By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: CyberhavenPublished March 12, 2026

TL;DR: AI use is spreading across GenAI SaaS, endpoint AI applications, and AI agents while oversight remains fragmented, according to Cyberhaven’s 2026 AI Adoption & Risk Report for professional services. Its companion blog notes Claude Desktop usage grew 1,233% in six months alongside an 80% rise in GenAI SaaS data movement, and the governance gap is now a data exposure problem, not a future planning issue.


At a glance

What this is: This report shows that AI adoption in professional services is broadening across sanctioned and unmanaged environments while governance and visibility lag behind.

Why it matters: It matters because AI usage now intersects with identity, access, and data handling, forcing IAM, security, and governance teams to account for tools, accounts, and agents outside traditional control boundaries.

By the numbers:

👉 Read Cyberhaven's 2026 AI Adoption & Risk Report for professional services


Context

AI adoption in professional services is no longer a single-tool rollout. It is a distributed access problem, with employees using GenAI SaaS apps, endpoint AI applications, and AI agents across personal and unmanaged environments. That matters to IAM and governance teams because every new tool, account, and workflow expands the identity and data perimeter.

The central issue is not whether organisations use AI, but whether they can govern who and what can access sensitive data as usage fragments. In practice, that brings AI governance into contact with identity lifecycle, secrets management, and access oversight, especially where AI agents operate outside conventional approval paths.


Key questions

Q: What breaks when employees use unapproved AI tools with company data?

A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused. Unapproved tools can copy credentials into unmanaged workflows, which weakens revocation and makes audit trails incomplete. The result is shadow access outside the main identity programme.

Q: Why do local AI agents complicate identity and access management?

A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence. That means the visible identity may remain stable even as the operational behaviour becomes autonomous. IAM teams then lose the simple link between user session, authorisation, and accountability.

Q: What do security teams get wrong about AI governance reviews?

A: They often treat every use case as if it needs the same level of scrutiny. That creates bottlenecks and does not reflect actual risk. Effective governance separates routine, low-risk activity from higher-risk systems and uses runtime controls for interactions that can be governed continuously instead of repeatedly reviewed.

Q: How can organisations reduce data exposure in AI tools?

A: Start with data classification, then map where sensitive information can flow into prompts, connectors, and logs. Limit AI systems to the minimum data they need, require owner approval for higher-risk datasets, and monitor for unsanctioned sharing. Data controls work best when paired with identity controls and usage visibility.


Technical breakdown

Fragmented AI usage creates governance blind spots

Professional services firms rarely adopt AI through a single managed channel. Instead, usage spreads across SaaS applications, desktop tools, browser-based copilots, and agentic workflows, often with separate accounts and inconsistent policy enforcement. That fragmentation makes inventorying AI harder than tracking a normal application estate because the control point is no longer just the application. It is the identity behind each tool, session, and delegation path. Once those paths cross personal devices or unmanaged environments, visibility drops sharply and governance becomes partial at best.

Practical implication: build a complete inventory of AI tools, accounts, and agent paths before attempting policy enforcement.

AI agents change the identity problem, not just the application problem

An AI agent is not merely a tool with automation attached. It is a software entity that can make runtime decisions, choose actions, and interact with other systems. That means the security question becomes who authorised the agent, what it can reach, and how its privileges are bounded over time. If the organisation treats an agent like a normal application account, it will miss the governance controls needed for delegation, scope limitation, and lifecycle management. This is where agentic AI begins to intersect directly with NHI governance.

Practical implication: assign explicit ownership and lifecycle controls to agent identities, not just the systems they touch.

Data exposure follows access, not intention

AI governance fails when sensitive data can move into tools that were never brought under formal oversight. In professional services, that risk is amplified because employees routinely handle client, legal, financial, and operational information. Once data enters unmanaged AI environments, retention, reuse, and downstream exposure become difficult to control. This is not only a data security issue. It also becomes an identity problem because the original access decision, often made casually or informally, determines the exposure boundary.

Practical implication: connect AI usage controls to data classification and access policy, not to acceptable-use statements alone.


Threat narrative

Attacker objective: The practical outcome is unauthorized access to sensitive professional services data through unmanaged AI usage and weak governance boundaries.

  1. Entry occurs when employees adopt sanctioned and unsanctioned AI tools across personal and unmanaged environments, creating multiple access paths outside central oversight.
  2. Escalation follows when those tools, accounts, or agents reach sensitive data without consistent policy enforcement, lifecycle control, or approval boundaries.
  3. Impact is data exposure across fragmented AI workflows, with security teams losing visibility into where information is copied, processed, or retained.

NHI Mgmt Group analysis

AI governance debt is now an access-control problem. The report shows AI adoption widening faster than governance can keep pace, which means the issue is not simply policy lag. It is a mismatch between how quickly employees can adopt tools and how slowly organisations can assert control over accounts, permissions, and data movement. For security leaders, the practical conclusion is that AI governance must be treated as part of access governance, not a separate policy exercise.

Fragmented tool adoption creates a new control surface for NHI governance. When employees use multiple AI tools and environments, each integration, token, and delegated workflow can behave like a non-human identity in practice. That creates a governance burden similar to other machine-access problems: ownership, scope, expiration, and monitoring all matter. The field should expect AI programmes to expose the same weaknesses seen in NHI sprawl. Practitioners should therefore extend identity governance to AI-connected accounts and service paths.

Data exposure in AI programmes is usually a policy failure before it is a technical one. The report’s framing makes clear that sensitive information reaches AI systems because usage is ahead of control design. That means the decisive failure mode is not lack of sophistication in the model. It is lack of boundary-setting around what data can be shared, where, and by whom. Security teams should treat AI data handling rules as enforceable control points, not guidance documents.

Professional services is an early warning sector for broader enterprise AI risk. The combination of distributed knowledge work, client confidentiality, and fast tool adoption makes governance gaps visible sooner here than in many other sectors. What appears as an adoption story is actually a preview of how AI use will strain identity and data control elsewhere. Practitioners should assume the same governance pattern will spread across knowledge-worker organisations unless access, lifecycle, and data controls are aligned early.

What this signals

AI adoption is creating a control problem that looks different from classic SaaS sprawl because the identity behind the workflow may be an employee, a personal account, a token, or an AI agent. That is why governance teams should look at AI usage through the same lens they use for NHIs: ownership, scope, expiry, and monitoring. The [Ultimate Guide to NHIs , Key Challenges and Risks](https://nhimg.org/the-ultimate-guide-to-non-human-identities#key-challenges-and-risks) remains relevant because visibility gaps are now appearing in AI-connected workflows as well.

AI governance debt: this is the gap between how quickly workers adopt AI and how slowly controls are formalised. Organisations that already struggle with identity lifecycle management will feel the pressure first because every unmanaged AI path becomes another entitlement path. Mapping this to the NIST Cybersecurity Framework 2.0 helps teams align governance, protection, and detection without treating AI as a separate security silo.

Professional services teams should expect shadow AI to become a recurring audit issue before it becomes a headline breach. The practical next step is to pair access reviews with data classification checks, especially where client and regulated data are involved. For teams extending identity discipline into AI, the [Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs](https://nhimg.org/the-ultimate-guide-to-non-human-identities#lifecycle-processes-for-managing-nhis) is the most direct operational reference.


For practitioners

  • Inventory AI tools, accounts, and agent paths Create a live register of sanctioned and unsanctioned AI tools, the identities tied to them, and the data they can reach. Include personal accounts, browser-based access, and embedded AI features so governance is based on actual use rather than approved software lists. Use the inventory to identify unmanaged access paths.
  • Apply identity lifecycle controls to AI agents Assign each AI agent an owner, a defined purpose, a scoped permission set, and an expiry or review point. Treat tokens, connectors, and delegated credentials as lifecycle items that require review and offboarding. This is especially important where agents reach client or regulated data.
  • Link AI access rules to data classification Set policy so sensitive data cannot be copied into AI tools unless the tool, account, and workflow are approved for that data class. Enforce this at the point of use, not only through training or acceptable-use notices. Align the rule set with the organisation’s data handling and retention controls.
  • Monitor unmanaged AI usage as a governance signal Track usage patterns that indicate shadow AI, such as personal accounts, browser extensions, and unsanctioned desktop tools. Treat these signals as evidence that governance boundaries are being bypassed and that access policy needs adjustment. Bring the findings into IAM, data security, and compliance reporting.

Key takeaways

  • AI adoption in professional services is widening faster than governance, creating a control gap across tools, accounts, and agentic workflows.
  • The core risk is data exposure through unmanaged access paths, not simply increased AI usage.
  • Security teams need to extend identity lifecycle, data classification, and monitoring controls into AI adoption before shadow usage becomes normalised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNAI governance and accountability are central to the report's control gap.
NIST CSF 2.0PR.AC-4The report is fundamentally about access control drift across AI tools and accounts.
OWASP Agentic AI Top 10The article touches agentic workflows and delegated runtime behaviour.
NIST SP 800-53 Rev 5AC-6Least privilege is directly relevant when AI tools can reach sensitive data.
ISO/IEC 27001:2022A.5.15Access control governance is directly implicated by unmanaged AI usage.

Define ownership for AI use, approve boundaries, and document accountability for tools and agents.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Credential Exposure Boundary: The point in an authentication journey where a secret, token, or reusable credential can first be observed or handled by client-side code. In practice, this boundary determines how much trust you place in the application, browser, or device environment.

What's in the full report

Cyberhaven's full report covers the operational detail this post intentionally leaves for the source:

  • The full report's tool-by-tool adoption patterns across GenAI SaaS, endpoint AI applications, and AI agents
  • The data exposure detail behind the report's governance findings, including where the biggest movement is occurring
  • The mid-year update context for teams tracking adoption shifts and policy drift over time
  • The companion blog on agent containment and the OpenAI-Hugging Face breach

👉 Cyberhaven's full report covers the adoption patterns, exposure trends, and governance signals in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle control. It helps security practitioners build the access and lifecycle discipline needed when AI tools, tokens, and agents start behaving like operational identities.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org