In the first article of this series, I outlined why government agencies need to address ungoverned data and high-risk human access before deploying AI at scale. These are foundational priorities for the safe adoption of agentic AI, but they are not the complete picture. The third piece of the puzzle, and the one that many public sector agencies in New Zealand have barely begun to tackle, is machine identities.
The machine identity gap that predates AI
Every agency operates with thousands of non-human identities that most security teams have never fully inventoried. This includes service accounts running automated processes overnight, API keys connecting systems and integration accounts moving data between platforms built years apart. These identities are not attached to a person, do not appear in HR systems, and rarely receive the same access reviews as human accounts. According to SailPoint research, 75% of machine identities have no designated owner. In government, where legacy systems are common and institutional knowledge turns over through restructures and attrition, that proportion is likely conservative.
Getting access controls and privileges right for machine identities is already a challenge for most agencies, even before AI enters the picture. Agencies that have not established ownership, lifecycle management and monitoring for their existing service accounts and integration credentials are already carrying exposure. That security foundation needs to be in place before AI agents add a new layer of speed, scale and complexity.
AI agents are the same problem at a different scale
AI agents are a new class of machine identity, and the governance principles that apply to a service account should apply to them equally. Every agent needs a named owner, access proportionate to its function, and monitoring capable of detecting when its behaviour changes.
What makes agents different from machine identities is the breadth of what they can do. A service account performs a defined, repeatable task, whereas an AI agent is goal-oriented, traversing systems, retrieving and analysing data, and making autonomous decisions in pursuit of an objective. Poorly scoped access gives an AI agent room to act beyond its intended purpose, creating the conditions for sensitive data exposure and unauthorised actions that are hard to trace.
SailPoint research shows 82% of organisations are already using AI agents in some capacity, and 80% report those agents have performed unintended actions, including accessing systems they should not have or sharing data unexpectedly. In government, where agencies manage citizen records, health information, tax files and social services data, the consequences of that exposure extend beyond operational disruption.
The urgency is reflected in the guidance coming from New Zealand’s own cybersecurity authorities. In May 2026, New Zealand’s NCSC co-signed joint guidance with Australia’s ASD and its counterparts in the United States, United Kingdom and Canada. The guidance was clear, calling on agencies to treat AI agents as a distinct identity, apply least privilege access, and continuously verify agent behaviour at runtime, not simply at the point of deployment. Far from being a case against AI adoption, it is a statement of what needs to be in place before agencies can responsibly scale it.
Visibility is where governance has to begin
Before any non-human identity can be governed, it must be discovered. That means building a complete inventory of every service account, bot and AI agent operating across government systems, including those embedded in platforms such as Microsoft 365 Copilot or procurement tools. Without that inventory, governance is guesswork.
Once agencies have visibility, the next step is control. Every non-human identity should have a named owner, a clearly defined purpose, access limited to that purpose, and regular review as systems, roles and services change. When that purpose ends, the machine identity should be decommissioned rather than left dormant in the environment. These are not new principles. They are the same disciplines that underpin human identity governance, now extended to agents, which have too often been allowed to operate outside formal oversight.
New Zealand’s public sector reform programme depends in part on AI delivering efficiency gains that manual processes cannot. That ambition is achievable, but only if agencies govern non-human identities operating inside their environment.
Agencies that cannot see, own and govern their existing non-human identities will struggle to control AI agents across systems at speed. That is where the next article in this series turns: to AI agents themselves, and the new governance questions they bring into the public sector.
To learn more, visit us here.