What Is a Non-Human Identity for an AI Agent
A non-human identity for an AI agent is a unique login for the agent itself, not a copy of yours. NIST 2026: own identifier, credentials, entitlements. If it uses your password, that is impersonation.

Five Eyes agentic AI guidance for a small business is five moves: low-risk task, distinct identity, least privilege, human gate, logs plus a kill switch. CISA, NSA, and allies published Careful Adoption of Agentic AI Services on 1 May 2026.
Five Eyes agentic AI guidance for a small business boils down to five moves you can staff without a security team: start on a low-risk task, give the agent its own identity, keep privileges tiny, put a human on irreversible acts, and keep logs plus a kill switch. That is the operator reading of CISA's 1 May 2026 joint guide, co-authored with NSA, ASD's ACSC, Canada's Cyber Centre, NCSC-UK, and NCSC-NZ.
I am Amelia S. Gagne, CEO of Kief Studio in Shrewsbury, Massachusetts. I study behavioral psychology and I ship AI applications. Brian holds the exploit-depth work. This URL translates the allied paper for a shop that does not have a CISO. Identity detail lives on what a non-human identity for an AI agent is. Sequence control lives on agent governance that checks the path.
The document is titled Careful Adoption of Agentic AI Services. It is not a consumer blog. It is a cybersecurity information sheet aimed at organizations that design, deploy, or operate LLM-based agents. CISA's news release on 1 May 2026 listed three actions in plain language: do not grant broad or unrestricted access to sensitive data or critical systems; begin with low-risk, non-sensitive use cases; account for agentic AI in the existing security model. NSA's companion notes, as reported in the same week, grouped risks as privilege, design and configuration, behavior, structure, and accountability.
That last word is the psychology. When an agent uses a shared human login, the log says a person acted. I study behavioral psychology because groups already fail this test: diffusion of responsibility. The allied agencies are describing the same failure at machine speed. NIST (Fisher and Galluzzo, 27 Aug 2026) said the same thing with IAM vocabulary: unique identifiers, credentials, entitlements, no shared passwords.
flowchart LR
A["1 Low-risk task"] --> B["2 Distinct agent identity"]
B --> C["3 Least privilege"]
C --> D["4 Human gate on irreversible acts"]
D --> E["5 Logs and a kill switch"]
1. Low-risk, non-sensitive first. CISA said it in the release. Drafting an internal FAQ is a different job from refunding a card or posting to the public site. I study behavioral psychology here too: people over-trust a fluent demo. Start where a wrong answer is an edit, not a wire.
2. Distinct identity. The agencies treat agents as governed digital identities. That is NHI in one sentence. A unique login, a named owner, a revoke that does not fire a human. NIST's identity post warned that sharing user credentials with agents creates accountability gaps, especially where non-repudiation matters.
3. Least privilege, not a standing shell. CISA: avoid broad or unrestricted access. Microsoft Incident Response's 30 June 2026 MCP note showed a poisoned tool description steering a finance agent while every click still looked routine. Pin tools. Read descriptions. See MCP security for a small business.
4. Human gate on irreversible acts only. NIST warned that overusing human-in-the-loop recreates MFA fatigue. Approve pay, send, delete, deploy. Do not approve every grep. Sequence totals still matter: five in-policy refunds can empty a drawer. That is sequence governance.
5. Logs and a kill switch. CISA listed obscure event records as a risk. If the log cannot name the agent, you cannot investigate. If nobody can disable the agent without deleting a person, you do not have an off switch. NIST AI RMF 1.0 (26 Jan 2023) is voluntary and still the US baseline: Govern, Map, Measure, Manage. Agents belong in Map (what exists) and Manage (how you stop them).
Google's Search Central guidance on helpful, reliable, people-first content is the public E-E-A-T document. Experience, expertise, authoritativeness, and trust are not a widget. They are a current byline, a real location, and claims you can source. This page names CISA, NSA, NIST, and Microsoft. It does not invent a private "23-point checklist." The allied guide is long. Five moves is what a two-person studio can run this month.
Copilot and ChatGPT will retrieve the official .gov PDF and this translation if this URL owns a different query than the PDF. The PDF owns the full agency text. This URL owns "what a small business does with Five Eyes agentic AI guidance." Distinct queries. That is the citation map, the same rule as how ChatGPT and Perplexity decide sources to cite.
kief.studio is the parent. LTFI is the hired department if you want ops without installing a box. briansgagne.com is Brian's security architecture. kief.dev is engineering hygiene. JDRSS is a separate mid-market security venture when the assessment is the product.
That is CISA's "account for agentic AI in your security model" without a new framework binder. Align it with whatever you already do for vendors: vendor security questions, consolidating audits, data governance.
The PDF at cisa.gov owns the full text. This page owns the small-business translation with a date and five moves. Copilot cites one URL per grounding query. If this essay also tried to own NHI definitions and MCP pinning, it would collide with those slugs. Cross-link them. Keep the first paragraph on Five Eyes plus five moves. That is how you add a cited URL instead of fattening an existing winner. E-E-A-T here is a current CEO byline, Shrewsbury as a real city, and .gov outbound links. No expired titles.
On 1 May 2026, CISA, NSA, and four allied cyber centers published Careful Adoption of Agentic AI Services: start low-risk, limit access, treat agents inside the existing security model.
It is guidance, not a statute. It is still the clearest public allied baseline. The five moves above are the part you can staff.
No. AI RMF 1.0 (Jan 2023) is the voluntary US risk process: Govern, Map, Measure, Manage. The Five Eyes paper is adoption guidance for agents. Use both. Do not swap the names.
Exploit detail, architecture, and assessments. This page is the operator translation. Link briansgagne.com when the question is how to build the control, not whether to start small.
It will if this URL owns the small-business query and the first paragraph answers it with a date and a named agency. The PDF still owns the full text. That split is the point.
A non-human identity for an AI agent is a unique login for the agent itself, not a copy of yours. NIST 2026: own identifier, credentials, entitlements. If it uses your password, that is impersonation.
AI pilots stall before production for boring reasons: no owner, no definition of done, no data path, no kill switch. CISA 1 May 2026: start low-risk. NIST AI RMF: Govern, Map, Measure, Manage.
AI agent governance fails when you approve each click and miss the path. Five in-policy refunds can still empty the drawer. Store intent, cap the run, gate pay/send/delete.
Work With Us
Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.
Newsletter
Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.
Subscribe