Singapore’s machine identity problem is already bigger than its human one

As agentic AI reshapes government services, BeyondTrust’s Chief Security Advisor Morey Haber says that the real risk is not the algorithm but who is watching the identities it creates.

A more solidified identity management position is critical to reduce the privileged attack surface and safeguard citizen trust in digital services as they continue modernising. Image: Canva.

The growth of non-human identities is no longer a science fiction plot point, it is the reality for enterprises that now run over 100 non-human identities for every human one.

 

These include Application Programming Interface (API) keys, service accounts, and artificial intelligence (AI) agents, for which most organisations have no offboarding process.

 

An AI agent, while helpful, could also be the “single most efficient lateral movement path in your environment” if it runs with excessive, unmonitored and non-expiring privilege, says Morey Haber, Chief Security Advisor at BeyondTrust.

 

According to him, this is a “governance and risk problem” that requires immediate attention, and it starts with making visible the technology changes that continue accelerating.

 

This is particularly important for public sector agencies whose services directly impact citizen trust, he notes.

 

For that reason, he calls for a stronger identity management position to reduce the privileged attack surface and safeguard citizen trust in digital services as they continue modernising.

 

Talking to GovInsider, he discusses the growth of non-human identities and the risks they bring, alongside the opportunities for organisations to strengthen their security stance against increasingly more sophisticated threats.

 

Haber will be speaking at GovWare 2026 where he will talk about identity attack vectors, how incidents can occur the moment that privilege is wrongly granted, and what organisations need to understand to better protect their identities.

Visibility before anything else

 

In the past, prior non-human identities like service accounts and IoT (internet of things) devices were static. That has changed with AI agents, who can make real-time privilege decisions with no judgement or accountability.

 

“In the last year and a half, we have gone from agents that summarise a document to agents that can authenticate to a system, call an API, move data, and chain that action into a second and third system without a human in the loop,” says Haber, calling it a “paradigm shift”.

 
Morey Haber, Chief Security Advisor at BeyondTrust, will be speaking at GovWare 2026 in Singapore. Image: BeyondTrust.

The AI agent thus becomes a new middleware tool with its own class of privileged user access that follows instructions literally and runs the risk of conducting nefarious tasks when guardrails are compromised, he explains.

 

With so much at stake, organisations cannot just rely on policies to govern these technologies.

 

The first move before any policy should be visibility, says Haber. He recommends a VIP strategy: Visibility, Intelligence, and Protection.

 

This means getting a real count of every service account, key, token, and agent, who owns it, and the gap between granted and used privilege.

 

“This gap, between granted and used privilege, is where nearly every cybersecurity incident starts.

 

“It is not a glamorous first step, but it is a foundational one to every subsequent control for least privilege, secrets rotation, and session monitoring possible instead of just another policy,” he says.

The weight of the risk

 

While the risk of non-human identities and AI-driven cyberthreats affect both private and public sectors, government exposure is broader than corporate exposure because it impacts citizen trust, not just corporate loss, says Haber.

 

These risks manifest in impersonation and deepfakes, particularly for digital identity confidence and identity verification technology.

 

While the technology enabling these attacks is new, the target is the same, says Haber.

 

“The moment identity is asserted, and privilege is granted based on that assertion, an incident can occur.

 

“If that moment relies on a human's trust in a voice or a face rather than a verified, out-of-band, phishing-resistant credential or even a simple passcode, it does not matter how sophisticated your identity security program is, something bad could happen,” he warns.

 

A call centre authentication for tax or health services, for example, could be attacked by cloned voices to pass as a legitimate citizen, or use synthetic faces for video-based identity proofing services.

 

In some cases, these deepfakes also impersonate government officials communicating with the public.

 

A threat actor could do this easily by pulling a few seconds of their voice from a public keynote and calling a help desk or finance employee, then spoofing that voice and faking some urgency: “I am travelling, I need my access restored”.

 

“The compromise does not happen in the audio,” says Haber. “Identity is compromised based on a skipped authentication step that was supposed to prove who was asking.”

 

For public sector, the real cost is “an erosion of trust in the digital ID system a government has spent years and significant budget building,” he adds.

Looking ahead

 

“Sophistication of the attacks will keep outpacing the maturity of defences in 2027,” Haber says.

 

Identity management is the highest leverage fix available, he notes, adding that while not everything can change suddenly in just a year, he expects that basic cybersecurity strategies will mature.

 

For this upcoming edition of GovWare, he hopes for more “we have solved for…” and less “we plan to…” conversations, as he notes industry learns faster when practitioners compare real world notes and use cases.

 

Haber looks forward to hearing how teams are governing agent sprawl in production, what have they done to unwind an agent after granting too much standing privileges, and how they are thinking about accountability when an autonomous system takes an action that needs to be explained to a regulator or a citizen.

 

BeyondTrust will also feature a booth at GovWare (Booth #R02) with the theme “Identity Security of the Future” where attendees can listen to lightning talks, witness live demos, and access a free identity security risk assessment after the event.

 

---------

 

Alongside his session on Adversarial AI and Deepfake Attacks, Haber is a panellist at GovWare’s Healthcare Forum on Day 2, October 14, from 15:25 – 15:55. Do drop by if you want to meet him in person.

 

Do not miss out on these conversations, register for GovWare, and connect with the regional cybersecurity community here!