Ai

With AI Agents Up 460% in a Year, BeyondTrust Launches a Governance Tool to Match

Kasun Illankoon

By: Kasun Illankoon

7 min read

The company's new Pathfinder platform module moves enterprise security past counting non-human identities and toward deciding who owns them, what they can reach, and when they should be shut down.

[For more news, click here]

Every large company now runs a second workforce that never asks for a raise, never takes a sick day, and almost never gets fired even after it should. It is made up of service accounts, API keys, OAuth tokens, and increasingly, autonomous AI agents, and in most organizations it already outnumbers the human employees on the payroll. For years, the security industry's answer to that shift has been to count these identities more precisely. BeyondTrust is betting that counting was never the hard part.

The privilege-centric identity security company on Thursday introduced NHI Governance, a new solution built on its Pathfinder platform designed to govern non-human identities across cloud, SaaS, endpoint, and on-premises environments. Where earlier tools in this category have focused on discovery, essentially producing a longer and more accurate inventory of machine identities, NHI Governance is built around a different question: once a company knows an identity exists, who is responsible for it, and when does its access get taken away.

The Math Behind the Announcement

The scale of the problem is what makes the shift feel overdue rather than incremental. Research from BeyondTrust Phantom Labs, the company's internal threat research unit, found that non-human identities already vastly outnumber human ones inside the typical enterprise, with the population of AI agents specifically growing more than 460 percent year over year. Almost none of those identities are assigned an owner. Their privileges are rarely reviewed or rightsized, their credentials are seldom rotated, and they typically keep whatever access they were granted on the day they were created, indefinitely.

That gap has stopped being theoretical. A recent wave of software supply chain attacks moving from one SaaS application to another has exploited exactly this blind spot, with attackers compromising the OAuth tokens that applications use to trust one another. There is no malware involved and no privilege escalation to catch, because the access being used was legitimate from the start. Every action an attacker takes reads as authorized, because it was authorized, just to the wrong party. Stopping that kind of intrusion requires the access to already be scoped down, the token to already be rotated, or the identity to already be retired before an attacker arrives. Visibility alone, arriving after the fact, does not do that work.

That distinction, between knowing an identity exists and having already reduced what it can do, is where most identity security programs still fall short. A dashboard that lists ten thousand service accounts and API keys is only useful if someone is assigned to act on what it shows, and in practice almost no one is. Security teams describe a familiar pattern: a discovery tool surfaces the scale of the problem, the finding gets logged, and the underlying accounts remain exactly as privileged as they were before anyone looked. NHI Governance is built on the premise that this pattern, repeated across thousands of identities, is itself the vulnerability.

From Inventory to Accountability

Marc Maiffret, chief technology officer of BeyondTrust, argues that the industry has spent its energy on the easier half of the problem.

“Seeing non-human identities was only half the equation,” Maiffret said. “The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren't using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That's not paperwork you bolt onto a tool built for employee onboarding. That's managing non-human identities at machine scale.”

That framing echoes a shift already underway among BeyondTrust's closest rivals. Okta has pushed toward treating AI agents as identity-bearing entities in their own right rather than extensions of the humans who built them, and CyberArk has leaned on partnerships to bring the same privileged access discipline it built for human accounts to machine and agent identities. The competitive convergence suggests the market has largely agreed on the diagnosis. What separates NHI Governance is an attempt to automate the prescription rather than leave it to manual review, on the theory that a population of identities this large cannot be governed one ticket at a time.

The product itself is built to execute what BeyondTrust describes as the non-human equivalent of the joiner, mover, leaver process that has long governed human employee access, applied in the sequence the company argues actually reduces risk. Every non-human identity is assigned to a person or team accountable for it, so nothing runs unowned. Identities that hold meaningful privilege get locked down, with what each one can reach constrained to close off paths to privilege it was never meant to have. Stale, orphaned, and abandoned identities, which make up the bulk of the ungoverned population, get retired outright rather than simply flagged. AI agents are brought under the same rules, with their own credentials and their own access rather than borrowed permissions.

Building on Two Decades of Privilege Work

NHI Governance does not stand alone inside BeyondTrust's platform. The company's Identity Security Insights product already supplies visibility and intelligence across non-human identities and the privileges attached to them, while BeyondTrust Password Safe secures, manages, and rotates the credentials behind those identities. NHI Governance is designed to take that existing visibility and credential management and turn it into lifecycle governance, establishing ownership and enforcing least privilege rather than simply reporting on what already exists. It also follows the company's recent introduction of AI Agent Security, part of a broader effort to unify discovery, governance, and enforcement inside a single Pathfinder platform rather than spreading the work across point tools.

Why the Timing Lines Up for Two Very Different Markets

The launch arrives at a moment when North American enterprises and Gulf governments are converging on the same problem from opposite directions. In the United States, the SaaS supply chain attacks that have exploited OAuth trust relationships have pushed identity security further up the boardroom agenda than almost any other category of cyber risk this year, particularly for the financial services and technology companies that run the most interconnected application stacks. In the Gulf, the calculus is different but points toward the same solution. Governments across the region, including Bahrain and Saudi Arabia, have committed to sweeping AI and digital government programs that are deploying autonomous agents and machine identities at a pace few compliance frameworks were built to handle, making ownership and lifecycle governance less a security nicety than a prerequisite for the AI ambitions themselves.

Neither market is short of tools that can see the problem. What both are increasingly short of is a mechanism that closes it. NHI Governance is a bet that the next phase of identity security will be judged not by how complete the inventory looks, but by how quickly an unowned or unnecessary identity can be found an owner, stripped of privilege, or simply removed, and by how much of that work never needs a human to do it one identity at a time.

If that bet plays out, the change will be felt less as a new product category than as the quiet retirement of an old excuse. For years, the standard answer to a board asking who has access to what has been an inventory, with a dashboard update promising that visibility was improving. That answer has always been a stopgap rather than a solution, and the events of the past year have made the gap between the two harder to ignore. The measure of progress from here is not how much of the machine workforce a company can see, but how much of it can actually be held accountable, one owner assigned and one retired credential at a time.

Related Articles:

The Internet Already Has a Directory for AI Agents, It Was Built in the 1980s

Exclusive: AI Agents to Cause 25% of Enterprise Breaches by 2028

The AI Agent Security Gap Is Closing, and the Middle East Is Proving to Be the Fastest Market to Demand It

Share this article

Related Articles