The Replicant in Your Directory: AI Agents and the Identity Security Gap

In the past few years, cybersecurity teams have been facing a growing challenge: non-human entities with access to sensitive data and systems. These “replicants” are AI agents, service accounts, OAuth applications, workload identities, and machine identities that already outnumber people in many enterprise environments. The issue isn’t new, but it’s gaining urgency as these entities multiply rapidly, exposing the limitations of traditional identity security.

These replicants have their own accounts, permissions, and access to sensitive data, which is a far cry from the human-centric identity security programs built over the years. Those systems were designed around people joining companies, changing roles, taking vacations, and eventually leaving. But machine identities rarely follow that pattern, making it challenging for organizations to keep track of who owns them, why they exist, or what they can access.

The numbers are staggering: according to the Non-Human Identity Management Group, machine identities now outnumber human users by as much as 50 to one in many environments. Some of these entities exist for just minutes, while others remain active years after the application or automation that created them has been forgotten. Most organizations struggle to answer basic questions about their non-human identities, leaving a significant gap in identity governance.

One recent example highlights the problem: threat actors tracked as UNC6395 obtained an OAuth token associated with Salesloft’s Drift chat integration and used it to move through Salesforce environments across hundreds of organizations. The issue wasn’t that the token exploited a software vulnerability; it was that it was already trusted, providing attackers with a pathway to sensitive data.

AI agents don’t create this problem; they accelerate it. Organizations are deploying AI agents that create identities, inherit permissions, interact across systems, and expand the number of trusted credentials operating inside the environment. If security teams don’t know these identities exist or understand what they can access, the attack surface grows quietly in the background.

Human identity programs assume someone owns an account, reviews access periodically, and eventually removes it. AI agents don’t naturally fit this lifecycle; they can be created automatically, inherit permissions from other identities, interact with systems at machine speed, and even create additional identities as they work. The result is an identity population growing faster than most governance processes were designed to handle.

Organizations often know they’re adopting AI faster than they’re governing it but don’t know where the gaps are. That’s why it’s essential to assess your organization’s identity, data, and AI governance practices. Netwrix offers a free AI Maturity Assessment that benchmarks your organization’s strengths and blind spots, providing practical recommendations to reduce AI-related risk.

It’s not enough to have visibility into non-human identities; organizations need continuous answers to four fundamental questions: What identities exist? Who owns them? What can they access? When should they no longer exist? Without those answers, every new AI deployment quietly expands the number of trusted identities operating inside the environment. The accountability question is pressing: when an AI agent contributes to a breach, who’s responsible for it?


Source: Bleeping Computer — 2026-07-10