By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: CyberhavenPublished July 24, 2026

TL;DR: Enterprise AI use is moving away from chat interfaces toward agentic applications on the endpoint, while data movement into and out of GenAI SaaS rose 80% year over year and Claude desktop agent adoption grew 1,233% in six months, according to Cyberhaven. The governance problem is no longer adoption alone, but unmanaged AI pathways that expand data exposure and workflow risk.


At a glance

What this is: This whitepaper tracks mid-year enterprise AI adoption and finds that endpoint agentic AI and data movement are rising faster than traditional GenAI usage.

Why it matters: It matters because IAM, data security, and endpoint teams now need controls for AI-enabled workflows, not just approved applications and user access.

By the numbers:

👉 Read Cyberhaven's 2026 AI Adoption & Risk Report mid-year update


Context

Enterprise AI adoption is no longer confined to chat-based interfaces. The security issue is shifting toward endpoint-hosted assistants and agentic applications that can move data, trigger workflows, and blur the boundary between approved user activity and machine-driven action.

For identity and data governance teams, that shift creates a new control problem: access is no longer only about who signed in, but also what the AI-enabled workflow can see, move, and retain. That makes visibility, policy enforcement, and least privilege relevant across human identity, NHI governance, and endpoint control.

The report’s starting point is typical of the current market. Most organisations are seeing AI adoption spread faster than their governance model has adapted, especially where employees can use consumer GenAI SaaS tools or desktop agents outside centrally managed controls.


Key questions

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring. The control set should include inventory, task-bound credentials, audit trails, and revocation paths. If an agent can call tools or touch production systems, it belongs in the same governance model as service accounts and other machine identities.

Q: Why do endpoint agentic AI tools create more governance risk than chat-only GenAI?

A: Endpoint agentic AI can act inside a user’s session, move data, and trigger downstream actions, which expands the effective privilege boundary. Chat-only tools may still create data risk, but agents can combine access and action in ways that are harder to see and easier to over-scope. That makes workflow control and telemetry more important than simple application approval.

Q: What do organisations get wrong about AI observability?

A: They often confuse technical telemetry with governance evidence. Dashboards can show latency, throughput, and error rates, but that does not prove the AI system stayed within approved data, policy, or accountability boundaries. Effective observability must capture the decision path, not just the system status.

Q: How do NHI controls apply to AI-enabled workflows?

A: If an AI system authenticates to storage, code, or collaboration services, it should be governed like any other non-human identity. That means clear ownership, least privilege, lifecycle review, and rapid revocation when the workflow changes. Without those controls, the AI tool can outlive its business purpose and keep access that no one is actively supervising.


Technical breakdown

Why endpoint agentic AI changes the control surface

Endpoint agentic AI changes the control surface because the application is not just producing text, it is acting within a user’s session and data environment. That means the security question is no longer limited to prompt quality or model accuracy. It becomes a control issue around data access, action scope, and tool interaction. When an AI assistant can read files, move content, or invoke downstream services, the effective privilege boundary shifts from the human user alone to the combined human-plus-agent workflow. This is where identity and access management meets data handling and endpoint governance.

Practical implication: define which endpoint AI tools are allowed to access which data classes and system actions.

How data movement events expose hidden AI workflow risk

Data movement events are useful because they show the operational path of information into and out of GenAI services rather than just counting logins. A spike in these events often indicates employees are pasting, uploading, or synchronising content into AI tools that sit outside normal data controls. That creates risk even when the AI use itself appears benign. The governance gap is usually not one of intent but of observability. Organisations may know AI is being used, but not whether regulated, confidential, or high-value content is being transferred through unmanaged channels.

Practical implication: monitor AI-related data transfer paths as a distinct telemetry stream, not as general web traffic.

What tool sprawl means for AI governance and NHI controls

Tool sprawl means the enterprise is not dealing with one AI product, but a growing set of assistants, plugins, browser add-ons, and endpoint agents with different permission models. Each new tool introduces its own identity, token, and policy boundary, which is why NHI governance becomes relevant even in an endpoint report. Any AI workload that authenticates to data sources or acts on behalf of a user effectively becomes a non-human identity problem as well as an endpoint problem. Without inventory and lifecycle control, organisations cannot tell which AI tools remain active, what they can reach, or who owns them.

Practical implication: inventory AI tools with the same discipline used for service accounts, tokens, and other NHIs.


Threat narrative

Attacker objective: The attacker objective in this pattern is to gain access to sensitive enterprise data through legitimate-looking AI workflows and move it beyond normal control boundaries.

  1. Entry occurs when employees adopt GenAI SaaS applications and endpoint agentic tools outside tightly governed workflows, creating multiple uncontrolled access paths into enterprise data.
  2. Escalation follows when those tools receive broader read or write permissions than the human task actually requires, allowing data to move across applications and services.
  3. Impact is the expansion of workflow risk, where sensitive information leaves approved boundaries and the organisation loses practical control over where AI-enabled actions place that data.

NHI Mgmt Group analysis

AI adoption is becoming an endpoint governance problem, not just an application selection problem. The report shows that adoption is shifting toward autonomous and agentic tools on the endpoint, which means the security boundary now sits inside daily work rather than around a discrete platform. That weakens older assumptions that approved SaaS access alone equals managed risk. Practitioners should treat endpoint AI as part of the access model, not a separate productivity layer.

Data movement through AI creates a visibility gap that conventional SaaS governance does not close. Counting users of GenAI tools tells only part of the story. The more material issue is what data is being transferred into and out of those tools, because that is where confidential content, regulated data, and business context leave normal controls. The named concept here is AI data path sprawl: the spread of unmanaged routes through which data enters AI systems and then returns to the enterprise in altered form. Security teams need to govern those routes explicitly.

AI tool sprawl is also an NHI problem because many of these tools operate with their own credentials, tokens, and delegated access. Once an AI application can authenticate to storage, code repositories, or collaboration systems, it behaves like a machine identity with its own lifecycle risks. That creates the same governance requirements the industry already applies to service accounts and API keys: inventory, ownership, scoping, and revocation. Practitioners should stop treating every AI control issue as a user training problem.

The rise of desktop agents validates the move toward least privilege at the workflow level. Traditional IAM often focuses on accounts and roles, but agentic AI can combine multiple permissions across one task. That makes task scoping and policy enforcement more important than broad user entitlement reviews. The practical consequence is a shift from static approval to context-aware governance across identity, data, and endpoint controls.

Security leaders should expect AI governance to converge with DLP, endpoint, and NHI programmes. The report’s trend lines suggest the next control stack will need to follow data, not just users, and to understand which machine-operated tools are acting on behalf of people. That convergence is where policy, observability, and ownership will determine whether AI adoption stays manageable. Practitioners should align AI oversight with existing identity and data governance rather than create a detached AI exception process.

What this signals

AI data path sprawl: the next governance failure is likely to come from unmanaged routes between employee workflows and AI services, not from a single high-profile model event. Security leaders should assume that data will increasingly move through multiple endpoint AI tools before it is visible in central monitoring, which makes control-by-application insufficient.

The practical response is to align endpoint policy, DLP, and NHI lifecycle management around AI-mediated actions. Organisations that can inventory agent identities, trace data movement, and revoke delegated access quickly will be better positioned than those still treating AI as an isolated productivity layer.


For practitioners

  • Inventory endpoint AI tools and delegated access paths Build a live register of GenAI SaaS, desktop agents, browser extensions, and plugins that can reach enterprise data. Include the credentials, tokens, and permissions each tool uses so ownership and revocation are explicit.
  • Separate AI data movement telemetry from standard web logging Track uploads, copy operations, sync events, and API transfers into AI services as a distinct control signal. This makes it easier to spot sensitive content leaving approved channels before it becomes a broader data governance issue.
  • Apply least privilege to AI-enabled workflows Limit each AI tool to the smallest set of files, repositories, and downstream actions needed for the task. Where possible, isolate high-risk tasks into tightly scoped service identities instead of broad user sessions.
  • Add AI tools to NHI lifecycle controls Treat agent identities, API keys, and service tokens used by AI systems as governed non-human identities. Require ownership, expiration, review, and revocation workflows so dormant access does not persist after tool changes.
  • Reconcile DLP and endpoint policy with AI usage Update data loss prevention and endpoint policy to recognise GenAI prompt traffic, agent actions, and file transfers. Existing controls often miss the business context of AI-mediated movement, which leaves gaps in enforcement and response.

Key takeaways

  • Enterprise AI risk is shifting from chat interfaces to endpoint agents that can move data and act inside user workflows.
  • The most material signal in this report is not adoption alone but the sharp rise in data movement through GenAI services.
  • Security teams need to govern AI tools as access-bearing systems, with lifecycle control, data-path visibility, and least privilege.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4AI workflow access and delegated permissions map to least-privilege access management.
NIST SP 800-53 Rev 5AC-6Least privilege is central when AI tools can act on behalf of users.
NIST AI RMFGOVERNAI adoption governance needs ownership, accountability, and policy oversight.
OWASP Agentic AI Top 10Endpoint agents and AI workflow risk align with agentic application governance concerns.
MITRE ATT&CKTA0009 , Collection; TA0010 , ExfiltrationThe article centres on data movement through AI services and potential information transfer abuse.

Map AI-enabled workflows to PR.AC-4 and scope each tool to the minimum data and actions required.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Data movement event: A data movement event is any user action that transfers information from one controlled context to another, such as pasting text or uploading a file. In Shadow AI scenarios, treating these actions as governed events helps security teams connect identity, content, and policy.
  • AI Data Path Sprawl: The accumulation of unmanaged routes through which data enters AI systems and returns to the enterprise. It describes the governance gap created when multiple AI tools, plugins, and agents handle information in ways that are difficult to observe, classify, or revoke.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.

What's in the full report

Cyberhaven's full report covers the operational detail this post intentionally leaves for the source:

  • Breakdowns of how GenAI SaaS adoption differs from endpoint agent adoption across the mid-year dataset.
  • The underlying measurement approach for data movement events into and out of AI services.
  • Practical examples of how the report interprets workflow risk as AI usage shifts beyond chat.
  • The specific readouts behind the 1,233% rise in Claude desktop agent adoption.

👉 Cyberhaven's full PDF includes the adoption data, risk framing, and source charts behind these findings.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, agentic AI identity, machine identity security, and secrets management. It gives security practitioners a practical way to connect identity controls to the broader security programme.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org