The Best Podcast Episodes on Non-Human and Agentic AI Identity
Twelve podcast episodes that explain non-human identity and AI agent identity well enough to act on: secrets sprawl, workload identity, SPIFFE, delegation, MCP authorization, and Entra Agent ID, ordered for architects and security leads.
- Most non-human identity incidents come from credentials nobody owns: service accounts, API keys, and service principals with standing privilege. The better episodes start there, not with AI.
- The architecture answer that recurs across shows is to give workloads and agents verifiable identities (SPIFFE, workload identity federation, managed identities) and short-lived credentials instead of stored secrets.
- For AI agents, the strongest episodes argue you can start with OAuth specifications that already exist (token exchange, JWT authorization grant, transaction tokens) rather than waiting for new standards.
- MCP security is an authorization problem first: analysts and practitioners on separate shows report that few MCP servers implement the OAuth the MCP specification requires.
- All 12 episodes were checked against a transcript. Vendor guests are common on this topic, so each entry names the guest's employer.
The most useful podcast episodes on non-human identity and AI agent identity agree on one point before they disagree on anything else: the risk sits in credentials nobody owns. Service accounts, API keys, service principals, and now AI agents accumulate standing access because no person is accountable for them. The 12 episodes below, chosen from about 3,000 across the identity shows we track, take an architect or security lead from that problem to the current answers: workload identity, short-lived credentials, OAuth-based delegation for agents, and authorization for MCP.
Most of this field's podcast content comes from vendors selling NHI products, so we name each guest's employer. All 12 entries were checked against a transcript.
Part 1: The problem, stated plainly
1. #365 Exploring the Future of Machine Identity with Felix Gaehtgens (Identity at the Center, 62 min, 2025). A former Gartner analyst on how machine identities differ from human ones, why static credentials such as API keys and service accounts become technical debt, and the case for dynamic, ephemeral credentials. He argues most organizations still do this wrong, which makes it the right first listen.
2. NHI Workshop: What Are NHIs, Criticality, Risks and Challenges (The Non-Human & AI Identity Podcast, 23 min). A recorded panel with guests from SailPoint and P0 Security that defines non-human identities, explains why they matter, and lists the main risks. Short and introductory.
Read alongside: What is non-human identity? and the credentials nobody owns, our analysis of five September 2026 incidents built on unowned credentials.
Part 2: Secrets and the hidden admins
3. Discovering and Stealing Secrets with Mackenzie Jackson (401 Access Denied, 33 min). A GitGuardian researcher on the main ways attackers find and use secrets leaked in source code, and how developers defend against it. The talk names other vendors' tools and does not pitch.
4. Shadow Admins: The Non-Human Identities Hiding in Your Entra Tenant (Entra.Chat, 69 min, 2026). The most practical episode on this list. How service principals, app registrations, and agent identities in Microsoft Entra become hidden administrators, which API permissions to hunt for, and why to replace secrets with managed identities. If you run Entra, act on this one first.
Read alongside: secrets management, secrets rotation, and our best secrets management tools.
Part 3: Workload identity instead of stored secrets
5. Analyst Chat #264: Persistent Identity, Ephemeral Secrets (KuppingerCole Analyst Chat, 22 min). Martin Kuppinger on treating workload identities as privileged, why long-lived secrets widen the attack surface, and how ephemeral secrets, SPIFFE and SPIRE, and policy-as-code help. The clearest short statement of the target architecture.
6. Root Causes 640: What is SPIFFE? (Root Causes, 2026). A short explainer from two certificate industry veterans at Sectigo on how SPIFFE puts a workload or AI agent identifier inside a certificate, and how policy engines can allow-list those identifiers.
7. The Co-Inventor of Tor on Why Your NHI Strategy Is Already Behind (The Identity Jedi Show, 63 min, 2026). David Goldschlag of Aembit, a workload identity vendor, on why non-human identity risk built up while human identity matured: unrotated keys, hardcoded credentials, and applying zero trust to agents. Useful for the strategic argument; weigh the product context.
Read alongside: workload identity, workload identity federation, and Workload identity 101.
Part 4: AI agents and delegation
8. #422 Decoded: Securing AI Agents with Standards You Already Have (Identity at the Center, 78 min, 2026). The single best episode on this topic. Pieter Kasselman, who chairs the IETF WIMSE working group, explains how SPIFFE and existing OAuth specifications (token exchange, the JWT authorization grant, client ID metadata, transaction tokens) secure AI agents treated as workloads. The message: you can start now.
9. #390 Identity Management for Agentic AI with Tobin South (Identity at the Center, 56 min). Drawing on the OpenID Foundation's agentic AI whitepaper, this covers the hard parts that existing specs leave open: recursive delegation, scope attenuation as an agent hands work to another agent, and where MCP fits.
10. Agentic AI and the Authorization Gap No One Closed (Hybrid Identity Protection Podcast, 35 min, 2026). SecureAuth's chief executive on why agents need each action authorized in real time, why few MCP servers implement the OAuth the MCP specification requires, and how to roll agents out from zero privileges.
Read alongside: Securing AI agent identities and OAuth 2.0.
Part 5: MCP and attack research
11. Analyst Chat #317: MCP Is Just Another API, and That's the Bad News (KuppingerCole Analyst Chat, 52 min, September 2026). Alexei Balaganski frames MCP security as an API, identity, and authorization problem: unauthenticated MCP servers, tool poisoning, prompt injection, and practical next steps. Pairs naturally with episode 10.
12. One Compromised Agent ID Blueprint Can Cross Tenant Boundaries (Entra.Chat, 54 min, 2026). Datadog researcher Katie Knowles on how Entra Agent ID blueprints, agent identities, and agent users relate, and how stolen blueprint credentials could reach agent identities in other tenants. A concrete reminder that new agent identity features bring new attack paths.
The show to subscribe to
If you want a feed rather than a list, The Non-Human & AI Identity Podcast is the only show dedicated to the topic, publishing interviews, conference panels, and short Q&A several times a week. Many guests sell NHI products, so use it to track the conversation and this list for the fundamentals. KuppingerCole Analyst Chat and Identity at the Center's Decoded episodes are the strongest general shows on agent identity.
What no episode covers well yet
Two subjects that matter to architects lack a strong dedicated episode on any identity show we track: workload identity federation in practice across clouds, and governance of agent identities over their lifecycle (who approves an agent, who owns it, when it is retired). Both are covered in part by episodes 5 and 8.
The full ordered list, with 15 episodes and a note on which were checked against transcripts, is our non-human and AI agent identity learning path. For vendors in this space, see our AI identity and machine identity categories.
Frequently asked questions
- What is the best podcast for non-human identity?
- The Non-Human & AI Identity Podcast from NHI Mgmt Group is the only show dedicated to the topic, with several items a week. For fewer, deeper episodes, Identity at the Center's Decoded series and KuppingerCole Analyst Chat both cover workload and agent identity well.
- What is agentic AI identity?
- It is the problem of giving AI agents their own identities and scoped, auditable permissions, so an agent acting for a user or a business can be authenticated, limited to what its task needs, and traced afterward. It extends non-human identity with delegation: the agent acts on someone's behalf, often across several systems.
- Do AI agents need new identity standards?
- Partly. Several podcast guests, including IETF WIMSE working group chair Pieter Kasselman, argue most of the building blocks exist today in OAuth token exchange, the JWT authorization grant, transaction tokens, and SPIFFE. Open problems remain around recursive delegation and per-action authorization, which the OpenID Foundation's AI identity work is addressing.
- How do attackers compromise non-human identities?
- Mostly by finding credentials that were never meant to be exposed: secrets in source code and public issues, long-lived API keys, and over-privileged service principals or app registrations. Because no person owns these credentials, they are rarely rotated or reviewed.
Related on Start with Identity
- ArticleLearn Identity by Ear: Podcast Episodes on OAuth, OIDC, SAML and Passkeys
A listening plan for people new to identity: 14 podcast episodes, in order, that teach OAuth, OpenID Connect, SAML and passkeys from the people who wrote the sp
- RankingBest Non-Human Identity Security Platforms: Top 5
The best non-human identity (NHI) security platforms in 2026: Astrix Security, Token Security, Oasis Security, Entro Security, and Aembit. Ranked for discovery,
- GlossaryNon-Human Identity (NHI)
Any identity that is not a person: service accounts, API keys, OAuth tokens, certificates, workloads, and AI agents. NHIs now outnumber human identities in most
- GuideNon-Human Identity (NHI) Security: The 2026 Guide
Non-human identities now outnumber people many times over, and most are under-governed. A practical guide to what NHIs are, why they are the fastest-growing att
- ArticleTop 6 Open-Source Secrets Scanning and Non-Human Identity Tools
The best open-source secrets scanning tools in 2026, from TruffleHog and Gitleaks to detect-secrets, git-secrets, Kingfisher, and NHI Hound, compared on validat
- BlogAgentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was