By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: CyberhavenPublished March 12, 2026

TL;DR: AI adoption is accelerating across GenAI SaaS, endpoint AI apps, and AI agents, while governance and visibility lag behind, creating uneven exposure patterns across organisations, according to Cyberhaven’s 2026 financial services report. The core problem is not AI use itself, but fragmented control over accounts, tools, and data paths.


At a glance

What this is: This report maps how AI adoption is concentrating in financial services and finds that usage is spreading faster than AI governance, visibility, and control.

Why it matters: It matters because identity, access, and data teams need to govern AI use across sanctioned tools, unmanaged environments, and emerging agent workflows before exposure becomes routine.

By the numbers:

👉 Read Cyberhaven's report on AI adoption and risk in financial services


Context

AI adoption in financial services is expanding across sanctioned software, endpoint applications, and agentic workflows, but governance is not expanding at the same speed. That gap creates a familiar security pattern: usage becomes distributed faster than teams can see, classify, and constrain it. For identity security leaders, the relevant issue is not simply AI uptake, but where access is granted, how data moves, and which identities now operate outside traditional oversight.

The article points to a broader governance problem that sits between data security, identity controls, and AI oversight. When employees use multiple AI tools and accounts, including unmanaged environments, the organisation loses a stable view of who or what is accessing sensitive information. That makes AI usage a governance and access-control issue, not just an innovation or productivity issue. In financial services, that starting position is increasingly typical rather than exceptional.


Key questions

Q: What breaks when AI adoption outpaces governance?

A: What breaks first is attribution. Teams lose visibility into which tools are in use, which data they can reach, and which actions were taken automatically versus manually. Once adoption is ahead of control design, security teams end up retrofitting policy around live workflows instead of governing them from the start.

Q: Why do AI agents complicate traditional IAM and PAM controls?

A: AI agents complicate IAM and PAM because they can make decisions, chain tools, and act faster than human review cycles can respond. They also blur the line between authentication and authorization, since the same identity may trigger multiple actions after a single approval. That means organizations need policy, telemetry, and revocation designed for autonomous behavior, not just human login events.

Q: What do security teams get wrong about agentic AI security tools?

A: The most common mistake is treating agentic AI security as an extension of an existing category such as NHI, endpoint, or DSPM. That view misses the fact that agents operate across multiple deployment patterns and require both posture controls and runtime response. A narrow tool can be useful, but it is not comprehensive governance.

Q: How can organisations tell whether AI governance is actually working?

A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.


Technical breakdown

Why fragmented AI usage breaks visibility

AI usage fragments quickly because employees do not treat it as a single system. They use GenAI SaaS apps, endpoint AI applications, browser-based assistants, and embedded agents, often across both managed and personal environments. Each of those paths creates a different identity surface, different logging quality, and different data-handling risk. Traditional IT visibility assumes software is inventoried and access is centrally managed. AI usage often bypasses that assumption, which means security teams see outcomes after the fact rather than the access path that enabled them.

Practical implication: security teams need inventory and telemetry that distinguish sanctioned AI use from unmanaged AI use before policy enforcement can work.

How AI agents change the identity and access model

AI agents are not just another application category because they can act on data and tools in ways that resemble delegated access. That makes them relevant to NHI governance, since an agent may operate with tokens, service accounts, or API credentials that outlive a single interaction. If those identities are not scoped, monitored, and lifecycle-managed, the organisation inherits an access model that is faster than review processes. This is where AI governance intersects with IAM and PAM: the question becomes which identity is acting, under what authority, and for how long.

Practical implication: classify AI agents and their credentials as governed identities, not as generic software features.

Why data exposure becomes the downstream control failure

Once AI tools sit inside ordinary work patterns, data exposure is often the downstream symptom of a governance failure upstream. Sensitive content can flow into prompts, outputs, logs, browser sessions, or connected applications without a clear boundary between approved and unapproved use. In regulated environments, that creates accountability questions around data classification, permitted processing, and retention. The operational problem is that data controls cannot be effective if the organisation does not know which identities and tools are touching the data in the first place.

Practical implication: align AI governance with data classification and access policy so exposure controls follow the identity, not just the application.


Threat narrative

Attacker objective: The likely outcome is uncontrolled sensitive data exposure through AI workflows that security teams cannot reliably see or govern.

  1. Entry occurs when users adopt GenAI SaaS apps, endpoint AI tools, or agents outside tightly governed deployment paths.
  2. Escalation happens as those tools gain access through personal accounts, unmanaged environments, or broadly scoped credentials.
  3. Impact follows when sensitive financial data moves through prompts, outputs, logs, or connected systems without consistent oversight.

NHI Mgmt Group analysis

AI governance debt is becoming an access-control problem. The article shows that AI adoption can outpace the organisation’s ability to classify and constrain it, which is a familiar governance failure in a new form. When usage spreads across tools, accounts, and unmanaged environments, the real gap is not policy absence but policy unenforceability. Practitioners should treat AI governance as an access and lifecycle discipline, not a branding layer over existing controls.

AI agents are converging with non-human identity governance. Once agents act on behalf of users or processes, they create the same governance questions that service accounts and tokens already raise: who owns them, what can they reach, and when do they expire? That makes NHI controls directly relevant to AI adoption programmes, especially in financial services where data sensitivity and auditability are central. The practitioner takeaway is to govern agent identities before they become embedded in production workflows.

Unmanaged AI use creates a verification trust gap. Organisations assume that approved tools and approved users define the boundary of safe use, but distributed AI adoption breaks that assumption. If employees can move between sanctioned and unsanctioned environments without clear verification, the security function loses the ability to enforce consistent handling of sensitive data. The result is a control environment that can look mature on paper while remaining porous in practice.

Financial services will need policy that follows the data path, not just the app list. This report reinforces that AI risk is shaped by how information moves across tools and identities. Data security, IAM, and AI governance now intersect at the same operational decision point: what is allowed to touch regulated information, and under what authority. Practitioners should expect board and audit scrutiny to move from generic AI policy statements to evidence of enforceable control over actual usage.

Standards alignment will matter more as AI adoption becomes operationalised. The governance questions raised here map naturally to NIST AI RMF, NIST CSF, and NHI control thinking because the problem spans accountability, monitoring, and access scope. As AI usage becomes embedded in everyday work, programmes that cannot tie policy to identity, data classification, and telemetry will struggle to prove control. The practical conclusion is that AI governance must be measurable, not aspirational.

What this signals

The immediate signal for practitioners is that AI governance now needs the same operational discipline as access governance. If security teams cannot distinguish sanctioned AI use from unmanaged AI use, policy, classification, and monitoring will not converge into a controllable programme. The control objective is to make AI activity observable, attributable, and governable across identities and environments.

Verification trust gap: when employees move between managed and unmanaged AI tools, the organisation loses confidence that sensitive data is only reaching approved processing paths. That gap is especially important in regulated sectors, where auditability and accountability matter as much as detection. The practical response is to connect AI usage telemetry to identity records and data controls, then validate exceptions against NIST Cybersecurity Framework 2.0.

As agentic workflows mature, teams should expect NHI governance to become part of AI control architecture, not a separate hygiene exercise. Agent credentials, service accounts, and tokens used by AI systems need ownership, scope limits, and lifecycle management. For practitioners, this means the next governance review should ask which AI identities exist, what they can reach, and how they are retired.


For practitioners

  • Inventory AI usage by identity and environment Separate sanctioned GenAI SaaS, endpoint AI applications, personal accounts, and AI agents into distinct telemetry and policy categories so you can see where governance breaks down. Use this inventory to identify unmanaged environments and shadow usage paths first.
  • Treat AI agents as governed identities Assign ownership, scope, expiry, and review requirements to agent credentials, API keys, and service accounts used by AI systems. Tie those identities to the same lifecycle controls you apply to other high-risk non-human identities.
  • Constrain sensitive data pathways Map where regulated or confidential information can enter prompts, logs, outputs, and connected applications, then block or monitor those flows based on classification. This is where data governance and access control need to work together.
  • Build audit evidence for AI policy enforcement Document how policy is enforced in managed tools, how unmanaged use is detected, and what control signals prove the organisation can distinguish approved AI activity from unsanctioned activity. Pair that evidence with NIST Cybersecurity Framework 2.0 reporting expectations.
  • Use NHI governance for agentic workflows Where AI tools can call services or act independently, apply NHI lifecycle controls for provisioning, monitoring, rotation, and offboarding. The Ultimate Guide to NHIs and the Lifecycle Processes for Managing NHIs are useful reference points for this control model.

Key takeaways

  • AI adoption in financial services is creating a governance gap because usage is spreading across tools and environments faster than security teams can control it.
  • The operational risk is not only AI misuse but also uncontrolled data movement and delegated access through identities that are hard to see and review.
  • Practitioners should treat AI agents, credentials, and unmanaged usage paths as governance objects, with lifecycle controls and evidence of enforcement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe article is fundamentally about AI governance and accountability.
NIST CSF 2.0PR.AC-4AI access paths and approvals hinge on least-privilege access management.
OWASP Agentic AI Top 10A2Agentic workflows and tool use create direct misconfiguration and access risks.
NIST SP 800-53 Rev 5AC-6Least privilege is essential where AI tools can reach sensitive systems or data.

Establish ownership, policy, and oversight for AI use across managed and unmanaged environments.


Key terms

  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.

What's in the full report

Cyberhaven's full report covers the operational detail this post intentionally leaves for the source:

  • Breakdowns of which AI tools and deployment models are most concentrated in financial services environments.
  • Evidence on how employee AI usage shifts across sanctioned, unmanaged, and personal environments.
  • The report's data exposure framing for security leaders who need to align AI governance with risk management.
  • Industry-specific guidance for understanding where AI adoption is accelerating fastest and where governance is falling behind.

👉 Cyberhaven's full PDF covers the financial-services-specific data behind AI usage, governance gaps, and exposure trends.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is relevant for practitioners who need to bring identity discipline to AI agents, service accounts, and other non-human identities.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org