The Secret Digital Workers Running the Internet: A Guide to Non-Human Identities

Imagine walking into a modern digital hotel. You use a plastic key card to unlock your room door. That key card represents your human identity—it proves who you are and gives you permission to enter.
However, behind the scenes, hundreds of automated systems are moving without human intervention: luggage delivery bots unlock elevator doors, security cameras check authority passes, and automated payment kiosks talk to bank servers.
To open those doors, these machines need their own keys.
In the digital world, humans are no longer the only ones logging in. Computer programs, automated scripts, software tools, and AI agents log in millions of times per second. These machine passes are called Non-Human Identities (NHIs).
In fact, in modern enterprise environments, non-human identities outnumber human identities by a ratio ranging between 45:1 and 140:1 1.
What Exactly is a Non-Human Identity (NHI)?
At its simplest, a Non-Human Identity is a set of digital credentials—such as an API key, a service account, or a digital token—that allows one software program to speak to another program without a human having to type in a password 2.
- An API Key: A special digital password that lets your weather phone app fetch live updates from a weather server.
- A Service Account: A background login created so a cloud service can automatically back up your files at midnight.
- A Digital Certificate: An encrypted pass that proves a website or device is legitimate and safe to connect with.
Without NHIs, the modern internet would grind to a halt because humans would have to manually approve every single background data exchange.
The 4 Places Where Unmanaged Machine Keys Hide
Because these machine keys are created automatically, they are easy to forget. Security teams face four major challenges when trying to manage them:
- Cloud-Native Growth: As companies move to the cloud, billions of tiny software connections are made across multiple servers 2.
- Software Assembly Lines (CI/CD Pipelines): Developers use automated tools to build and test code continuously. At every step of this automated assembly line, software tools leave behind digital access keys 1.
- Smart Devices & Forgotten Systems (IoT): Connected hardware, old dormant accounts, and expired digital certificates sit silently in networks, still holding active master access 2.
- Supply Chain Connections: Modern apps rely on third-party vendor tools. If an app trusts a vendor's API, it creates inherited trust. If that vendor gets hacked, the attacker can walk right into your system through that trusted connection 1.
The Emerging Threat: Logging In with "Borrowed Trust"
Security leaders have noticed a major shift: 80% of security leaders rank AI and machine-related identity risks as their top concern 3.
Why? Because tricking a human into giving up a password takes effort, and humans often have two-factor authentication (like a text message code).
Machine keys, however, rarely have two-factor checks. If a hacker finds a forgotten API key accidentally published in code or stored on a server, they don't need to break in. They simply "log in" using borrowed trust—the system assumes the attacker is just another friendly internal software tool 2.
The Agentic AI Escalation
The risk becomes even bigger with the rise of Agentic AI.
Traditional software only follows rigid, step-by-step instructions. Agentic AI, by contrast, makes autonomous decisions to complete complex goals 2:
- It can execute financial transactions.
- It can manage supply chain inventory and place orders automatically.
- It can interact directly with industrial control systems.
The Danger: Context Loss in Multi-Agent Chains
When AI Agent A hires AI Agent B, which then triggers AI Agent C to perform a financial trade, software systems can experience context loss. They lose track of who originally authorized the command, making it easy for mistakes or malicious instructions to slip through unnoticed 2.
The WEF Safety Framework for Machine Identities
To help organizations protect themselves, cybersecurity experts at the World Economic Forum (WEF) and its Global Future Councils designed a five-step governance framework specifically for non-human identities and agentic AI 2:
1. Universal Discovery ➔ 2. Eliminate Static Keys ➔ 3. Extend Zero Trust ➔ 4. Behavior Anomaly Detection ➔ 5. Identity Delegation Tracing
1. Universal Discovery & Ownership
You cannot protect what you cannot see. The WEF framework emphasizes that organizations must inventory every single API key, bot, and AI agent, and assign a responsible human owner to every machine identity 2.
2. Eliminate Long-Lived Secrets
Static passwords that last for years are dangerous. Organizations must phase out static keys and replace them with ephemeral (short-lived) tokens that expire automatically after a few minutes or hours 2.
3. Extend "Zero Trust" to Machines
Never assume a program is safe just because it is inside your network 2.
- Continuous Authorization: Continuously re-verify machine identities.
- Strict Least-Privilege Scoping: Give a machine key access only to the specific folder or task it needs—nothing more.
- Post-Quantum Cryptography: Upgrade security standards so future quantum computers won't be able to crack machine keys 2.
4. Behavior-Based Anomaly Detection
Instead of just checking if a key is valid when it logs in, systems must watch how the machine behaves. If a bot that normally checks weather updates suddenly attempts to download a customer database at 3 AM, the system must immediately flag and block it 2.
5. Identity Delegation Tracing
As AI agents pass commands down a chain of other tools, temporary safety passes must be attached at every step. This creates a full audit trail so humans can always review exactly why an AI agent made a specific decision 2.
Summary
As AI shifts from simple assistants to autonomous agents that take action on our behalf, protecting machine keys is no longer just a technical detail—it is the foundation of digital safety. Frameworks like the World Economic Forum's give us a roadmap to manage these digital workers safely as our systems grow.
References
[1] Enterprise NHI Statistics (45:1 to 140:1 Ratio): Cloud Security Alliance (CSA) & Entro Security Research. Data shows non-human identities outnumber human users by 45:1 in average enterprise setups and over 140:1 in cloud-native environments.
[2] World Economic Forum (WEF) NHI Framework: World Economic Forum Centre for Cybersecurity. Research and governance guidelines published by the Global Future Councils, titled "Governing Non-Human Identities & Agentic AI."
[3] CISO Threat Landscape Surveys: Gartner Cybersecurity & CISO Insights. Global Chief Information Security Officer (CISO) Industry Reports on Identity & Access Management (IAM), showing ~80% of security executives rank non-human identity exposure and autonomous AI access as top priorities.



