TL;DR
- No instrument names NHI. Not the EU AI Act, NIS2, DORA, ISO/IEC 42001, ISO/IEC 27001 or the NIST AI RMF.
- All of them require things that cannot be evidenced without it: access control, logging, oversight, accountability, incident attribution.
- The obligations terminate in artefacts. If a control does not produce an export you can hand over, it does not exist for compliance purposes.
- The EU AI Act high-risk dates moved. Annex III to 2 December 2027, Annex I to 2 August 2028, via the Digital Omnibus adopted in June 2026. A deferral, not a repeal.
- The most expensive error is scoping an AI management system around models and excluding the agents that touch production data.
The gap between what the rules say and what they require
Search any of the major instruments for "non-human identity" and you will find nothing. That absence is regularly used, inside organisations, as an argument that NHI is not a compliance matter. It is the wrong reading.
Every one of these instruments requires, in some form, that you can say what happened, who or what caused it, and under whose authority. None of those questions is answerable without identity records. The obligation is derived rather than stated, which makes it harder to fund and no less real. Your job in this is largely translation: turning a derived obligation into a named artefact with an owner.
Obligation to artefact
The following is our practical mapping, not text from the instruments. It reflects what assessors actually ask for.
| Instrument | Obligation in substance | NHI artefact that evidences it |
|---|---|---|
| ISO/IEC 42001 | Operate and evidence an AI management system | Agent inventory as controlled documented information; delegation-chain logs; tested revocation record; access reviews covering non-human identities |
| ISO/IEC 27001 Annex A | Access control, cryptography, supplier relationships | Credential inventory with owners and expiry; key management records; third-party integration register |
| EU AI Act | Logging, record-keeping, human oversight for in-scope systems | Records attributing agent actions to an agent and a delegating human; evidence oversight was exercised, not merely designed |
| NIS2 | Access control policy, asset management, supply-chain security, incident reporting | Inventory; scoped credentials; third-party grant review; ability to attribute an incident to a credential inside the reporting window |
| DORA | ICT risk management and third-party risk | Register of credentials held by ICT providers; scope and lifetime evidence; exit and revocation provisions |
| SOC 2 | Logical access controls operating effectively over a period | Provisioning and deprovisioning records for non-human accounts across the period, with exceptions |
The common thread is that every row terminates in an export, a record or a log. A control that produces no artefact cannot be tested, and an assessor will treat it as absent regardless of how well it is described in policy.
Dates that moved in 2026
The Digital Omnibus on AI amended Regulation (EU) 2024/1689. The European Parliament endorsed the final text on 16 June 2026 and the Council gave final approval on 29 June 2026.
- Annex III stand-alone high-risk systems: 2 August 2026 → 2 December 2027
- Annex I embedded high-risk systems: 2 August 2027 → 2 August 2028
- Article 50(2) marking for generative systems already on the market: 2 December 2026
- Unchanged: Article 5 prohibitions in force since 2 February 2025; GPAI obligations since 2 August 2025
How to present a deferral internally
A deferral read as a reprieve is the most predictable way to lose programme funding. The co-legislators were explicit that preparation should already be under way, the obligations are unchanged in substance, and the evidence that satisfies them, inventories, delegation logs, tested revocation, takes quarters rather than weeks to build. The accurate framing is that you gained runway, not relief, and the work that fills the runway is the same work.
Two framing errors that make the programme unfundable
Framing it as a regulatory requirement. Because no instrument names NHI, this framing invites the response that no rule requires it, and the conversation ends. Frame it as evidence capability instead: we currently cannot answer which agent took an action under whose authority, and several obligations we already hold depend on being able to. That is checkable and harder to dismiss.
Framing it as a security problem. This routes it to a security budget already committed elsewhere and to a team that does not control credential issuance. The work is disproportionately platform engineering work, and the funding argument is strongest when it is joint. See the platform engineering guide for what that side of it involves.
Scoping an AI management system without a hole in it
The most consequential decision in an ISO/IEC 42001 implementation is made at the very beginning, in the scope statement, and it is routinely made wrongly.
A scope written around "AI systems developed by the organisation" excludes the third-party copilot with write access to the CRM, the SaaS vendor's agent reading your ticketing system, and the assistant an individual team enabled without a procurement process. Those are usually the highest-risk AI in the estate, and they are outside the management system by construction.
Inventory before you scope. Find what is actually running, including what you did not deploy, and write the scope statement afterwards. Scoping first guarantees you scope around what you already know about, which is the subset with the least risk.
Frequently asked questions
Does any regulation require non-human identity governance?
None names it. The EU AI Act, NIS2, DORA, ISO/IEC 42001, ISO/IEC 27001 and the NIST AI RMF all avoid the term. Each requires things that cannot be evidenced without it: access control over credentials, logging that attributes actions, human oversight that can be demonstrated, and incident attribution within reporting windows. The obligation is derived rather than stated, which affects how you fund it but not whether it applies.
Did the EU AI Act high-risk deadline move?
Yes. The Digital Omnibus on AI was endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026. Annex III stand-alone high-risk obligations moved from 2 August 2026 to 2 December 2027, and Annex I embedded systems from 2 August 2027 to 2 August 2028. Article 5 prohibitions and GPAI obligations did not move and remain in force.
Does ISO/IEC 42001 certification demonstrate EU AI Act compliance?
No, and no accredited certification body claims it does. The two overlap substantially on risk classification, transparency, accountability and human oversight, and a 42001 management system produces much of the evidence the Act requires. They remain different instruments with different scopes and conformity routes. Use 42001 as the operating spine, not as a compliance shortcut.
What is the most common scoping mistake in an ISO 42001 implementation?
Writing the scope around AI systems the organisation develops, which silently excludes third-party copilots and vendor agents that have write access to production systems. Those are frequently the highest-risk AI in the estate. Inventory what is actually running, including what you did not deploy, and draft the scope statement afterwards.
How should we fund an NHI programme when no rule names it?
Frame it as an evidence capability rather than a regulatory requirement, because the regulatory framing invites the reply that no rule requires it. State plainly which questions you currently cannot answer, which obligations you already hold depend on answering them, and what the evidence gap would cost during an audit or incident. Fund it jointly with platform engineering, since most of the work sits there.
Building the AIMS documentation itself?
The ISO 42001 Toolkit covers the 23 core AIMS documents with all 38 Annex A controls pre-populated, plus a four-way crosswalk across ISO 42001, ISO 27001, NIST AI RMF and the EU AI Act.
Scoping an AI management system with agents in it?
HumanAudit runs ISO/IEC 42001 scoping and readiness work where non-human and agent identity is in scope, including the delegation-chain evidence most implementations discover too late.