Back to Blog

Your Agents Are Identities Now — And Most Enterprises Are Governing Human Identities While The Non-Human Ones Multiply Unwatched.

The security research of September 2026 is converging on a shift in where enterprise risk lives: from managing human identity and access to governing autonomous non-human entities. Agents act across APIs and systems on their own credentials, at machine speed and scale, and more than 40% of enterprise users have already installed AI-powered browser extensions that act on their behalf. The identity perimeter has moved, and the enterprises still securing only the human side are watching the wrong door.

The security research of September 2026 has converged on a shift that reframes enterprise risk. For decades, identity and access management meant governing human identities — who a person is, what they may access, what they may do. The agentic shift has introduced a new class of actor into the enterprise: autonomous non-human entities that act across APIs and systems on their own credentials, make decisions, and take actions at machine speed and scale. The research is consistent that enterprise risk is moving from managing human identity to governing these non-human ones, and that most enterprises have not made the shift.

The scale of the exposure is already concrete. More than 40% of enterprise users have installed AI-powered browser extensions that act on their behalf, and a meaningful share of those extensions alter their own permissions over time. Agents interacting with enterprise systems handle sensitive information routinely. The non-human actors are not a future consideration; they are already numerous, already credentialed, and already acting — and in most enterprises they are governed far more loosely than the human identities the security function has spent decades hardening.

The core insight the research offers is that agent identity must be treated as a privileged identity. A human identity governs one person acting at human speed; an agent identity may govern an autonomous entity acting across many systems at machine speed, which makes a compromised or misbehaving agent identity a far larger exposure than a compromised human one. The enterprises that govern their non-human identities to the standard they govern privileged human identities are securing the perimeter that has actually moved; the enterprises still focused on the human perimeter are hardening a door the risk has already walked past.

This blog is for research, security, and risk leaders who need to extend identity governance to the non-human entities now acting across their systems.

Why Non-Human Identity Is A Larger Exposure Than Human Identity

Three properties make non-human identity a larger exposure than the human identity the security function is used to governing.

The first property is speed and scale. A human acts at human speed on a bounded set of systems; an agent acts at machine speed across many systems, and can take many consequential actions in the time a human takes one. A misbehaving agent identity therefore causes damage faster and wider than a misbehaving human one, which means the containment window is shorter and the potential blast radius larger.

The second property is proliferation. Human identities grow with headcount; non-human identities grow with the agent estate, which grows far faster. The enterprise that governs a few thousand human identities may soon govern far more non-human ones, and the governance mechanisms sized for the human population are not sized for the non-human explosion. Proliferation means the non-human identity problem outgrows the human one it evolved from.

The third property is dynamism. Human permissions change slowly and deliberately; agent permissions can change dynamically, and some agents — as the browser-extension research shows — alter their own permissions over time. A non-human identity is a moving target in a way a human identity is not, which means governing it requires continuous attention rather than periodic review.

These three properties — speed and scale, proliferation, dynamism — make non-human identity a distinct and larger exposure. Governing it with the mechanisms built for human identity is insufficient, because the non-human identity behaves differently in exactly the ways that matter for risk.

The Five Requirements Of Non-Human Identity Governance

Governing non-human identities to the standard the exposure requires involves five things.

The first is managed, distinct identity per agent. Every agent has its own managed identity, issued and controlled by the enterprise, rather than sharing credentials or borrowing a human’s. Distinct identity is the foundation, because governance attaches to identity, and agents without distinct identities cannot be governed individually.

The second is narrowly scoped, revocable credentials. Each agent’s credentials grant the minimum access its function requires and can be revoked instantly. Narrow scope limits the blast radius of a compromised or misbehaving agent; revocability provides the containment mechanism the short damage window requires. The research is explicit that scoped, revocable credentials mapped to an accountable owner are the baseline.

The third is an accountable human owner per agent. Every non-human identity maps to an accountable human — the owner responsible for what the agent does with its credentials. The human owner is what connects the non-human identity to the enterprise’s responsibility structure, and it is what ensures every credentialed agent has someone answerable for its behaviour.

The fourth is hard boundary enforcement. The agent’s boundaries — particularly outbound network access — are enforced at the infrastructure level the agent cannot bypass, not left to the agent to observe. Hard boundaries are what contain a non-human identity that may act at machine speed to do something it should not; a boundary the agent enforces on itself is one it can also remove.

The fifth is continuous logging the agent cannot alter. Every action a non-human identity takes is logged to an append-only record the agent cannot modify. Continuous, tamper-proof logging is what makes non-human identity activity auditable and what preserves the evidence when an agent misbehaves. Logging the agent can alter is logging that fails exactly when it is needed.

These five — distinct identity, scoped revocable credentials, accountable owner, hard boundaries, immutable logging — are the requirements of non-human identity governance. They mirror the disciplines the security function applies to privileged human identities, extended to the non-human entities now acting across the enterprise.

The Gulf Research View

For Gulf enterprises, non-human identity governance is directly connected to the data-protection obligations the regional regulations impose. Agents acting on ZATCA-regulated or FTA-regulated data are non-human identities accessing regulated information, and the regulatory requirement to control and audit access to regulated data applies to non-human accessors as much as human ones. The scoped credentials, accountable ownership, hard boundaries, and immutable logging that non-human identity governance requires are the mechanisms by which regulated Gulf enterprises control agent access to regulated data.

The strategic implication for Gulf research and security leaders is that extending identity governance to non-human entities is a regulatory requirement, not just a security best practice, for agents touching regulated data. Gulf enterprises with mature privileged-identity governance for human access to regulated data have the model to extend; the work is to apply it to the proliferating non-human identities before they outnumber the human ones.

How Lynt-X Operates In This Picture

Minnato, our AI agent infrastructure, treats every agent as a managed, privileged identity. It issues distinct identities, scopes and revokes credentials to the minimum each agent requires, maps every agent to an accountable owner, enforces hard boundaries including egress control at the infrastructure level, and logs every action to an append-only record the agent cannot alter. The non-human identities are governed to the standard the exposure requires, consistently across the estate.

Vult and Dewply operate as governed non-human identities within this model rather than as ungoverned actors. Compliance & Invoicing uses the identity governance as the access-control and audit mechanism for agents touching ZATCA and FTA regulated data. Enterprise Operations, anchored in our Odoo partnership, brings embedded business-system agents under the same non-human identity governance.

Agents are identities now, and the perimeter has moved to the non-human side. The enterprises that govern their non-human identities to the standard they govern privileged human ones are securing the door the risk actually uses.

The Research Read

Enterprise risk is shifting from managing human identity to governing autonomous non-human entities that act across systems on their own credentials at machine speed and scale. The exposure is already concrete — non-human actors are numerous, credentialed, and acting, and many govern themselves more loosely than the human identities the security function has spent decades hardening. Agent identity must be treated as a privileged identity.

Non-human identity is a larger exposure than human identity because of its speed and scale, its proliferation, and its dynamism. Governing it requires five things: distinct managed identity, scoped revocable credentials, an accountable human owner, hard boundary enforcement, and immutable logging. These mirror privileged-human-identity discipline, extended to the non-human entities now acting across the enterprise.

The perimeter has moved. The enterprises still securing only the human side are hardening a door the risk has already walked past — while the non-human identities multiply, unwatched, on the side of the perimeter that has actually become the exposure.

“A human identity governs one person at human speed; an agent identity may govern an autonomous entity acting across many systems at machine speed — which makes a misbehaving agent identity a far larger exposure than a misbehaving human one. Agent identity must be treated as a privileged identity: distinct and managed, scoped and revocable, mapped to an accountable owner, bounded at the infrastructure level, logged immutably. The perimeter has moved to the non-human side, and most enterprises are still watching the human door.”