Non-human identities outnumber people in production by nearly ten to one. So the term is worth pinning down, and the definition turns out to be the easy part.

Ask ten security teams what counts as a non-human identity and you get ten overlapping answers. That gap matters, because the ClearVector Identity Intelligence Report 2026 found non-human identities (NHI) make up 87 percent of the active identities in a typical AWS or GCP production environment. Fold in third parties and 91 percent of everything acting in production is something other than a person at a keyboard. The category we understand least is the category doing almost all of the work.
The easy part: a working definition
A non-human identity is any non-person entity that performs activity in production. In practice that means service accounts, API keys, managed identities, execution roles such as AWS IAM roles, workload identities, and access keys. Anything that authenticates and acts, without being a human being, belongs in the set.
That definition is easy to write down. Applying that definition to a specific identity in a live environment is not.
Why the definition is the easy part
The neat line between human and non-human blurs almost immediately, because humans use non-human identities constantly. A developer authenticates to an identity provider, then federates into production by assuming an execution role. The person started the session. The role is the identity actually acting in production. Human or non-human? Both, at different points in one workflow.
An adversary takes the same path. An adversary exploits a vulnerability in a containerized workload, gains code execution, and then uses the container's pre-assigned execution role to reach the hyperscaler control plane. The activity looks like a machine going about routine business. The provenance traces back to a human adversary. The execution role is genuinely a non-human identity, and reading that activity as ordinary machine behavior is exactly the mistake the adversary is counting on.
This is why a permanent, single-label answer does not hold. An identity is not human or non-human for all time. Humans drive non-humans, non-humans act on behalf of humans, and the relationship looks less like a hierarchy and more like a connected network that shifts from one action to the next.
AI is widening the category, fast
The set is also growing. AI-driven identities do not fit any one category, because AI-driven activity inherits and uses credentials, sessions, or trust relationships that are sometimes human, sometimes non-human, and sometimes owned by a third party. Every new automated workflow, model, and pipeline adds more non-person actors to production, and each new actor moves faster and more autonomously than the workloads that came before. The definitional question grows harder every quarter, not easier.
Define non-human identities by what they do
Here is the shift that matters. The useful question is not "is this identity human or non-human," answered once at provisioning time. The useful question is "what is this specific non-human identity doing right now, and what set that activity in motion."
The data makes the case for behavior over labels. Non-human identities do not act as a single mass:

- The median non-human identity touches a single account or project, yet the variability runs to plus or minus ten. A small population of super-connectors ranges across large multi-account footprints, often as centralized security or logging roles. The average describes almost none of the extremes.
- 93 percent of non-human activity is read-only: describe, list, get. 4 percent is privileged, and 3 percent is destructive, meaning delete, terminate, and similar high-impact actions. That 3 percent looks small until you remember that non-humans run most of the actions in production, and a destructive action from a compromised machine identity scales instantly.
- 54 percent of non-human activity is periodic and scheduled, and more than three-quarters of that activity happens outside standard business hours. A non-human identity that suddenly acts off its own schedule is far more interesting than one that simply runs at 2 a.m.
None of that is visible from the label. "Non-human identity" names the intent of the provisioned identity or the current activity of the actor. Define the category as broadly as you like, because the definition was never the hard part. Knowing what each non-human identity does in production, and tracing every action back to its source, is the work that actually stops an adversary.

%201.avif)


