By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: CyberhavenPublished March 12, 2026

TL;DR: AI usage is spreading across GenAI SaaS apps, endpoint AI applications, and AI agents while governance and visibility lag, with employees also using personal and unmanaged environments, according to Cyberhaven’s manufacturing-focused 2026 AI Adoption & Risk Report. The result is a fragmented control surface where data exposure rises faster than security teams can see or govern it.


At a glance

What this is: This is Cyberhaven’s manufacturing-sector analysis of how AI adoption is fragmenting across tools, accounts, and environments while governance and visibility fall behind.

Why it matters: It matters because manufacturing security teams now have to govern AI use as both a data exposure problem and an identity control problem across sanctioned and unmanaged environments.

By the numbers:

👉 Read Cyberhaven's manufacturing report on AI adoption and risk


Context

AI adoption in manufacturing is no longer a simple question of whether employees are using approved tools. The real issue is that usage is splitting across GenAI SaaS apps, endpoint AI applications, personal accounts, unmanaged environments, and AI agents, which makes conventional visibility and policy enforcement incomplete from the start.

That creates a governance gap that sits at the intersection of AI security, data security, and identity control. When AI access is spread across multiple accounts and environments, security teams lose the ability to answer basic questions about who or what is acting, where sensitive data is going, and which controls actually apply.


Key questions

Q: What breaks when AI adoption spreads across unmanaged tools and accounts?

A: Governance breaks first. Once AI use spans SaaS apps, endpoints, personal accounts, and shadow environments, security teams lose a reliable inventory of where data flows and who is accountable. The result is inconsistent policy enforcement, weaker monitoring, and a control model that cannot keep pace with real usage patterns.

Q: Why do AI data leakage loops create identity and access risk?

A: Because retrieval-augmented AI systems can reach data on behalf of a user, the access boundary moves into the AI workflow itself. If identity checks are weak at query time, the system can reveal information outside the user’s normal permission scope. That makes least privilege and context-aware authorisation central to AI governance.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: How should manufacturing organisations respond when AI use moves into personal or unmanaged environments?

A: They should not assume policy alone will solve it. Start with discovery, then separate low-risk experimentation from workflows that handle sensitive data. For high-risk use, restrict access, require approved accounts, and route AI activity into the same monitoring and review discipline used for other privileged systems.


Technical breakdown

Fragmented AI usage creates a governance blind spot

In manufacturing environments, AI is not one workload. It is a mix of SaaS tools, endpoint applications, and agentic systems used by employees across managed and unmanaged contexts. That fragmentation breaks the assumption that security teams can govern AI through a single approved platform or a single policy set. Once usage spans personal accounts and shadow environments, visibility becomes partial and control ownership becomes ambiguous. The result is not just more tools, but more untracked data movement and more opportunities for policy drift.

Practical implication: map AI usage by account, tool, and environment before trying to standardise controls.

Why AI agents behave like identity and access problems

AI agents are not just applications with smarter interfaces. They can initiate actions, use tools, and move data in ways that resemble privileged system identities, especially when they operate across workflows without consistent human supervision. That means their risk profile overlaps with IAM, PAM, and secrets governance. If an agent can access files, APIs, or production systems, it needs explicit scoping, logging, and lifecycle controls. Treating agentic AI as ordinary software leaves an identity gap in the control model.

Practical implication: define access boundaries for AI agents the same way you would for high-risk non-human identities.

Data exposure increases when AI access is disconnected from policy

The central security issue in this report is not AI adoption itself. It is the mismatch between how quickly data moves into AI-supported workflows and how slowly policy, monitoring, and retention controls adapt. In manufacturing, where operational, design, and commercial data often converge, even ordinary employee use of AI can create unintended disclosure paths. Without classification-aware controls and monitoring, data leaves trusted boundaries through legitimate-looking interactions, which is harder to detect than a conventional exfiltration event.

Practical implication: align AI governance with data classification, DLP, and access review processes rather than treating it as a standalone initiative.


Threat narrative

Attacker objective: The practical objective is not necessarily intrusion, but unauthorized access to sensitive manufacturing data through normal-looking AI usage paths.

  1. Entry occurs when employees begin using GenAI SaaS apps, endpoint AI tools, or AI agents across managed and unmanaged environments without central oversight.
  2. Escalation happens when those tools are granted access to files, prompts, accounts, or workflows that expose sensitive manufacturing data beyond intended business use.
  3. Impact follows when data moves through AI interactions faster than policy and monitoring can constrain it, creating persistent exposure and weak accountability for where information goes.

NHI Mgmt Group analysis

AI adoption has become a governance distribution problem, not a deployment problem. The report shows that AI usage is no longer concentrated in a few approved systems. It is spread across SaaS apps, endpoints, personal environments, and emerging agents, which means security teams are governing a moving target rather than a bounded platform. That changes the operating model for AI oversight and makes inventory discipline the first control plane.

Manufacturing now faces an AI visibility gap that mirrors classic NHI sprawl. When multiple accounts and unmanaged environments are part of daily AI usage, the organisation loses line-of-sight over both the actor and the data path. That is structurally similar to other non-human identity problems: the issue is not only access, but unsanctioned reach and poor lifecycle visibility. Practitioners should treat AI usage discovery as part of identity governance, not just cloud or endpoint monitoring.

Data security posture management becomes more effective when it is tied to AI identity boundaries. If AI systems and agents can move data, then controlling data without controlling the identities behind those interactions leaves an enforcement gap. This is where data security, IAM, and NHI governance converge. The manufacturing sector should expect AI controls to move from policy documents to enforceable access boundaries, with classification, logging, and approval workflows tied together.

Shadow AI should be treated as an unmanaged access channel, not only an acceptable-use issue. The report’s emphasis on personal and unmanaged environments shows that some of the highest-risk AI activity will never appear in traditional IT inventories. That makes discovery and entitlement review more important than broad tool bans. If an organisation cannot identify where AI is being used, it cannot reliably govern disclosure, retention, or accountability.

Agentic AI governance will increasingly borrow from NHI controls. AI agents that can act across workflows behave less like static software and more like non-human identities with a lifecycle, privileges, and audit requirements. That is the named concept here: AI governance debt, meaning the control gap that forms when adoption outruns policy, ownership, and inspection. Manufacturers should assume this debt grows until they assign explicit identity-style governance to AI systems.

What this signals

AI governance debt is now a programme risk. In environments where adoption moves faster than policy, teams accumulate controls they cannot operationalise. That pushes AI oversight into the same category as other identity governance failures: the organisation may have rules, but not enough enforcement fidelity to make them meaningful. Security leaders should expect AI inventory, ownership, and entitlement scoping to become board-level questions, especially where sensitive manufacturing data is involved.

The practical shift is toward combining discovery, data controls, and identity controls in one operating model. A manufacturing programme that cannot tell which AI systems are acting, which accounts they use, and which data they can reach will struggle to prove governance is effective. That is why AI security is converging with NHI governance, DLP, and access review workflows rather than remaining a standalone AI initiative.


For practitioners

  • Build a complete AI usage inventory Discover where employees are using GenAI SaaS apps, endpoint AI tools, personal accounts, and AI agents. Classify each by business function, data sensitivity, and whether it sits inside a managed control domain or a shadow environment.
  • Define identity boundaries for AI agents Treat AI agents as governed entities with explicit access scopes, logging, and offboarding rules. If an agent can reach files, APIs, or workflow systems, restrict it with the same discipline used for high-risk non-human identities.
  • Align AI governance with data classification Map which data classes are allowed into AI workflows and enforce those rules through DLP, access review, and monitoring. Focus first on design files, operational data, and commercially sensitive content that often appears in manufacturing workflows.
  • Close the shadow AI oversight gap Create a review process for personal and unmanaged AI use, then route exceptions into policy or containment decisions. Tie discovery to endpoint, SaaS, and identity telemetry so unmanaged AI activity does not remain invisible.

Key takeaways

  • Manufacturing AI adoption is fragmenting across tools and environments faster than security teams can govern it.
  • The main risk is not AI use itself but uncontrolled access paths that expose sensitive data through ordinary workflows.
  • Effective response means treating AI systems and agents as governed identities, with discovery, access boundaries, and lifecycle controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNAI governance and accountability are the report's core themes.
OWASP Agentic AI Top 10Agentic AI use and unmanaged AI workflows create identity and control risks addressed here.
OWASP Non-Human Identity Top 10NHI-01Unmanaged AI systems function like non-human identities with privilege and lifecycle concerns.
NIST CSF 2.0PR.AC-1Access control and identity governance are needed for AI tools and data paths.
NIST SP 800-53 Rev 5AC-6Least privilege is directly relevant to AI systems that can reach sensitive data and workflows.

Assign ownership for AI use cases, approval paths, and oversight before adoption spreads further.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

What's in the full report

Cyberhaven's full report covers the operational detail this post intentionally leaves for the source:

  • Tool-by-tool breakdown of where AI adoption is concentrating across manufacturing environments
  • Data exposure patterns by usage type, including GenAI SaaS apps, endpoint AI, and AI agents
  • Practical context for security leaders deciding how to prioritise governance controls
  • Industry-specific findings that help compare managed, unmanaged, and personal AI usage

👉 The full Cyberhaven report covers manufacturing-specific usage patterns and exposure detail

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and workload identity. It gives security practitioners a practical foundation for extending identity discipline into AI and other non-human systems.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org