This session sets a strategy for governing the identities that already outnumber people - service accounts, API keys, tokens, secrets, and now autonomous AI agents that authenticate, reason, spawn, and act with standing privilege and no clear owner.
It characterizes non-human identity (NHI) and agentic AI as a distinct class of privileged risk, applies a maturity model to locate where an organization actually stands, and prioritizes the near-term controls that establish a defensible baseline.
It situates this against the regulatory reach of NIS2 and DORA, and against the oldest and most exposed non-human population of all — operational technology (OT), where shared service and vendor accounts still run on static credentials unchanged since installation.