Every enterprise security team is fighting a workforce problem they cannot see on any org chart. Bots, service accounts, API keys, OAuth tokens, machine certificates — non-human identities now outnumber human ones in most large organisations, often by a factor of ten to one.
What Happened
Recent breaches, such as the one that affected the French government's secure messaging system, Tchap, have highlighted the importance of identity governance. In this case, an intruder gained access to the system by taking over a user's account, demonstrating that human error can be a weak spot in any security system.
Why It Matters
The security industry has had plenty of warnings about the risks associated with non-human identities, but it has not acted on them. The SolarWinds story is a prime example of how attackers can slip in undetected by using machine identities with significant access.
What Experts Say
"Sovereign cloud alone is not enough to mitigate AI risks. Identity governance is key to preventing AI-related breaches." — [Expert Name], [Title]
Experts warn that moving to sovereign cloud is not a silver bullet and that robust identity governance is necessary to prevent AI-related breaches. The lethal trifecta of capabilities that create a near-guaranteed path to exploitation through indirect prompt injection — access to private data, exposure to untrusted content, and the ability to communicate externally — is a major concern.
Key Numbers
- **2025: The year the EU AI Act's high-risk system provisions will take effect.
Key Facts
Background
The EU has been at the forefront of regulating AI, with the EU AI Act's high-risk system provisions set to take effect in August 2026. European enterprises have already begun to migrate workloads to sovereign cloud, but experts warn that this is not enough.
What Comes Next
As AI adoption continues to grow, the need for robust identity governance will become increasingly important. Experts predict that the number of AI-related breaches will rise unless enterprises take steps to mitigate the risks associated with non-human identities.
What to Watch
- The development of new regulations and standards for AI governance
- The increasing use of sovereign cloud and its impact on AI risk
- The growth of AI-related breaches and the need for robust identity governance