By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “The Silent Storm of Shadow AI: Why Unsanctioned Agents Outpace Traditional Defenses” (June 9, 2026)

TL;DR: AI agents are already performing around 30% of daily work at about 3x the rate leaders estimate, while fewer than 20% of companies have written AI policies and AI credential leakage rose 81% year over year to 1.27 million exposed secrets, according to Abnormal AI. Human-first IAM, DLP, and SIEM assumptions are collapsing as non-human actors increasingly behave like account takeovers.


At a glance

What this is: This is an Abnormal AI analysis arguing that AI agents and shadow AI are already stretching human-first IAM, with behavioural risk, policy gaps, and exposed credentials now defining the attack surface.

Why it matters: It matters because IAM, IGA, PAM, and monitoring programmes built for people need to distinguish sanctioned human activity from unmanaged non-human behaviour before those gaps become routine incident paths.

By the numbers:

  • Employees use AI for about 30% of daily work at roughly 3x the rate leaders believe, according to Abnormal AI.
  • AI credential leakage climbed 81% year over year to 1.27 million exposed secrets, according to Abnormal AI.
  • Fewer than 20% of companies have written AI policies, according to Abnormal AI.

Context

AI agents are non-human actors that can read data, take actions, and use tools inside enterprise systems. The governance problem is not simply that they exist, but that current IAM models still assume the primary actor is a person and the primary anomaly is a human account behaving badly.

Abnormal AI argues that this assumption is already breaking across discovery, authorisation, and monitoring. Shadow AI tools, exposed AI credentials, and autonomous agents using sanctioned access all create a control gap where identity behaviour no longer maps cleanly to HR-managed accounts or traditional security policy.


Key questions

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius. Human-centric controls can misclassify normal agent activity as compromise, or miss policy violations that happen entirely within legitimate access. The failure is not only technical, it is governance design that assumes a person is always behind the action.

Q: Why does unmanaged AI tool adoption increase identity and data risk so quickly?

A: Every AI tool, embedded feature, or agent identity can become a new access path to sensitive data. If security teams do not define who approved it, what it can reach, and how it is monitored, the tool inherits broad permissions and creates audit gaps. That combination turns fast adoption into unmanaged exposure across identity and data controls.

Q: What are the warning signs that shadow AI is becoming a security problem?

A: Look for AI tools connected outside approved procurement, unexplained API or token usage, and data leaving normal SaaS boundaries. Those signals show that access has expanded beyond governance, even if the user-facing application still appears legitimate.

Q: How should organisations govern AI agents alongside human identity and device access?

A: Organisations should treat AI agents as a separate identity class with their own entitlement boundaries, logging expectations, and approval model. Human IAM controls often assume interactive sign-in and review cycles, which do not fit autonomous or programmatic access. The safer approach is to define actor-specific policy and verify which access paths can be delegated without expanding trust unnecessarily.


Technical breakdown

Why human-first IAM fails when the actor is a non-human identity

Human-first IAM assumes a stable person behind every account, with intent, usage patterns, and accountability anchored to employee lifecycle events. AI agents and shadow AI break that model because access can be created outside HR, used at machine speed, and exercised through tools that look like ordinary application behaviour. Once behaviour becomes the primary signal, an identity control stack built around login events and approved users loses much of its explanatory power. The operational issue is not only access sprawl, but attribution sprawl: who owns the actor, who approves its scope, and who can tell normal from abnormal when the same account can act like both a user and a workload.

Practical implication: Classify AI systems and agents as governed identities, not just software, and tie ownership to explicit lifecycle and access accountability.

How shadow AI turns credential exposure into governance failure

Shadow AI becomes an identity problem when tools, tokens, and API keys are created, copied, or embedded without governance. That is why public repository leakage matters so much: exposed credentials let a non-human actor retain access long after the original user or team has lost visibility. In practical terms, the issue is less about a single leaked secret than about how quickly one unmanaged credential becomes a persistent access path. Once credentials are outside inventory, IAM cannot certify scope, revoke cleanly, or prove that access remains justified. The article’s point is that leakage is now a routine condition, not a rare exception.

Practical implication: Treat AI credentials as inventory-sensitive assets and force ownership, rotation, and revocation into the same governance workflow as other privileged secrets.

What behavioural monitoring has to do that DLP and SIEM cannot

DLP and SIEM were built to spot data movement and suspicious events, but they do not by themselves explain whether an AI actor is behaving within its intended role. Abnormality in this context is not just volume or velocity. It is an account or agent taking a new path through systems that should not match its usual task profile. That is why discovery alone is insufficient. Once an organisation finds the tools, it still has to determine what normal behaviour looks like for each actor type and where sanctioned activity ends. Behavioural monitoring becomes the control that bridges inventory and policy enforcement.

Practical implication: Build behavioural baselines for AI accounts and agents so monitoring can flag scope drift, not merely log activity after the fact.


Threat narrative

Attacker objective: To gain durable access through unmanaged AI pathways that enable data exfiltration, unauthorized action, and hidden persistence under the cover of legitimate-looking identity activity.

  1. Entry occurs when employees or teams adopt AI tools, extensions, or agents outside approved governance, often through downloads, trials, or signups that bypass central inventory.
  2. Credential exposure follows when those tools or workflows use hardcoded, copied, or leaked AI secrets and API keys, creating persistent access paths in public repositories or other uncontrolled locations.
  3. Escalation happens when an AI actor or shadow AI tool uses the exposed credentials to query data, read email, access repositories, or act inside business systems at machine speed.
  4. Impact is the loss of data, control, and attribution, where the resulting activity can look indistinguishable from account takeover and expands the enterprise attack surface.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Human-first IAM is no longer a complete identity model. The article’s core claim is not simply that AI is changing workflows, but that enterprise controls still assume the actor is a person with predictable lifecycle events. That assumption fails when a non-human identity can execute work, call tools, and access data without fitting HR-centric governance. Practitioner takeaway: identity policy has to classify AI actors as governed subjects, not just applications.

Shadow AI is an inventory problem only until it becomes a privilege problem. Once unmanaged tools obtain credentials, tokens, or delegated access, the issue is no longer discovery but accountability for what those identities can do. This is exactly where human-first access governance breaks down, because the access path is often created outside formal onboarding. Practitioner takeaway: governance must follow the credential, not just the application.

Abnormal behaviour in AI systems can resemble account takeover because the control plane was built for people. Security teams that rely only on static allowlists, login telemetry, or DLP miss the more important question of whether the actor is staying within its intended task boundary. That is why behavioural analysis becomes the bridge between identity and runtime risk. Practitioner takeaway: baseline intent and scope for AI identities as distinct control objects.

Identity blast radius is the right concept for the AI era. Each new agent, workflow, or tool can multiply the number of systems and datasets reachable before review, and the article’s numbers show that this is happening faster than policy maturity. The security problem is no longer simply access creep but access acceleration. Practitioner takeaway: measure how quickly AI identities can widen their effective reach, not just how often they are reviewed.

Governance cycles built for humans cannot keep pace with machine-speed identity behaviour. Annual policy updates, periodic recertification, and manual approvals were designed for slower, observable human patterns. AI actors collapse that cadence by acting continuously and often invisibly between review points. Practitioner takeaway: align governance to issuance, runtime behaviour, and revocation, because after-the-fact review alone no longer contains the risk.

From our research library:

What this signals

Governance teams need a non-human identity boundary, not just an AI policy. The practical shift is to decide which tools, agents, and workflows qualify as governed actors before they accumulate access that outpaces review cycles. Without that boundary, IAM, PAM, and monitoring all end up chasing activity after it has already widened the blast radius.

Identity teams should expect AI credential leakage to behave like a standing access channel. Once secrets are copied into public code, shared notebooks, or unmanaged integrations, the access path can persist long after the original tool is forgotten. That is why ownership, revocation, and behavioural monitoring have to operate together, not in separate programmes.


For practitioners

  • Classify AI actors as governed identities Create an explicit inventory of AI systems, agents, and shadow AI tools, and assign each one an owner, purpose, and approval path. Treat unmanaged AI as an identity governance issue, not just a software discovery task.
  • Bind credentials to lifecycle ownership Track every AI credential, token, and API key back to a business owner and a revocation process so leaks do not become permanent access paths. Include repository scanning, rotation triggers, and offboarding for abandoned tools.
  • Baseline behavioural scope for each AI identity Define expected actions, data boundaries, and tool usage for sanctioned AI actors, then alert on new paths, unusual timing, or expanded resource access. The goal is to detect scope drift before it is misread as ordinary usage.
  • Separate human and non-human policy enforcement Do not apply the same review and approval mechanics to people and AI actors. Build policy branches that recognise machine-speed execution, delegated access, and the absence of HR-driven lifecycle events.

Key takeaways

  • AI agents and shadow AI are forcing IAM to treat non-human actors as governed identities rather than treating them as ordinary software.
  • The article points to a widening gap between rapid AI adoption, weak policy coverage, and exposed credentials that can be reused for unauthorized access.
  • The practical answer is to combine identity ownership, credential lifecycle control, and behavioural monitoring so AI access is governed at runtime, not only after discovery.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents gaining and using access beyond human-first assumptions.
Recommendation — Map AI agent access paths to ASI03 and constrain privilege to explicitly approved runtime scope.
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article highlights exposed AI credentials and repository leakage as a primary risk driver.
NHI-05 — Overprivileged NHIThe piece argues that AI actors often receive more access than their role justifies.
Recommendation — Scan for leaked AI secrets under NHI-02 and revoke any exposed credentials immediately. Review AI access grants against NHI-05 and trim any permissions not needed for the defined task.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle control is central to preventing AI secrets from becoming standing access.
Recommendation — Apply IA-5 to rotate, revoke, and track authenticators used by AI systems and agents.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about permission scope and authorisation for human and non-human actors.
Recommendation — Use PR.AA-05 to align AI entitlements with documented business purpose and ownership.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI Credential: A credential used by an AI service, model, or pipeline to access data, tools, or billing systems. In practice, it functions like a privileged machine secret and should be governed with ownership, scope, rotation, and revocation controls rather than treated as ordinary configuration.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org