Contents · 4 sections+
There is a quiet crisis unfolding inside enterprise IT environments that nobody is particularly keen to discuss at the board level. Not because it's complicated — it isn't. But because it exposes something deeply uncomfortable: that the governance frameworks organisations spent the last decade building were designed for humans. And humans, it turns out, are now a minority in their own digital estates.
Let me paint you a picture.
Your organisation has deployed AI agents to handle customer triage. Automation bots to reconcile invoices. RPA platforms to process compliance checks. API integrations threading your cloud infrastructure together like invisible sinew. Service accounts quietly humming away, running workloads that nobody quite remembers authorising. Cloud-native applications spawning identities like rabbits in spring.
All of them have access. All of them have privileges. All of them are, in the language of identity and access management, actors.
And yet, when you ask who is responsible for the service account running your financial data pipeline at 2am on a Tuesday — you are often met with the corporate equivalent of a shrug. "It's just a system account."
No. It isn't.
I.The accountability gap nobody budgeted for
We have spent considerable energy in recent years talking about Zero Trust architecture. Least privilege. Identity-first security. Worthy ambitions, all of them. But they were conceived in a world where the identity problem was fundamentally a human problem. Rogue employees. Credential theft. Insider threats.
The new problem is structural, not behavioural. It is not that a malicious actor compromised a machine identity. It is that nobody owns it in the first place.
Machine identities — service accounts, API keys, bot credentials, agent tokens — are now proliferating faster than governance teams can track them. In many environments, non-human identities already outnumber human ones by a ratio that would alarm any risk committee unfortunate enough to be told the truth. These identities hold elevated privileges. They operate continuously. And they answer to no one.
When a human misuses access, you investigate. You have an audit trail. You have a name. You have a performance review on file and a legal team on speed dial.
When a machine identity misbehaves — or is quietly compromised, or drifts outside its intended scope, or is simply abandoned when the vendor relationship ends — you often don't know it happened. And when you do find out, the first question — who was responsible for this identity? — is frequently unanswerable.
That is not a technology failure. That is a governance failure dressed up as an IT problem.
II.Autonomous privilege is not a feature
Here is the uncomfortable framing that the industry has been slow to confront: if no human is accountable for a non-human identity, you have not automated a process. You have created autonomous privilege.
Autonomous privilege sounds rather thrilling in a sci-fi context. In an enterprise risk context, it is a liability with a very expensive tail.
The solution is not to slow down AI adoption or treat automation as inherently suspect. That ship has sailed, and frankly, it was never a realistic option for organisations competing at pace. The solution is to extend accountability frameworks to every identity in the estate — regardless of whether that identity belongs to a human or a system.
Every machine identity should have a named human custodian. Not a team. Not a department. A person. One person who can be held responsible for what that identity does, what it can access, and what happens when it is no longer needed.
Every machine identity should be registered against a configuration item. Lifecycle-managed. Policy-bound. Monitored against an accountable authority. Decommissioned when its purpose expires — not left to drift through the environment like a ghost with a valid access token.
This is not exotic. It is the same principle we apply to human identities, extended to cover the actors we have been quietly ignoring.
III.The sovereign dimension
There is a larger argument lurking beneath the operational one, and it is worth naming plainly.
At enterprise scale, unmanaged machine identity is operational risk. At national scale, it is something closer to digital sovereignty risk. As governments and regulators increasingly scrutinise AI deployment, the question of who is accountable for automated decision-making — not just who built it — is moving from philosophy seminar to regulatory requirement.
The organisations that get ahead of this will not be those with the most sophisticated AI deployments. They will be those who built accountability structures capable of governing them.
The rest will be explaining to their boards — and eventually to regulators — how a service account nobody owned managed to become a significant compliance event.
IV.What this means if you are hiring for it
From where I sit — placing technology and infrastructure leaders across Singapore, Amsterdam, and Dubai — the organisations asking the right questions are now hiring for this intersection specifically. Not pure security. Not pure IAM. But leaders who understand that identity governance in a machine-dense environment requires a fundamentally different operating model.
The CISO who can only think in human identity terms is already behind. The IAM leader who has not yet built a non-human identity programme is operating on borrowed time. And the CTO who thinks AI deployment and governance are sequential activities — first deploy, then govern — is setting up an expensive lesson.
The future is not just Zero Trust. It is accountable trust.
And accountable trust requires someone, somewhere, with their name attached to every actor in your environment. Human or otherwise.