By NHI Mgmt Group Editorial TeamBased on WitnessAI: “How to shorten your AI approval cycle” (June 28, 2026)

TL;DR: AI approval cycles can stretch from under two minutes of user adoption to eleven weeks of security review, driving Shadow AI and pilot purgatory when governance cannot keep pace with business demand, according to WitnessAI. The core problem is not AI usage itself but the mismatch between manual review models and the velocity of modern AI adoption.


At a glance

What this is: This is an analysis of why enterprise AI approval cycles stall, with WitnessAI arguing that the real problem is governance latency rather than AI adoption itself.

Why it matters: It matters because IAM, security, and governance teams need approval models that let low-risk AI move quickly without creating unmanaged Shadow AI or leaving funded projects stuck before production.


Context

The security and governance gap is simple: business teams adopt AI far faster than enterprise review processes can sanction it. When approval authority is unclear and the review path is built for slower, manual decision cycles, organisations create a queue that pushes users toward unsanctioned tools and delays legitimate production use.

AI approval cycles are the structured decision paths that route a use case through security, legal, compliance, data governance, and risk review before production. In this article, the issue is not the existence of governance, but the mismatch between governance design and AI velocity, which turns control into delay.

For IAM and governance teams, the practical question is how to preserve control without forcing every AI request through the same slow, high-friction process. The article argues that the answer is not fewer controls, but better routing, clearer ownership, and runtime enforcement where routine interactions do not need repeated human review.


Key questions

Q: Why do manual AI approval processes break down as AI adoption expands?

A: Manual review breaks down because volume, reuse, and operational speed quickly outpace human committees. AI use cases spread across teams and environments, so waiting for one-off approvals creates delays and uneven enforcement. A scalable programme relies on embedded policy, clear ownership, and automated checks that keep pace with change while still preserving oversight and trust.

Q: Why do slow AI approvals create more governance risk instead of less?

A: Slow approvals create risk because they do not stop demand, they divert it. If the sanctioned path is too cumbersome, employees adopt tools outside the governance process, which reduces visibility, weakens enforcement, and makes it harder for security teams to prove control over AI use.

Q: How should security teams speed up AI approval without weakening governance?

A: Use risk-tiered review lanes, clear production authority, and sanctioned catalogs for common low-risk use cases. Then reserve deep review for systems that touch sensitive data, external vendors, or write access. The goal is not fewer controls, but controls that match the actual risk level and the speed at which the business is adopting AI.

Q: When should organisations prioritise runtime controls over pre-deployment review?

A: Organisations should prioritise runtime controls when the AI system can influence regulated, operational, or safety-critical outcomes in production. Pre-deployment review still matters, but it cannot catch behaviour that emerges only during live use. If the system learns, adapts, or acts through tools, runtime monitoring and enforcement become the primary risk-reduction layer.


Technical breakdown

Why manual AI review cycles break at enterprise speed

AI approval cycles often inherit control patterns that were built for files, apps, and static access requests, not conversational systems that change every interaction. A manual committee can evaluate a use case once, but it cannot practically re-approve every prompt, output, or workflow at the pace business users expect. That creates a structural lag between request and sanction. In governance terms, the problem is not control absence, but control granularity: the review model is too coarse for the interaction model. Practical implication: move routine AI interactions out of repetitive manual review and reserve human oversight for genuinely novel or high-risk cases.

Practical implication: separate one-time policy approval from ongoing runtime enforcement so reviewers are not forced to inspect every routine AI interaction.

How risk-tiered lanes reduce approval bottlenecks

Risk-tiered review works because it links governance effort to actual exposure. Low-risk use cases can move through a fast lane when they run on pre-approved infrastructure, avoid new vendors, and do not touch confidential data, while higher-risk systems stay in a deeper review lane. This is consistent with the NIST AI Risk Management Framework approach of focusing the most intensive review where consequences are highest. The operational value is in pre-decision routing: teams decide the lane before the review starts, which removes ambiguity and shortens queue time. Practical implication: define risk tiers in advance and make lane selection part of intake, not a late-stage debate.

Practical implication: use predefined risk tiers to route AI requests before review begins, rather than after the queue has already formed.

Why approval authority becomes a governance failure point

Many AI programmes stall because the committee exists, but the person or role with final production authority does not. That ambiguity creates pilot purgatory: the project is validated, but no one is clearly empowered to say it can operate. The article points to a wider governance pattern where policy exists on paper but is not operationalised through named ownership. In practice, that means legal, security, compliance, and business teams can all review a project without any single accountable path to production. Practical implication: assign explicit decision ownership for AI approvals so governance produces an outcome instead of a waiting loop.

Practical implication: name a final decision owner for AI production approval, or the review process will keep absorbing projects without resolving them.


NHI Mgmt Group analysis

Approval latency is now a governance risk, not just an inconvenience. When users can adopt AI in minutes but the enterprise needs weeks to approve the same tool, the control model has already lost the race. That gap creates Shadow AI because people route around slow process, not because they reject governance. The practitioner conclusion is that approval speed has become part of the security posture.

Risk-tiered governance is the only scalable alternative to uniform review. Treating every AI use case as if it carries the same consequence guarantees backlog and inconsistent decisions. The article shows why lane-based routing matters: low-risk productivity use cases should not wait behind systems that can affect identity, safety, legal exposure, or irreversible action. The practitioner conclusion is that governance must distinguish between routine interaction and material system risk.

Runtime control is where AI approval finally becomes operational. Manual review cannot inspect every conversational exchange without collapsing under its own weight, so the approval decision has to shift toward policy that is enforced continuously at runtime. That changes governance from event-based sign-off to evidence-based control, which is the only way to scale both adoption and oversight. The practitioner conclusion is that runtime enforcement, not repeated committee review, is what makes AI adoption governable.

Visibility and auditability are the missing currency of AI governance. Reviewers do not need more narrative reassurances, they need continuous evidence of what the AI did, what it touched, and what policy governed it. When audit trails, discovery, and intent classification are continuous, the approval question changes from speculative trust to documented control. The practitioner conclusion is that governance teams should optimise for evidence production as much as for approval speed.

AI governance now spans humans and agents, so approval logic must scale across both. The article’s most important signal is that the same governance bottleneck will recur as agentic workflows become more common. A process that cannot handle business-led human use today will struggle even more when autonomous systems begin requesting, chaining, and acting on AI capabilities. The practitioner conclusion is that approval design must anticipate both human adoption and machine execution.

What this signals

Approval velocity is becoming an identity governance test. If the enterprise cannot classify, route, and enforce AI use cases fast enough, the practical result is not stronger control but parallel shadow adoption. Governance teams should expect pressure to move from project-by-project sign-off to policy-driven enforcement.

Runtime evidence will matter more than committee consensus. As AI usage expands, reviewers will care less about whether a workflow was once approved and more about whether the controls still hold during live interaction. That shift favours continuous discovery, audit trails, and policy enforcement that can stand up to operational scrutiny.


For practitioners

  • Define risk-tiered approval lanes Separate low-risk productivity uses from higher-risk systems before review begins. Use clear criteria such as data sensitivity, write access, external model exposure, and irreversible action to decide whether a request enters a fast lane or a full governance path.
  • Assign final production authority Name the role that can actually move an AI use case from pilot to production. Make that decision owner explicit across security, legal, compliance, and business stakeholders so the review process does not become a permanent holding pattern.
  • Build a pre-approved AI tool catalog Create a sanctioned list of common AI tools and use cases that have already passed lightweight review. Update the catalog from observed employee usage so the approved path is realistic enough to replace unsanctioned adoption.
  • Move controls to runtime enforcement Use policies that evaluate prompts, responses, and context as interactions happen, rather than re-reviewing every routine use case. Reserve manual review for exceptions, escalation paths, and novel risk conditions that runtime policy cannot safely absorb.
  • Instrument continuous audit evidence Capture approvals, purpose boundaries, change logs, and monitoring outputs as part of normal operation. The goal is to give reviewers evidence on demand, not require teams to assemble a compliance packet after the fact.

Key takeaways

  • AI approval delays become a security problem when sanctioned paths are too slow and users adopt Shadow AI instead.
  • The article shows that unclear ownership and manual review are the main reasons AI pilots fail to reach production.
  • Risk-tiered lanes, pre-approved catalogs, and runtime controls are the mechanisms that compress approval cycles without dropping governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article centres on AI governance ownership, review lanes, and approval authority.
MANAGE — AI Risk ManagementRisk-tiered lanes and runtime enforcement are framed as the operational response to AI adoption speed.
Recommendation — Define accountable AI approval ownership and route use cases through governance before production. Apply risk-tiered controls so low-risk AI moves quickly while higher-risk use cases face deeper review.
NIST CSF 2.0GV.RR-01 — Roles, Responsibilities, and AuthoritiesUnclear decision ownership is the article's core governance failure mode.
PR.DS-10 — Data-in-transit is protectedThe article discusses runtime controls and continuous evidence around AI interactions that process sensitive data.
Recommendation — Assign clear roles and authorities for AI approval so governance produces a decision instead of delay. Protect AI interactions in motion with runtime policy enforcement and continuous monitoring.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article spans AI apps and agents, where approval and runtime control must prevent misuse of granted capabilities.
Recommendation — Constrain agent and application privileges so approved AI cannot exceed its intended scope.

Key terms

  • AI approval cycle: The AI approval cycle is the governance path a tool or use case follows from request to production use. It usually includes security, legal, compliance, risk, and data governance. In practice, the cycle should balance speed, evidence, and risk so that approved AI is usable rather than trapped in review.
  • Pilot Purgatory: A delivery state where AI initiatives cannot move from experimentation to production because identity, approval, and compliance steps are handled manually. In practice, the programme gets stuck between innovation pressure and governance delay, which encourages workarounds, shadow deployments, and shared credentials.
  • Risk-Tiered Review: Risk-tiered review is a governance model that matches approval depth to the likely impact of the use case. Lower-risk AI can move through lighter review, while higher-risk systems receive more scrutiny, which reduces queue time without removing control.
  • Runtime Enforcement: Runtime enforcement is the practice of blocking malicious behaviour while software is running, rather than only detecting it after the fact. It monitors process activity, network actions, and privilege changes so a live attack can be interrupted at the point of execution.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org