By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Defining Your AI Governance Dream Team: Aligning Legal, Security, and IT in the Age of AI” (March 17, 2026)

TL;DR: Unapproved AI tools are already widespread, with 61% of organisations encountering unsanctioned or unmonitored use, according to JumpCloud research, while breaches involving unmanaged applications add an average of $670,000 and 97% lack basic access controls. The real gap is governance, not experimentation, and it spans IT, security, and legal ownership.


At a glance

What this is: This is a governance-focused analysis of AI agent oversight, showing that unmanaged tools and unclear ownership create security gaps that traditional controls do not close.

Why it matters: It matters because IAM, security, and legal teams now have to govern AI agents as accountable identity-bearing actors, not as informal productivity tools.

By the numbers:

  • 61% of organisations report encountering unsanctioned or unmonitored use of AI tools by employees.
  • 97% of these breaches involve a complete lack of basic access controls.

Context

AI agent governance is the set of ownership, policy, and access-control decisions that determine who can use autonomous tools, what data they can reach, and who is accountable when they misbehave. In this article, the core problem is not experimentation with AI itself but the absence of clear governance over how AI tools enter, operate within, and leave the environment.

JumpCloud frames the governance gap as an organisational issue rather than a purely technical one: IT, security, and legal each hold part of the answer, but none can govern AI safely in isolation. That matters for identity programmes because AI agents behave like non-human actors that need ownership, scoped access, and auditability from the start.

The article also ties the governance failure to measurable exposure, including unsanctioned tool use, breach cost inflation, and weak access control. For IAM leaders, that combination turns AI governance into a lifecycle and accountability problem, not just a policy exercise.


Key questions

Q: What breaks when AI agents have no clear owner?

A: Lifecycle control breaks first, followed by revocation, review, and accountability. An ownerless agent can persist after the creator leaves, keep active credentials, and continue accessing systems without anyone clearly responsible for its permissions or behaviour. That is how orphaned identities become a standing governance liability.

Q: Why do unsanctioned AI tools create the same governance problems as shadow IT?

A: Unsanctioned AI use creates shadow IT risk because users often route around restrictions when a tool is blocked. That leaves security teams chasing exception lists instead of managing the real behaviour. The core issue is loss of visibility. Once teams cannot tell what is being used, they cannot consistently apply access, data handling, or monitoring controls.

Q: How do security teams know whether an AI agent control stack is actually working?

A: Look for three things: every agent has a traceable identity, permissions are narrow enough to explain in operational terms, and actions can be audited end to end. If any of those are missing, the control stack is incomplete even if the data layer uses advanced privacy techniques. Identity, scope, and logging should all line up.

Q: Who should be accountable for enterprise AI governance?

A: Accountability should sit with a named owner for each AI system, supported by a cross-functional governance structure that includes security, legal, IT, and business leadership. The committee can coordinate decisions, but each AI use case still needs a clear operational owner for approvals and oversight.


Technical breakdown

Why AI agent ownership becomes an identity control

When an AI agent can access data, initiate actions, or interact with business systems, it behaves like a non-human identity even if the organisation did not formally model it that way. The technical issue is not the model itself but the permissions, tokens, API access, and delegated trust attached to it. If those entitlements are created without a named owner, expiry logic, or review path, the agent becomes operationally real but governably invisible. That is why AI governance and identity governance converge at the point of registration and authorisation.

Practical implication: treat every deployed AI agent as an identity object with an owner, scope, and review cadence before it is allowed to act.

Why unsanctioned AI tools bypass existing control planes

Unapproved AI tools often enter through ordinary employee workflows, not through a formal deployment pipeline. That means they can sit outside approved application inventory, security review, data classification, and access governance while still handling sensitive content. Once usage is embedded in day-to-day work, the organisation loses visibility into where data goes, which accounts are in play, and whether the tool has persistent access to corporate systems. The control failure is less about detection after the fact and more about incomplete onboarding into the governance model.

Practical implication: extend application inventory and access review coverage to AI tools that employees adopt outside sanctioned procurement paths.

How ownership, least privilege, and legal policy intersect

The article’s governance model depends on three layers working together. IT defines where the tool is allowed to connect, security constrains what it can reach, and legal defines what data may be used at all. That is a lifecycle problem because ownership must persist across approval, use, exception handling, and retirement. Without that chain, least privilege becomes a paper policy and acceptable use becomes unenforceable. The result is a system that can be technically reachable but institutionally ungoverned.

Practical implication: align AI agent ownership with least-privilege access and documented acceptable use before any production rollout.


Threat narrative

Attacker objective: The attacker objective is to exploit unmanaged AI usage or weak token governance to gain access to data and actions that should have remained controlled.

  1. Entry occurs when employees adopt unsanctioned or unmonitored AI tools outside formal governance and inventory controls.
  2. Privilege is expanded when those tools are given access to company data, APIs, or workflows without a tightly scoped owner or approval path.
  3. Impact follows when unmanaged use leads to data exposure, breach cost inflation, or compromised control over automated actions.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent governance fails first as an ownership problem, not a tooling problem: When no team is clearly accountable for an AI agent, the organisation cannot consistently assign scope, approve data use, or retire access. That breaks the basic governance chain that IAM and legal rely on to make policy enforceable. The implication is that AI governance has to be built as an accountable lifecycle, not as a loose security checklist.

Unapproved AI use creates shadow identity exposure: The article’s 61% figure points to a familiar pattern in identity security, where adoption outruns registration and control. Once an AI tool is used outside sanctioned paths, it can become a shadow actor with access that is invisible to normal review and recertification processes. Practitioners should treat unmanaged AI usage as an identity inventory gap, not just a policy violation.

Least privilege does not survive vague agent boundaries: The article describes AI systems receiving permissions, but not always the disciplined scoping that human or service-account governance would demand. That creates permission drift, especially when teams assume a tool is temporary, low-risk, or isolated. The practical conclusion is that AI agent permissions need the same lifecycle discipline as other non-human identities.

Governance fragmentation is the real control weakness: IT, security, and legal each own a piece of the response, but the breach surface grows when those pieces are not stitched into one operating model. The article is effectively describing a cross-functional accountability gap that most IAM programmes still treat as exceptional rather than standard. That gap will keep widening until organisations assign a single governance path for AI adoption, access, and review.

AI agents are now part of the identity perimeter: Once a tool can act, access, or consume data on behalf of a business user or process, it belongs in the identity programme. That includes onboarding, policy enforcement, monitoring, and offboarding. Practitioners should stop treating agent governance as a side issue and instead fold it into core identity and access management.

From our research library:

What this signals

AI agent governance is becoming a control-plane issue: The practical boundary is shifting from “can people use AI?” to “which teams own the permissions, logging, and retirement of AI actors?” That means identity teams need to extend lifecycle thinking to software entities that can act on behalf of the business and outlive the approval that created them.

Shadow AI is now an identity inventory problem: If organisations cannot see where unapproved AI tools are operating, they cannot enforce least privilege or audit data access. The programme response is to treat discovery, registration, and ownership as the first line of governance, not the last line of cleanup.


For practitioners

  • Define named ownership for every AI agent Record a business owner, technical owner, and approval authority for each deployed agent before it can access enterprise data or systems.
  • Extend application inventory to shadow AI Add unsanctioned AI tools to discovery, inventory, and access review workflows so hidden usage does not remain outside governance.
  • Enforce least privilege on agent access Scope each agent to the minimum data, APIs, and actions required for its task, then remove standing access that is not actively needed.
  • Tie legal policy to operational access controls Map acceptable use rules to specific technical guardrails for data handling, retention, and cross-border processing so policy is enforceable in practice.
  • Add agent offboarding to identity lifecycle When an agent is retired, disable its tokens, revoke API access, and confirm there is a documented closure path for its ownership record.

Key takeaways

  • AI governance fails when organisations adopt tools faster than they assign ownership, scope access, and define accountability.
  • The evidence in the article links unsanctioned use to breach cost inflation and missing access controls, which makes the risk operational rather than theoretical.
  • IAM teams should fold AI agents into normal lifecycle governance, because unmanaged tools create the same accountability gaps as any other unowned non-human identity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents receiving unmanaged privileges and unclear ownership.
Recommendation — Map AI agent access to ASI03 and require explicit ownership before production use.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationAI tools and agent connections depend on identity controls that fail when access is ungoverned.
NHI-05 — Overprivileged NHIThe article stresses least privilege for agents and warns against broad access.
Recommendation — Review agent authentication paths and remove any unmanaged credentials or trust links. Scope each AI agent to the minimum permissions needed for its task and revoke excess access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about controlling who and what can access systems and data.
Recommendation — Apply PR.AA-05 to register AI agents, review entitlements, and enforce authorization boundaries.
NIST AI RMFGOVERN — AI Governance and AccountabilityOwnership, policy, and accountability are the article's central governance issues.
Recommendation — Use GOVERN to assign AI governance roles, decision rights, and accountability paths.

Key terms

  • AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI Agent Ownership: AI agent ownership is the assignment of a named human steward who is accountable for an agent’s access, behaviour, and lifecycle. It turns responsibility into an enforceable control, so the organisation can review privilege, investigate incidents, and retire the identity when the business need ends.
  • Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org