Non-human identities like AI agents now exceed human users in 83% of organisations, according to JumpCloud's Q3 2026 research. These agents operate across business systems, accessing Salesforce, creating Jira tickets, managing infrastructure, and processing financial transactions. Despite their widespread use, only 21% of organisations have implemented governance controls specifically for non-human identities. Unlike human employees, most AI agents are not formally onboarded, lack assigned owners, and have no offboarding process when their function ends.
JumpCloud outlines a framework to secure these digital workers, starting with discovering every agent in an organisation's environment. Many AI agents are deployed independently by product teams, operations leaders, or individual staff, leading to incomplete inventories. The next stages involve assigning ownership, defining access scopes, monitoring activity, and establishing lifecycle management. Without these steps, organisations risk unauthorised access, data exposure, and unchecked automation. The framework treats AI agents as workforce members that require the same level of identity governance as people.
Most AI agents in companies today operate without owners, oversight, or exit plans, even as they outnumber human users. This creates a hidden access risk in systems handling sensitive operations and data. If governance lags behind deployment, organisations may face breaches through unmanaged digital identities.
Editorial note: AI-assisted opinion, not established fact. Full disclaimer →