Cyber Security Threat Detection

Keeper Security Research Exposes Critical Gaps in Securing AI Agents and Non-Human Identities

Cyber Security  /  Threat Detection  |  4 min read


New research from Keeper Security, the leading zero-trust and zero-knowledge identity security and Privileged Access Management (PAM) platform, has exposed a widening gap in enterprise security: organisations are rapidly expanding the access of non-human and AI-driven identities — without the visibility and controls required to secure them. The findings, drawn from a survey of 109 cybersecurity professionals conducted on-site at RSA Conference 2026 in San Francisco, reveal that Non-Human Identities (NHIs) — including service accounts, API keys, automation scripts, and AI-powered tools — are now deeply embedded in modern enterprise infrastructure, frequently operating with privileged access that is not consistently monitored or governed.

"AI and automation are expanding how systems interact and access an organisation's data. That shift introduces new complexity around identity, and requires a unified approach to visibility and control across both human and non-human access."

— Darren Guccione, CEO and Co-founder, Keeper Security

The Data: What Cybersecurity Professionals Reported at RSA 2026

The survey findings quantify the NHI security gap across three dimensions. On access and governance: nearly half — 46% — of respondents report that AI-powered tools already have access to critical systems and data, yet 76% say those identities are not consistently governed under privileged access policies. On visibility: only 28% of organisations report full visibility into NHIs across cloud, on-premises, and SaaS environments, while 53% identify the lack of visibility into AI, automation, and machine access as their top security risk. Without centralised visibility, security teams cannot enforce least-privilege access or monitor how identities are used — resulting in excessive privileges and unmanaged access. On incidents: more than 40% of respondents report experiencing a security incident involving non-human identities or credentials in the past year, while a further 32% are unsure whether such an incident has occurred — a figure that itself illustrates the detection gap.

Why NHIs Are a Structurally Different Security Problem

Non-Human Identities create a category of security risk that traditional Identity and Access Management (IAM) frameworks — designed for human workforce accounts — are not built to handle at scale. Unlike human users, NHIs are created programmatically, distributed across environments, used continuously, and often managed across multiple tools and teams with inconsistent policies and fragmented ownership. Most organisations continue to rely on manual processes that are not designed to scale in environments driven by automation and continuous system-to-system interaction. As AI agents, service accounts, and machine identities multiply — now estimated to far outnumber the human workforce at many organisations — credential sprawl, unclear ownership, and uneven lifecycle controls compound the risk. Static credentials and over-permissioned standing access make NHIs high-value targets: an attacker who obtains an API key or access token can gain unauthorised access, manipulate data, or disrupt critical operations — often without triggering existing alarms.

Keeper Security's Response: KeeperPAM

Keeper Security's response to the NHI security gap is KeeperPAM — a unified platform that integrates enterprise password management, secrets management, and privileged access controls in a single zero-trust, zero-knowledge architecture. The platform provides centralised visibility, enforces least-privilege access, and enables continuous monitoring across both human and non-human identities — treating service accounts, AI agents, and automation scripts with the same governance rigour applied to human employee accounts. Key capabilities include: automated credential rotation to eliminate standing access with static credentials; role-based access controls (RBAC) and time-based credential expiration; Just-in-Time (JIT) access and ephemeral secrets to replace long-lived API tokens; privileged session monitoring; and continuous auditing and behavioural monitoring to identify misuse before it leads to compromise. Keeper Security protects thousands of organisations and millions of people in more than 150 countries.

Key Takeaways

  • Keeper Security's RSA Conference 2026 survey of 109 cybersecurity professionals finds: 46% of organisations give AI-powered tools access to critical systems and data; 76% say those NHI identities are not consistently governed under privileged access policies; and only 28% have full visibility into NHIs across cloud, on-premises, and SaaS environments.
  • 53% of cybersecurity professionals identify lack of visibility into AI, automation, and machine access as their top security risk — and the detection gap is severe: 40%+ report a security incident involving NHIs or credentials in the past year, while 32% don't know whether one has occurred.
  • NHIs (service accounts, API keys, automation scripts, AI-powered tools) represent a structurally different security category: created programmatically, distributed across environments, used continuously, managed across fragmented tools and teams — with static credentials and over-permissioned standing access making them high-value targets for credential theft and session hijacking.
  • Most organisations rely on manual processes not designed to scale with automated, continuous system-to-system interaction — creating inconsistent policies and fragmented ownership as the number of machine and AI-driven identities grows far beyond the size of the human workforce.
  • Keeper Security's KeeperPAM unifies password management, secrets management, and privileged access controls in a zero-trust, zero-knowledge architecture — providing centralised visibility, least-privilege enforcement, automated credential rotation, JIT access, ephemeral secrets, and continuous behavioural monitoring across both human and non-human identities.
Tags: Cyber Security News AI in Cybersecurity Identity Security AI Tech Trends Zero Trust Artificial Intelligence News