This week we ran the first Identity Leaders Network virtual roundtable on AI agent inventory and governance, with ten identity leaders joining from a range of industries. Before the session we surveyed the wider community on where their organisations actually stand.
The short version: nowhere near as far along as the vendor marketing suggests. Not one respondent, and not one person in the room, expressed confidence in how many AI agents or non-human identities are running in their production environment.
What the survey found
Nobody can count their agents. 40% of respondents said they have no idea how many AI agents or non-human identities are running in production. The remaining 60% could offer only an educated guess, somewhere between 50 and 500 agent identities. Nobody could give a number they would defend to an auditor.
Engineers are creating most of them. 80% of respondents said their engineering teams are already using AI agents. Business teams are creating them through low-code and AI tools, and, most uncomfortably, SaaS platforms are creating them automatically. Two of those three creation paths never touch an identity process at all.
Ownership is genuinely unresolved. 40% said AI agent identity governance sits with the IAM team. Another 40% said there is currently no clear owner at all. The remaining 20% said it is shared across multiple teams. And when asked how agents should be governed, not a single respondent chose to treat them like applications with a service account. The group split between treating agents like employees, with a joiner, mover and leaver lifecycle, and building a new governance model entirely.
What the room said
Inventory is unsolved, and third-party agents are the blind spot. One attendee has built a partial inventory of Microsoft-related agents using Microsoft Purview and Microsoft Security Center, with the obvious weakness that it only sees Microsoft. Another has a clean process for internally developed agents, register, authenticate, then publish, but no equivalent for third-party agents brought in by employees. That gap fed a wider discussion of shadow AI, which the group saw as the biggest single cause of the inventory problem.
The more autonomy an agent has, the more attribution it needs.
Shared identities are already causing operational pain. One attendee has multiple agents operating under the same global system identity. They cannot tell which agent performed a given action, and they cannot shut one agent down without affecting everything else using that identity. The ideal state the room described was one non-human identity per agent, linked to the agent's type, its business area and the human responsible for it. The obstacle is that many older downstream systems and APIs were never built for that kind of authentication, which means there is a real technical debt problem underneath the whole topic.
Nobody agrees who should own it. Some argued identity should enable agent governance rather than own it: IAM handles authentication, attribution, auditability and enforcement, while the team that builds the agent owns what it does. Others argued identity should own it outright, because accountability, lifecycle and access governance already live in the function. A third camp described a federated model, where the business owns the risk, a shared services function acts as custodian, and cyber provides the assurance framework. The room did not settle it, which matches the survey almost exactly.
Do agents actually need a new identity model?
The most practical position in the session came from attendees who are deliberately not inventing anything new. One onboards non-human identities through the same path as humans: a team requests a robotic identity through ServiceNow, it is provisioned into the right OU with a named owner and standard metadata, and access is granted just-in-time rather than as standing privilege. Another manages workforce agents through the same workforce identity platform their employees already use.
That framing produced the best question of the session: do AI agents actually need a completely new identity model, or do the foundations already exist and just need adapting? Nobody claimed to know. But the group that is making progress is the group reusing rails that already work.
What to take back to your own programme
Produce a number, even a bad one. Count the agents you can see, write down the paths you cannot see, and date the document. Every survey respondent is currently at zero.
Find your SaaS-created agents. They are the creation path nobody approves and nobody logs, and several platforms now create them by default.
Break up shared agent identities before there are more of them. One identity per agent, with a named human owner, is dramatically cheaper to retrofit at ten agents than at five hundred.
Put the ownership question to your leadership in writing. Whatever the answer, 40% of your peers currently have nobody accountable, and that is the worst of the available options.
The full survey findings are available to download, and the question we keep returning to remains open: if you are governing AI agent identities in production today, we want to hear what it actually looks like. Get in touch at danny@clutchgroup.co.
The Identity Leaders Network is a free, global and vendor-neutral identity community run by the publisher of Identity Briefing. Members meet through virtual roundtables, peer-matching sessions, dinners and a community WhatsApp channel.