Defenses Survey<\/em>, which is based on interviews with over 500 security professionals&nbsp;globally.<\/p>\n<p>It revealed that three-quarters (76%) of organizations report growth in non-human identities (NHIs) such as service accounts, API keys, automation bots&nbsp;and workload identities.<\/p>\n<p>A growing number of these are tied to agentic AI: 74% of organizations are already using AI agents or automations that require credentials, SANS Institute said.<\/p>\n<p>This has led to the number of NHIs operating within organizations quietly doubling or tripling, the report claimed.<\/p>\n<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/infosec2025-agentic-ai-risks\/\" target=\"_blank\"><em>Read more on agentic AI risk: #Infosec2025: Concern Grows Over Agentic AI Security Risks<\/em><\/a><\/p>\n<p>However, agentic AI in particular represents a potentially new security risk few enterprises seem able to manage.<\/p>\n<p>Agents require credentials and access permissions to work autonomously, and are often granted privileged access to interact directly with critical infrastructure and data, SANS Institute said.<\/p>\n<p>However, unlike traditional NHIs&nbsp;which follow fixed logic, agentic AI interprets instructions and can take unpredictable actions &ndash; meaning they behave more like an over\u2011privileged insider, but operating at machine speed. There&rsquo;s also a risk of hallucination.<\/p>\n<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/forrester-agentic-ai-breach-2026\/\" target=\"_blank\">Forrester warned last year <\/a>that an agentic AI deployment will cause a publicly disclosed data breach by the end of 2026, and called for organizations to follow a &ldquo;minimum viable security&rdquo; approach to mitigate associated risks.<\/p>\n<h2>AI Governance Is Lacking<\/h2>\n<p>Most organizations appear to lack a coordinated security-first approach to AI deployment, according to the SANS Institute study.<\/p>\n<p>It found that 92% fail to rotate machine credentials on a 90-day cycle, fearing that this might break service accounts. Most (59%) rotate fewer than half of their NHI credentials quarterly, while some (15%) don&rsquo;t even know their rotation rate.<\/p>\n<p>A further 5% don&rsquo;t know if they&rsquo;re running agentic AI in their organization at all, the report noted.<\/p>\n<p>Another challenge highlighted in the report is that many organizations rely on manual access reviews, ticket\u2011based provisioning, and periodic rotation, which simply don&rsquo;t scale when environments have large volumes of NHIs operating at machine speed across DevOps, cloud and SaaS systems.<\/p>\n<p>Richard Greene, certified instructor at&nbsp;SANS&nbsp;Institute, warned that organizations are giving AI decision-making power faster than they&rsquo;re building governance frameworks to control it.<\/p>\n<p>&ldquo;We&rsquo;ve already seen what happens when non\u2011human identities scale without guardrails, and agentic AI is moving even faster,&rdquo; he added.<\/p>\n<p>&ldquo;The early signs of governance are encouraging &ndash; nearly four in ten organizations now use human in-the-loop approvals for AI agent actions &ndash; but the real challenge is staying ahead of these systems as they shift from pilots to core operations.&rdquo;<\/p>\n<p>The SANS Institute recommended adoption of secrets vaults, automated rotation and scoped least-privilege access as a bulwark against agentic AI risk, but emphasized the importance of scaling these efforts to match the continued growth of NHIs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The SANS Institute has warned that the race to incorpor [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45283","post","type-post","status-publish","format-standard","hentry","category--infosecurity-magazine"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45283"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45283\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}