Johannesburg Wednesday 7th October 2026: As AI agents and other non-human identities rapidly overtake the number of humans within organisations, security, risk, and compliance teams are challenged in controlling and governing a plethora of often-invisible entities. This is according to Solid8 Technologies, South African Development Community (SADC) region, sole distributor of Saviynt, a global organisation that assists many of the largest enterprises in the world to transform their identity programs and protect their people, assets, and infrastructure.
Kamel Heus, Vice President Sales at Saviynt, says the ratio of non-human identities to human identities is around 144 to one and expected to climb.
“These numbers are climbing fast. Gartner projects that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% last year. In addition, organisations are deploying AI rapidly to improve efficiency and productivity,” he says.
Heus notes that while security teams should be involved in AI deployments, they are sometimes seen as ‘blockers’ who slow progress down. As a result, AI projects and shadow AI are proliferating without security, risk, and compliance oversight.
Adding to the challenge is the fact that AI agents are autonomous, dynamic, and capable of taking actions across multiple systems at machine speed.
Saviynt notes that many enterprise identity programmes were designed for people, extended to cover machine identities, and are now expected to handle AI agents in the same way. However, while earlier non-human identities and AI agents may look similar on paper, the controls designed for humans and traditional NHIs will fail to govern AI agents.
“The big difference between AI agents and other RPA is that agents are by nature non-deterministic – they learn and adapt, so you cannot assume you know what they are doing in your systems and with your data,” Heus says.
“AI agents are becoming enterprise security’s biggest blind spot,” he says. “If you don’t know what AI agents are running on your network and you cannot manage and govern them, you can’t protect your environment.”
Mastering AI’s biggest security challenges
Heus emphasizes that visibility, accountability, and governance are crucial for safely harnessing AI agents.
“AI agents cannot be allowed to exist without clear ownership and accountability. Every agent operating within an organisation should have a named owner, and the organisation must have sight of who is responsible for what. As people move roles or leave the business, that ownership must move, or be terminated, with them. Without this level of governance, organisations risk creating a growing population of orphaned agents operating inside their networks, with no clear accountability for what they are doing or the outcomes of decisions they are making,” he adds.
To empower security teams to take control of the environment, Saviynt recently launched the industry’s first comprehensive enterprise AI Identity Security Platform. Named Zuma, for Zuma Beach in Malibu, the platform builds on Saviynt’s heritage as an identity management leader to offer a unified foundation to discover, protect, and manage AI agents and non-human identities.
Zuma Insights enables real-time discovery of all identities on the network and mapsrelationships between AI agents, applications, resources, and human owners. Zuma Governance establishes ownership, purpose, access reviews, lifecycle controls, and auditability for every AI agent and non-human identity. Zuma Access introduces a new approach to runtime authorisation through Intent-Aware Runtime Authorization (IARA) based on identity, context, risk, policy, and intended purpose.
“With Zuma, organisations can see every new agent, assign them to people, establish guardrails, and determine at runtime whether any action they take is in line with the agent’s original intent and purpose,” he says. “We offer not just full visibility, but also we enable organisations to govern AI agents at machine speed and protect the organisation at runtime.”
Heus says this control and security layer does not slow AI innovation or the user experience: “We have carried out extensive testing with our design partners to ensure that our guardrails and checks take place in real time,” he says.
As a SaaS solution, Zuma is highly scalable and offers a comprehensive dashboard giving organisations a real-time, centralised view of all AI agents, workloads, accounts, and credentials.
Patrick Devine, Head of Data and Identity Security Business Development at Solid8 Technologies, confirms Zuma fills a gap in the local market. “We have seen significant interest from leading enterprises across all sectors since Zuma was launched in the local market,” he concludes.
