Join our Newsletter — 33% off our NHI Course

Should organisations consolidate IT before expanding AI use?

Consolidation does not need to come first in every case, but expanding AI on top of fragmented identity and access control increases risk quickly. The practical test is whether the organisation can govern machine access, system integration, and visibility consistently across the stack. If not, AI adoption will amplify existing control gaps rather than simplify them.

When consolidation is the right prerequisite

The practical question is not whether every organisation must finish consolidation before any AI work starts. It is whether the organisation can apply the same access model, logging standard, and integration control across the systems AI will touch. If the answer is no, consolidation becomes a risk-reduction move because AI will otherwise inherit fragmented governance and multiply it at machine speed.

That matters most where AI agents, automation, or model-driven workflows need to act across multiple applications. In that environment, scattered identities, inconsistent entitlements, and duplicate integrations make it harder to prove who or what is acting, what it can reach, and whether access should still exist.

A useful way to frame it is to consolidate the control plane, not necessarily every application first. Centralising identity, approval, and observability can be enough to make AI expansion safer even while the business keeps some systems fragmented for a period.

Where AI expansion fails first

AI usually does not fail because the model is unavailable. It fails because the surrounding operating model is inconsistent. The first breakpoints are almost always access sprawl, unclear ownership, and weak boundaries between systems, especially when AI needs to use existing APIs, service accounts, or delegated permissions.

In practice, that means AI can expose old weaknesses that were tolerated in manual workflows. A human operator can notice an unusual access path or pause to validate a request. An automated workflow will often reuse whatever access it is given, so over-permissioned credentials or loose system coupling become more dangerous when they are machine-executed.

Consolidation also becomes more valuable when the organisation cannot answer simple questions consistently, such as which system owns a credential, which team approves a new integration, or which logs prove a machine action was authorised. Without that clarity, AI adoption is usually a control acceleration problem, not a productivity problem.

What good readiness looks like

Readiness is less about having a single platform than about having a consistent control pattern. You want one place to govern machine access, a repeatable way to approve integrations, and telemetry that can show which automated action used which permission set. That gives the organisation enough visibility to scale AI without losing accountability.

The strongest signal is that the organisation can define and enforce bounded access for AI use cases before they are deployed. If a workflow can be given narrow scope, monitored execution, and a clear owner, it can often be introduced safely even in a mixed environment. If none of those are true, expansion should be slower and more controlled.

Consolidation is therefore a means to an end: reducing the number of places where identity, approval, and audit logic can drift. When that logic is already centralised, AI adoption is easier to govern because the new workload inherits a known control pattern instead of forcing every legacy system to improvise one.

Risk and Threat Considerations

Expanding AI on top of fragmented access control increases the blast radius of any mistake. The main risk is not just misconfiguration, but inconsistent permissioning across systems, duplicated credentials, and poor visibility into which automated action used which access path. That creates both operational exposure and a larger target for abuse.

Failure mechanism: AI workflows inherit standing access, broad service permissions, or weak integration boundaries, then reuse them at scale without the human checks that previously limited misuse.

Impact: A single control gap can turn into cross-system overreach, unauthorized actions, or difficult-to-trace abuse, especially when machine actions are spread across multiple platforms and owners.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 provides the primary governance reference for this topic.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-9 — Service Identification and Authentication AI workflows and integrations depend on authenticating services and workloads.
AC-6 — Least Privilege The question centers on limiting AI access before it spreads across fragmented systems.
AU-2 — Event Logging Visibility into automated actions is essential when AI spans multiple systems.
Recommendation — Enforce IA-9 for AI-to-system access so machine actions use authenticated, accountable identities. Apply AC-6 to bound AI permissions to the minimum required for each workflow. Require AU-2 logging for AI-driven actions so access and execution remain traceable.

Practitioner Guidance

What to prioritise: Start with the access and integration layer, not the model layer. If you cannot bound machine permissions, assign owners, and see activity end-to-end, the organisation is not ready for broad AI rollout.

Decision rule: If an AI use case needs cross-system actions, require a clear approval path, narrow permissions, and auditable execution before production use. If those controls cannot be implemented consistently, keep the use case constrained or delay expansion.

What to verify: Confirm that the organisation can inventory the identities, credentials, and APIs the AI will use, and that each one has a named owner, review cycle, and monitoring path.

Practitioner takeaway: Consolidation is most important where it removes ambiguity in machine access and accountability; if the control plane is already coherent, AI can expand safely, but if it is fragmented, AI will magnify the fragmentation.