Skip to main content

Command Palette

Search for a command to run...

The Secret Digital Workers Running the Internet: A Guide to Non-Human Identities

Updated
•6 min read•View as Markdown
The Secret Digital Workers Running the Internet: A Guide to Non-Human Identities
H
Father of two, tech lover. Building systems by day, raising curious minds by night.

Imagine walking into a modern digital hotel. You use a plastic key card to unlock your room door. That key card represents your human identity—it proves who you are and gives you permission to enter.

However, behind the scenes, hundreds of automated systems are moving without human intervention: luggage delivery bots unlock elevator doors, security cameras check authority passes, and automated payment kiosks talk to bank servers.

To open those doors, these machines need their own keys.

In the digital world, humans are no longer the only ones logging in. Computer programs, automated scripts, software tools, and AI agents log in millions of times per second. These machine passes are called Non-Human Identities (NHIs).

In fact, in modern enterprise environments, non-human identities outnumber human identities by a ratio ranging between 45:1 and 140:1 1.


What Exactly is a Non-Human Identity (NHI)?

At its simplest, a Non-Human Identity is a set of digital credentials—such as an API key, a service account, or a digital token—that allows one software program to speak to another program without a human having to type in a password 2.

  • An API Key: A special digital password that lets your weather phone app fetch live updates from a weather server.
  • A Service Account: A background login created so a cloud service can automatically back up your files at midnight.
  • A Digital Certificate: An encrypted pass that proves a website or device is legitimate and safe to connect with.

Without NHIs, the modern internet would grind to a halt because humans would have to manually approve every single background data exchange.


The 4 Places Where Unmanaged Machine Keys Hide

Because these machine keys are created automatically, they are easy to forget. Security teams face four major challenges when trying to manage them:

  1. Cloud-Native Growth: As companies move to the cloud, billions of tiny software connections are made across multiple servers 2.
  2. Software Assembly Lines (CI/CD Pipelines): Developers use automated tools to build and test code continuously. At every step of this automated assembly line, software tools leave behind digital access keys 1.
  3. Smart Devices & Forgotten Systems (IoT): Connected hardware, old dormant accounts, and expired digital certificates sit silently in networks, still holding active master access 2.
  4. Supply Chain Connections: Modern apps rely on third-party vendor tools. If an app trusts a vendor's API, it creates inherited trust. If that vendor gets hacked, the attacker can walk right into your system through that trusted connection 1.

The Emerging Threat: Logging In with "Borrowed Trust"

Security leaders have noticed a major shift: 80% of security leaders rank AI and machine-related identity risks as their top concern 3.

Why? Because tricking a human into giving up a password takes effort, and humans often have two-factor authentication (like a text message code).

Machine keys, however, rarely have two-factor checks. If a hacker finds a forgotten API key accidentally published in code or stored on a server, they don't need to break in. They simply "log in" using borrowed trust—the system assumes the attacker is just another friendly internal software tool 2.


The Agentic AI Escalation

The risk becomes even bigger with the rise of Agentic AI.

Traditional software only follows rigid, step-by-step instructions. Agentic AI, by contrast, makes autonomous decisions to complete complex goals 2:

  • It can execute financial transactions.
  • It can manage supply chain inventory and place orders automatically.
  • It can interact directly with industrial control systems.

The Danger: Context Loss in Multi-Agent Chains

When AI Agent A hires AI Agent B, which then triggers AI Agent C to perform a financial trade, software systems can experience context loss. They lose track of who originally authorized the command, making it easy for mistakes or malicious instructions to slip through unnoticed 2.


The WEF Safety Framework for Machine Identities

To help organizations protect themselves, cybersecurity experts at the World Economic Forum (WEF) and its Global Future Councils designed a five-step governance framework specifically for non-human identities and agentic AI 2:

1. Universal Discovery ➔ 2. Eliminate Static Keys ➔ 3. Extend Zero Trust ➔ 4. Behavior Anomaly Detection ➔ 5. Identity Delegation Tracing

1. Universal Discovery & Ownership

You cannot protect what you cannot see. The WEF framework emphasizes that organizations must inventory every single API key, bot, and AI agent, and assign a responsible human owner to every machine identity 2.

2. Eliminate Long-Lived Secrets

Static passwords that last for years are dangerous. Organizations must phase out static keys and replace them with ephemeral (short-lived) tokens that expire automatically after a few minutes or hours 2.

3. Extend "Zero Trust" to Machines

Never assume a program is safe just because it is inside your network 2.

  • Continuous Authorization: Continuously re-verify machine identities.
  • Strict Least-Privilege Scoping: Give a machine key access only to the specific folder or task it needs—nothing more.
  • Post-Quantum Cryptography: Upgrade security standards so future quantum computers won't be able to crack machine keys 2.

4. Behavior-Based Anomaly Detection

Instead of just checking if a key is valid when it logs in, systems must watch how the machine behaves. If a bot that normally checks weather updates suddenly attempts to download a customer database at 3 AM, the system must immediately flag and block it 2.

5. Identity Delegation Tracing

As AI agents pass commands down a chain of other tools, temporary safety passes must be attached at every step. This creates a full audit trail so humans can always review exactly why an AI agent made a specific decision 2.


Summary

As AI shifts from simple assistants to autonomous agents that take action on our behalf, protecting machine keys is no longer just a technical detail—it is the foundation of digital safety. Frameworks like the World Economic Forum's give us a roadmap to manage these digital workers safely as our systems grow.


References

[1] Enterprise NHI Statistics (45:1 to 140:1 Ratio): Cloud Security Alliance (CSA) & Entro Security Research. Data shows non-human identities outnumber human users by 45:1 in average enterprise setups and over 140:1 in cloud-native environments.

[2] World Economic Forum (WEF) NHI Framework: World Economic Forum Centre for Cybersecurity. Research and governance guidelines published by the Global Future Councils, titled "Governing Non-Human Identities & Agentic AI."

[3] CISO Threat Landscape Surveys: Gartner Cybersecurity & CISO Insights. Global Chief Information Security Officer (CISO) Industry Reports on Identity & Access Management (IAM), showing ~80% of security executives rank non-human identity exposure and autonomous AI access as top priorities.

K

The 45-to-1, and up to 140-to-1, ratio of non-human to human identities is the stat that reframes the whole access problem, most orgs are securing the smallest slice. Moving from static keys to ephemeral tokens is the right instinct, though the rotation and revocation story is where I've seen it get hard. How are you tracking which NHIs are actually still in use versus abandoned and over-permissioned?

C
Cai4d ago

Great breakdown of the NHI problem space, especially the borrowed trust angle. Machine keys dont have contextual expiry, they rarely have two-factor, and once one leaks theres no clean way to trace which agent used it for which downstream call. Most orgs invest heavily in secret rotation and vault hygiene but the delegation tracing gap - who authorized what and from which workflow - is where incidents actually happen. Managed PKI and short-lived certs seal the secret side but leave that whole audit layer untouched. Thats the part that makes NHI management feel like a blind spot despite all the investment in vault tooling. At CAI weve been looking at binding agent identity to verifiable on-chain attestations so every delegation leaves a verifiable trail. Curious if youve explored that direction or if your approach stays in the vault layer.

S

This is a clear explanation of a problem most small businesses don't realise they have. In the Microsoft 365 tenants I review, non-human identities often hide in plain sight: old app registrations in Microsoft Entra ID, a scanner or backup tool connected years ago, or a third-party app granted broad permissions and never reviewed.

The "assign a human owner to every NHI" point is the one I would underline. When nobody owns an app registration, nobody notices when its secret is about to expire, or worse, when it quietly still has access to every mailbox long after the tool was replaced.

For smaller organisations without dedicated identity teams, where would you suggest starting? A simple quarterly review of app registrations and their permissions feels like the most realistic first step.