Blog
The AI vocabulary decoder ring: Episode 3 - Non-human identity and shadow AI

Every identity term we have covered so far assumed you already know an agent exists. This episode is about the ones you do not know exist, and the much larger population of "identities" that were never human to begin with.
Non-Human Identity: Everyone who isn't a person
For decades, identity security mostly meant managing people: employees, contractors, their logins, their access. A Non-Human Identity, often shortened to NHI, is everything else that authenticates and acts inside your systems without being a person:
- Service accounts that keep applications talking to each other
- API keys and secrets embedded in code or automation scripts
- Bots and RPA scripts doing scheduled tasks
- AI agents, which are the newest, fastest growing, and most autonomous member of this category
The reason this term suddenly matters is scale. Human headcount grows slowly and predictably. Non-human identities do not. Every new integration, every automation script, every agent an engineering team spins up to solve a Tuesday afternoon problem adds another identity, and unlike a new hire, nobody runs it through onboarding, background checks, or an access request form. It just starts running.
The data backs this up, and the specific number is worth naming: Palo Alto Networks' 2026 Identity Security Landscape report, based on responses from nearly 3,000 cybersecurity decision-makers worldwide, put the ratio of machine identities to human identities at 109 to 1, up from 82 to 1 just a year earlier. Of those 109 machine identities per human, the report found roughly 79 are AI agents specifically, meaning agents alone now make up close to three-quarters of all machine identities in the average enterprise. Other vendor research lands at different points on the same trend line (estimates elsewhere range from roughly 45 to 1 up to 144 to 1 depending on how "machine identity" is scoped), but every recent measurement points the same direction: humans are no longer the majority of who, or what, is logging in, and the gap is widening every year, not narrowing.
Shadow AI: The agents nobody approved
Shadow AI is a specific, especially uncomfortable flavor of non-human identity problem: AI tools and agents that employees are using, building, or quietly deploying, without security or IT ever approving, registering, or even knowing about them.
This is not new in spirit. Shadow IT has existed for years, referring to unapproved software employees adopt on their own. Shadow AI is the same instinct, except now the unapproved tool can read your company's data, take autonomous actions, and connect to other systems on its own, often with far more reach than a rogue SaaS subscription ever had.
A marketing analyst wires an AI tool into the CRM to save time. A developer spins up an agent to auto triage support tickets and never tells anyone. Both are reasonable, well-intentioned decisions made by people trying to get work done faster. Both also create an identity with real access and zero governance, invisible to the very team responsible for knowing what has access to what.
Why this pairing matters
Non-human identity is the category. Shadow AI is what happens when that category grows faster than your visibility does. You cannot govern what you cannot see, and by definition, Shadow AI is the stuff nobody registered, reviewed, or assigned an owner to. It is the previous two episodes' problems (no harness discipline, no clear owner) happening at a scale and speed that manual, human driven discovery simply cannot keep pace with.
Where SailPoint fits in
This is the exact gap SailPoint Platform is built to close, and it starts before governance can even begin: you must find the thing first.
SailPoint's approach treats discovery as continuous, not a one-time inventory exercise. It actively surfaces AI agents and non-human identities across cloud platforms and AI services, including the ones nobody formally requested, and brings them into the same governed model used for human identities: registered, owned, access mapped, and subject to ongoing certification rather than a one-time approval that goes stale the moment the agent's permissions change.
That matters because the alternative to systematic discovery is hoping someone mentions it in a meeting. Shadow AI does not announce itself. It shows up in logs, in access patterns, in API calls to systems that were never supposed to have a new caller, and finding it requires the same kind of continuous, automated visibility SailPoint already applies to human access, extended to cover every identity that was never human at all.
The differentiator, in one breath
Anyone can write a policy that says all AI tools must be approved before use. SailPoint finds the ones that weren't, turning shadow AI back into governed AI instead of leaving it as an unmanaged identity quietly accumulating access in the dark.
That's the series so far: the plumbing (harness and loop), the accountability gap (agent owner and human in the loop), and the population nobody counted (non-human identity and shadow AI). Same decoder ring, same rule: no term gets to hide behind jargon.