
Sometime in March, a student advising bot at a U.S. university started answering questions it should not have been able to answer. It had access to enrollment records for thousands of students, and an attacker had the credential. The credential was a service account. The service account belonged to nobody.
Three weeks later, on April 5, a public university's enrollment chatbot got hit the same way. Different school, same story. The bot's application key had never been rotated after the staff member who provisioned it moved on. Applicant names, contact information, and identifiers walked out the door.
Two incidents. Thirty days. Same failure mode. And here is the part I want the CIO reading this at a budget meeting to sit with: this was not an AI failure. The models did what models do. The agents did what agents do. What broke was the human org chart underneath them.
I put this prediction on the record a year ago. I said within twelve to eighteen months, AI identities would cause major harm at two or more high-profile institutions. It arrived at twelve. I am not doing a victory lap. I am telling you the tools to prevent the next one already exist, they have been sitting in a category we all know how to run, and higher ed keeps declining to run it on the identities that need it most.
Every identity practitioner in higher ed can tell you what a ghost account is. The former employee whose Active Directory record never got disabled. The adjunct who taught one semester in 2019 and still has an active session token somewhere. The student worker who graduated and kept access to a shared drive for two years because nobody ran the review.
We have a name for the fix. It is called identity lifecycle management. Provisioning tied to enrollment or hire. Deprovisioning tied to separation or graduation. Attestation tied to a manager who can name the person and vouch for the access. It is unglamorous. It works.
Now do the same exercise with the service account your AI advising bot uses.
Who provisioned it? What was that person's title at the time? Do they still work at the institution? When was the credential last rotated? Whose calendar has the rotation reminder? What downstream systems does that account touch? If it disappeared tomorrow, whose phone rings?
If you do not know the answers, you already have the exposure. The two schools that got breached this spring did not have a novel AI problem. They had the same ghost-account problem we have been talking about for a decade, applied to a non-human identity that happens to be doing more work per second than any human employee ever did.
The vendor world has started to name this. Aembit launched an identity and access management product specifically for agentic AI, and Google Cloud shipped an Agentic Identity and Access Management capability that puts centralized policy and least-privilege roles around AI agents. Microsoft patched a role in their platform that was supposed to be agent-only and, as it turned out, was not. Veza released an identity governance product that explicitly treats human identities, machine identities, and service accounts as first-class subjects for access review and lifecycle provisioning.
The category exists. The vocabulary exists. What does not exist, as far as I can tell from six months of scanning higher-ed press and EDUCAUSE working group output, is a single documented institution that has folded service accounts and AI agents into a formal access review campaign.
The frameworks shipped. The adoption did not.
I have been calling out a pattern for a while. Vendors ship a capability. Higher ed is told the capability exists. Somewhere in the middle, a load-bearing human is expected to translate the capability into a working policy, own the roster, chase the exceptions, and keep the whole thing running. That person's title is usually not "person who owns AI agent lifecycle." Sometimes it is not anyone's title at all.
Here is what an access review looks like at most institutions today. A manager gets an email in June. The email lists their direct reports. The email asks the manager to confirm the direct reports still work at the institution and still need the access they have. The manager clicks a button. The audit gets its checkmark. Governance is documented.
Nobody attests to the service account that runs the nightly Banner integration. Nobody attests to the API key that lets the AI enrollment chatbot query the student information system. Nobody attests to the workflow token that gives the agent read access to seven downstream applications. Those identities live outside the review process because the review process was designed for the workforce we had in 2019.
The workforce we have in 2026 is not just humans. Every AI agent your campus stands up this fall is a new identity, with an authorization scope, a set of downstream permissions, and a lifecycle that should be tied to something. If it is not tied to something, it is tied to nothing. And when the human who set it up leaves, the credential does not leave with them. That is not a hypothesis. That is the mechanism behind both breaches this spring.
Here is what I would tell a CIO who wants to walk into Fall 2026 without becoming case study number three.
Build a non-human identity roster. Every service account, every API key, every application credential, every AI agent your institution has stood up. Name them. Give each one an owner who is a currently employed human being with a current title. If the owner leaves the institution, the roster forces the credential into review before the last day. This is not sophisticated. It is bookkeeping. It is the bookkeeping we already do for laptops and building keys and parking passes, applied to the identities that actually run the institution.
Fold non-human identities into the access review cycle. When the annual attestation goes out in June, it does not just list Sarah's direct reports. It lists the seven service accounts Sarah owns, the three AI agents she provisioned, and the rotation dates on each of their credentials. If Sarah cannot vouch for them, the review kicks the account into a remediation queue instead of quietly rolling the credential forward another year.
Tie credential rotation to human lifecycle events. Not to a calendar. To the moment a provisioner separates from the institution or changes roles. This is the piece that would have prevented both March and April. The credential was orphaned by a role change and never noticed because no policy connected the human lifecycle event to the non-human credential lifecycle.
None of this requires a new AI governance framework. It requires applying the identity governance and lifecycle discipline we already claim to have to a category of identity we quietly excluded from scope. The IGA vendors have shipped the tools. Veza will do it. Google will do it. Aembit is built specifically for it. Microsoft's platform will do it if you configure it. QuickLaunch will do it against Banner and Colleague because that is what we exist to do. The tool is not the constraint.
The constraint is deciding, as an institution, that the roster is somebody's job. Somebody with a name. Somebody who is in the room when the AI advising bot gets stood up in September, asking the question that neither of the March and April institutions asked before they turned theirs on: when the person who provisioned this credential leaves, whose desk does the key come back to?
The two AI advisor breaches this quarter are not a technology failure. They are an org chart failure. Somewhere on both campuses, there was a person who provisioned the service account the agent rode on. And by the time the agent was misbehaving, that person had a new job, a new title, or a new employer. Nobody owned the key when the lock changed.
I keep telling the locksmith story because I keep watching institutions treat identity like a product decision instead of a craft. A locksmith does not sell you a lock. A locksmith cuts a key to your door, tracks who has copies, and knows to change the tumblers when somebody leaves under bad terms. That is the job. It has been the job since before any of us were born. The tools got fancier. The job did not change.
Every AI agent your campus stands up this fall is going to inherit a credential from a human who will not be there in eighteen months. Some of those humans are going to leave for better jobs. Some are going to retire. Some are going to get restructured out of roles nobody meant to eliminate. The credential does not care why. The credential just keeps working.
Write down whose desk that key returns to before you turn the agent on. Put it in a system. Give the system a review cycle. Give the review cycle a human owner. If you cannot answer the question of who holds the key when the lock changes, you do not have an AI governance problem. You have an identity lifecycle problem that AI is about to make loud.
Do not turn the agent on until you can answer the question. That is not fear. That is craft.
Primary: Run the QuickLaunch ILM assessment against your current non-human identity roster. If you do not have a roster, the assessment produces one. That is the starting point for every conversation that follows.
Secondary: Subscribe to the QuickLaunch column. One post a week. Written for the CIO who already knows what is broken and wants a more honest map.
Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential