TL;DR: AI is speeding up IT work for 56% of daily users while 38% of leaders say it also increases job complexity, and 63% of companies now require AI training, according to JumpCloud. The real constraint is no longer tooling alone but the people, process, and risk controls needed to scale AI safely.
At a glance
What this is: This is a JumpCloud analysis showing that AI adoption is improving IT productivity while simultaneously increasing workflow complexity, skills pressure, and governance burden.
Why it matters: It matters because IAM, NHI, and AI governance teams cannot treat AI rollout as a tooling exercise; the limiting factors are training, risk controls, and operating-model change.
By the numbers:
- 56% of IT professionals who use AI daily say it saves them time and reduces stress.
- 38% of IT leaders who praise AI also report that it increases the complexity of their jobs.
- 63% of companies require their teams to complete some kind of AI training.
Context
AI adoption in IT is no longer just a technology question. It is a workforce and governance problem as well, because the value of AI depends on whether teams can absorb it into daily operations without creating unmanaged risk.
The article frames that shift around IT skills, workflow redesign, and training discipline. For identity leaders, the same pattern shows up whenever a new capability changes how people request access, approve actions, or supervise systems.
The article is also a reminder that AI maturity is not measured by deployment alone. When AI increases complexity for the people operating the environment, governance has to mature at the same pace.
Key questions
Q: How should organisations train IT teams for AI adoption?
A: Organisations should train IT teams on AI integration, risk management, and compliance using real workflows, not generic awareness content. Training needs to show staff how AI changes approval paths, exception handling, and data use. The goal is to make people capable of supervising AI safely, not just using it quickly.
Q: Why does AI adoption increase complexity for IT leaders even when it improves productivity?
A: Because productivity gains usually arrive with new dependencies, review points, and decisions that must be supervised. AI can remove repetitive work while adding ambiguity around accountability, workflow design, and exception handling. The result is faster execution with more coordination overhead, which means the control environment has to mature alongside the technology.
Q: What are the signs that AI training is not keeping pace with adoption?
A: Look for inconsistent outputs, frequent manual overrides, unclear escalation paths, and teams that cannot explain how AI-assisted decisions are reviewed. Those symptoms suggest the organisation has deployed capability without creating shared operating rules. When staff cannot challenge or validate AI outputs confidently, governance quality will fall behind usage.
Q: How should security teams govern access to AI training data?
A: Security teams should treat AI training data as a privileged asset and apply least privilege, ownership, and review cycles to every identity that can read, export, or transform it. The focus should be on the pipelines that create model behaviour, not just the model runtime. If data access is broad, the AI programme inherits unnecessary exposure.
Technical breakdown
Why AI adoption increases operational complexity in IT teams
AI reduces friction when it automates routine work, but it also adds new decision layers, new dependencies, and new review paths. In practice, that means staff are no longer just executing tickets. They are interpreting recommendations, validating outputs, and stitching AI into existing systems and processes. That creates an operating model problem, not only a productivity gain. In identity programmes, this is familiar: every new control or workflow changes how people route approvals, verify access, and handle exceptions. Practical implication: treat AI deployment as a change to control flow, not just a feature rollout.
Practical implication: assess whether AI changes approval paths, review points, and escalation handling before you expand usage.
What the AI skills gap means for governance and risk management
A skills gap becomes a governance gap when teams cannot confidently operate the tools they have adopted. The article shows that many organisations struggle not with ideas, but with applying AI inside existing workflows and managing the related compliance and legal exposure. That is especially important when AI is used to inform identity, access, or security decisions, because weak understanding produces inconsistent outcomes and undocumented exceptions. Skills are therefore part of the control environment, not a soft benefit. Practical implication: map the AI skills required to operate, review, and challenge AI-enabled processes.
Practical implication: align training with the actual governance tasks people must perform, not just with tool usage.
Why AI training has become a control, not just a learning exercise
Mandatory training matters because AI use changes how decisions are made and where accountability sits. The article notes that 63% of companies now require AI training, which reflects a broader shift toward formalising competence before systems become harder to supervise. For identity teams, training is one of the few ways to reduce unsafe variation in how staff use AI in workflows, handle data, and interpret outputs. Without it, the organisation gets adoption without consistency. Practical implication: use training to standardise how AI is introduced into operational and governance processes.
Practical implication: make AI training part of operational readiness, especially where AI influences access, compliance, or review decisions.
Breaches seen in the wild
- JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI adoption is exposing a workforce governance gap, not just a productivity opportunity. The article shows that AI can save time for daily users while making leadership work more complex, which means the same deployment can raise output and operating strain at once. That is the real governance issue: the control environment must absorb the speed-up without losing oversight. For identity programmes, this is the same pattern seen whenever a new layer of automation changes how decisions are made and reviewed.
Skills readiness is now part of the control stack. Half of IT teams say AI integration into existing workflows is their biggest problem, and that is not merely a training issue. It is a sign that AI adoption is colliding with organisational design, process discipline, and accountability boundaries. When teams cannot operate the workflow safely, the technology stack is ahead of the governance stack.
AI training has become a prerequisite for trustworthy scale. The article’s 63% training figure signals that organisations are starting to formalise competence, but the deeper point is that AI use without shared operating norms creates uneven risk. Training matters because it determines whether staff can challenge outputs, recognise limits, and maintain compliance under pressure. Practitioners should treat training as a governance control, not an HR checkbox.
Identity and access programmes will feel the same pressure as IT operations. As AI enters more workflows, approval quality, exception handling, and role clarity become more important than the raw speed of automation. That creates a new programme requirement: governance must keep pace with adoption, or teams will scale inconsistency instead of capability. The practical conclusion is to tie AI rollout to identity, risk, and operating-model readiness together.
Governance strain is the leading indicator of AI maturity failure. The strongest organisations will not be the ones deploying AI fastest, but the ones that can absorb it into a controlled, teachable operating model. The article points to that reality clearly: value comes from human readiness as much as tool capability. Practitioners should read AI adoption as a maturity test for the whole identity and operations programme.
From our research library:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Security Platform Buyer's Guide
What this signals
AI adoption is now testing organisational readiness, not just technical capacity. The article shows that the biggest constraint is often the ability of teams to absorb new workflows, not the availability of AI features. For security and identity leaders, that means rollout plans should be judged by whether they reduce operational friction without weakening approvals, oversight, or exception handling.
People controls now sit alongside technical controls. Training, role clarity, and accountability are becoming part of the execution model for AI-enabled operations. When 63% of companies require AI training, the signal is that organisations are starting to formalise competence as a condition for safe adoption. That same discipline should be applied wherever AI affects access, review, or policy enforcement.
For practitioners
- Build AI workflow readiness plans Map where AI changes day-to-day approvals, exception handling, and escalation paths before expanding use across IT operations.
- Tie AI training to governance tasks Train teams on the specific responsibilities they will carry, including validation, risk escalation, compliance review, and output challenge.
- Measure workflow friction and control drift Track where AI makes work faster but increases rework, ambiguity, or manual overrides, because those are early signs that governance is lagging.
- Define accountability for AI-assisted decisions Assign clear ownership for decisions that involve AI recommendations so staff know who signs off, who reviews, and who is accountable when outcomes fail.
Key takeaways
- AI is improving IT productivity, but it is also increasing the complexity of operating model decisions and governance oversight.
- The evidence points to a combined skills and workflow problem, with half of IT teams struggling to integrate AI into existing processes and 46% worried about risk and compliance.
- The practical response is to treat training, accountability, and workflow design as part of AI control maturity rather than as separate enablement activities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST AI RMF and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about organisational readiness, accountability, and oversight for AI adoption. |
| Recommendation — Define AI governance ownership, decision rights, and training expectations before expanding AI use. | ||
| NIST CSF 2.0 | GV.RR-01 — Roles, Responsibilities, and Authorities | The article centres on role clarity, training, and operational responsibility during AI adoption. |
| PR.AT-01 — Awareness and Training | Training is presented as a prerequisite for safe AI adoption across the workforce. | |
| GV.RM-01 — Risk Management Strategy | Risk, compliance, and legal exposure are named as major barriers to AI adoption. | |
| Recommendation — Assign clear roles and escalation paths for AI-assisted decisions and workflow changes. Build role-based training for AI use, validation, and exception handling into the programme. Integrate AI-related risk, compliance, and legal exposure into the organisation's risk strategy. | ||
| ISO/IEC 42001:2023 | 4.2 — Understanding the needs and expectations of interested parties | The article emphasises organisational expectations, capability, and governance around AI adoption. |
| Recommendation — Translate stakeholder expectations into AI operating requirements and accountability. | ||
Key terms
- AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
- Workflow integration: Workflow integration is the connection of credential management with identity, HR, ticketing, and physical access systems so changes propagate consistently. The security value depends on whether the integration preserves approvals, revocation triggers, and log integrity rather than simply moving data faster.
- Operational readiness: The point at which a person can apply knowledge reliably in live workflows. It is more than awareness or course completion. Operational readiness means the individual can make repeatable decisions, follow policy under pressure, and act consistently enough for the organisation to rely on their output.
- AI-assisted decisioning: AI-assisted decisioning is the use of machine learning or generative models to inform or automate risk judgments. For fraud programmes, the key issue is not whether AI is used, but whether its outputs are explainable, tunable, and governed with clear escalation paths when the model is wrong.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or security programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org