Skip to navigation Skip to main content Skip to footer

Non-Human Identities: A Dr. Jekyll and Mr. Hyde story for enterprise security

By Derek Gordon

18 August 2026

For many organisations, identity remains one of the defining factors in cyber risk. While security teams continue to prepare for increasingly sophisticated threats, they recognise that the fundamentals still matter. Credentials, privileges, and excessive access rights remain an attractive entry point for attackers. Therefore, maintaining clear visibility of who has access to organisational systems, applications, and data, and whether that access remains appropriate, a continuing priority.

Yet the risk does not always sit with traditional visible users. Increasingly, it sits with accounts that remain unnoticed, unmanaged, and without accountable ownership.

These accounts do not sit at desks. They do not appear in organisational charts. They operate silently in the background, executing tasks, connecting systems, and enabling the automated processes upon which the modern enterprise now depends. But what happens when such identities significantly outnumber human users and continue to proliferate across the enterprise? And how can security teams be confident they retain visibility and control over identities that operate largely beyond day-to-day human oversight?

Perhaps this is how Stevenson might have begun a modern digital tale. Not with a respectable doctor and his hidden alter ego, but with an enterprise unaware of the true identities operating beyond its intended field of vision.

Ever present, largely trusted, yet seldom understood, non-human identities have a Jekyll and Hyde quality. They power the modern enterprise, but when left unmanaged, they can quickly become one of its biggest security liabilities.

 

The shift from machine accounts to non-human identities

The term non-human identity (NHI) is increasingly being used to describe the growing range of machine-based credentials and entities operating across modern digital environments. This includes service accounts, workload identities, API keys, tokens, system accounts, administrative accounts, cloud-native identities, and increasingly, AI agents.

While industry purists may debate the distinction between an identity and an account, the semantics are becoming less important than the underlying security challenge. Security leaders are focused on a more pressing issue: how to discover, govern, secure, and monitor the vast volume of identity-related assets that exist outside the traditional workforce identity model.

These entities have become a form of “identity dark matter”. They are critical to the operation of modern enterprises, yet are often poorly understood, inconsistently governed, and insufficiently monitored.

 

Why the sudden focus?

Non-human identities are not new. Service accounts, scripts, integrations and machine credentials have existed for decades. What has changed is their scale, influence and autonomy.

As organisations accelerate cloud adoption, automation, DevOps practices and AI usage, the number of non-human identities is growing at an unprecedented rate, frequently outnumbering human identities by a significant margin.

Much of this renewed focus is directly related to the rapid adoption of AI. AI has fuelled an explosion of non-human accounts and credentials, with more digital platforms, orchestration processes, integrations and workloads being executed by autonomous agents.

Behind every AI agent, automated workflow, integration and orchestration process is a digital identity operating inside the organisation. Unlike human users, these identities operate continuously and can accumulate privileges at scale, often without the same levels of visibility, governance or oversight.

AI is transforming how work gets done, but this is not just about smarter models or more capable copilots. It is about ensuring these new digital actors operate within defined governance, security and accountability frameworks.

This places identity at the centre of enterprise AI adoption. Identity security becomes the critical foundation and control plane through which trust is established, policies are enforced and access is governed across both human and non-human actors.

What was once viewed as a technical challenge, has evolved into a critical security, governance and operational concern that organisations can no longer afford to ignore.

 

The new all-powerful digital worker

The most significant aspect of agentic AI is not simply its ability to learn. It is its ability to act.

When these two capabilities are combined, AI agents become far more than automation tools. They become powerful digital workers capable of executing tasks, making decisions and interacting with enterprise systems with increasing levels of autonomy.

The opportunity is enormous, yet so is the risk. The challenge for organisations is ensuring these agents operate as intended and that the access granted to them remains proportional to the tasks they perform. Much like Role-Based Access Control (RBAC) aligns human access rights with business responsibilities, organisations must establish equivalent controls for AI agents, ensuring permissions remain tightly aligned to purpose and do not evolve into unchecked privilege.

AI agents are fundamentally different from traditional service accounts. They are not static identities executing a single predefined function. They can reason, initiate actions, interact with multiple systems, access sensitive information, invoke APIs, trigger workflows and make decisions at machine speed and scale.

Their activities may be initiated directly by a human user, delegated by another system, or triggered by a chain of collaborating agents working together to achieve a desired outcome. In effect, these agents are becoming a new category of digital workforce.

 

The Jekyll and Hyde scenario

This creates a genuine Jekyll and Hyde scenario. The same capabilities that enable AI agents to deliver significant benefits, driving productivity, improving efficiency and unlocking new opportunities for innovation, can also introduce significant security, compliance and governance risks when they operate outside their intended purpose.

An AI agent that supports a business process can accelerate productivity. The same agent, if over-privileged, poorly monitored or misconfigured, could access sensitive systems, execute unintended actions, expose data, or become a route for misuse.

The challenge for organisations is ensuring that these agents operate as intended and that the access granted to them remains proportional to the tasks they perform. Permissions must remain tightly aligned to intended purpose and do not evolve into unchecked privilege.

 

Trust starts with identity

The future will not be defined by whether organisations deploy AI agents. Organisations inevitably will. However the defining (and crucial) question will be whether those organisations can trust them.

Building that trust requires the same principles that have underpinned identity security for decades: visibility, ownership, least privilege, governance, accountability and monitoring. The difference is that these controls must now be applied to an entirely new generation of digital workers that operate autonomously, at scale, and increasingly at the heart of the modern enterprise.

There is significant promise in modern NHI management. Done correctly, it has the potential to transform identity security from a compliance-driven control function into a genuine business enabler that supports rapid AI adoption and brings together greater insight across the wider cyber ecosystem.

By establishing visibility, governance and trust across both human and non-human actors, organisations can adopt AI with greater confidence, accelerate transformation initiatives and reduce risk simultaneously.

The bottom line is simple: double down on visibility and control.

You cannot govern what you cannot see. Understanding the scale, privilege, ownership and behaviour of non-human identities is the foundation of any pragmatic strategy. Visibility enables governance. Governance enables trust. Trust enables adoption.

Derek Gordon

Derek Gordon

Global VP Identity & Access Management, NCC Group

Derek is a seasoned technology executive with over 26 years of experience in information security, consulting, product management, and professional services. As a global digital identity leader, he oversees the strategy and execution of Identity and Access Management (IAM) and Privileged Access Management (PAM) services, providing thought leadership and insights across enterprise delivery projects. 

Throughout his career, Derek has held leadership roles at prestigious organizations, including titles like EMEA IAM Leader at IBM and the UK IAM Leader at PwC. He also founded a boutique IAM service provider, Praxism. A highly respected voice in the digital identity field, Derek actively invests his time in supporting a wide range of industry bodies and organizations.

Build trust in your digital workforce

Gain visibility into human and non-human identities, understand where risk exists, and establish the controls needed to support secure AI adoption.

Explore our Digital Identity solutions   Contact us