Non-human identities are becoming a bigger part of the enterprise as service accounts connect applications, API keys authenticate automation, CI/CD credentials deploy infrastructure, and AI agents access the repositories, SaaS applications, cloud environments, and other systems they need to do their jobs.
Security teams have responded by putting more controls around how these identities and credentials are created, stored, and managed. But there is another side of the NHI attack surface that is much harder to govern: what happens after a credential leaves the system designed to control it. A credential copied into Slack, committed to a repository, written to a CI artifact, saved on an endpoint, or included in an agent configuration file may still provide exactly the same access it did when it was properly stored, but the exposed copy now sits outside many of the controls intended to govern it.
One identity, two very different security states
Consider an API key that was properly provisioned and stored in a secrets manager, where it has an owner, a rotation policy, and an intended application. If that same key gets pasted into Slack while someone is troubleshooting a deployment, the credential itself hasn’t changed. As long as it still authenticates, it carries the same permissions regardless of where someone finds it.
What has changed is the security team’s visibility into it. The copy sitting in Slack may persist long after the conversation is forgotten, potentially without the owner or security team knowing it exists. Once a credential escapes its intended location, teams need to account for an identity that may still be trusted by downstream systems but is no longer contained by the controls surrounding its original copy.

Our research shows how long that gap can persist. When we recovered 678,376 deleted PyPI packages, we found 190 unique live secrets, including a GitHub token with admin access to the Apache and Astronomer organizations that had been sitting in a package from April 2023.
AI expands both sides of the equation
Credentials have been leaking into code, chat, logs, and configuration files for years, but AI can increase the scale of the problem on both sides. Inside the enterprise, agents need credentials to interact with the systems where they work. A coding agent might connect to GitHub, Jira, Slack, and a cloud environment, potentially giving a single agent access to several machine credentials, while agent and MCP configuration files create additional places where those credentials can surface.
Attackers are gaining more automation at the same time. AI can reduce the amount of manual work required to search large volumes of data for exposed credentials, determine which ones still authenticate, and identify useful access. That changes the economics of credential exposure because the age of a leak matters much less than whether the credential still works when an attacker finds it.
Our AWS research illustrates the problem. When we rechecked 64,024 AWS keys found in public code, container images, and datasets, 88% were still active. The median key had been active for five years, and only 14% had ever been rotated. The access behind those credentials also varied dramatically, from relatively limited permissions to paths into sensitive systems and data.
That is why an exposed secret represents more than something that needs to be removed from a file. If the credential still authenticates, it represents an identity that can potentially be used to access the environment.
The NHI problem doesn’t end at provisioning
Organizations are investing heavily in managing non-human identities, and for good reason. Knowing which identities exist, limiting their permissions, preferring short-lived credentials, and moving toward managed identities can all reduce risk. But governing the identity you intentionally created does not automatically account for every place its credentials end up.
As AI increases the number of machines acting on behalf of people, that distinction becomes increasingly important. Security teams need to think not only about the NHIs they provision and manage, but also about the credentials that escape those controls and continue to provide trusted access.
On October 14, Truffle Security Solutions Architect Matt Brady will dig into this problem during Stopping Exposure Before It Becomes Breach Risk. He’ll cover how unmanaged NHI credentials create hidden paths into enterprise environments, how AI is changing the attack surface, and how security teams can find and close those exposures before attackers take advantage of them.
Watch the webinar: Stopping Exposure Before It Becomes Breach Risk.


