By NHI Mgmt Group Editorial TeamBased on Collibra: “New Collibra Survey by The Harris Poll Finds 84% of Decision Makers Say Organizations Must Increase AI Spending in 2026 to Remain Competitive with Big Tech, with Almost Half Saying AI is Falling Short” (March 30, 2026)

TL;DR: A Harris Poll survey of 313 U.S. technology decision makers found that 93% want companies to disclose AI tools and agents, 90% support federal disclosure requirements for high-risk AI systems, and 91% say human oversight is critical, according to Collibra. The governance gap is no longer about adoption speed alone, but about accountability, verification, and trust boundaries that existing programmes were not built to enforce.


At a glance

What this is: This is a Collibra survey-backed analysis of rising AI disclosure and oversight expectations, showing that technology decision makers increasingly want transparency, documented governance and human review around AI tools and agents.

Why it matters: It matters because identity, access and governance teams will be asked to prove who can deploy AI, who oversees it, and what evidence exists when AI outputs affect business decisions.

By the numbers:

  • 93% want companies to disclose AI tools and agents to encourage transparency, monitoring and responsible use.
  • 90% support federal requirements for companies to disclose and document high-risk AI systems.
  • 91% of decision-makers believe that human oversight for AI systems is critical.

Context

AI disclosure is the public-facing side of AI governance. In this article, the issue is not whether organisations are experimenting with AI tools and agents, but whether they can explain where those systems are used, who is accountable for them, and how oversight is enforced when outputs influence decisions.

For IAM and governance teams, the pressure point is evidence. Disclosure requirements create demand for inventories, ownership, approval records and reviewable control boundaries across human, NHI and agentic use cases. The survey results suggest that executives now expect governance to be demonstrable, not implied.

That shift is especially important for AI agents, because once tools act with delegated access, the question stops being adoption speed and becomes accountability under controlled access, documented oversight and verifiable policy.


Key questions

Q: What breaks when AI tools and agents are not fully disclosed?

A: Undisclosed AI systems create blind spots in ownership, access review and accountability. Teams cannot govern what they cannot inventory, and they cannot prove oversight for systems that sit outside procurement, IAM and policy records. The result is shadow AI that may already influence decisions without a defensible control boundary.

Q: Why do organisations need formal oversight for high-impact AI systems?

A: High-impact AI can affect hiring, finance, healthcare and other decisions where error or bias has real consequences. Formal oversight creates a required checkpoint before outputs become actions, which is the only reliable way to keep automated decisions within policy, legal and business boundaries.

Q: What are the signs that AI governance is failing in the enterprise?

A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk. Another indicator is weak visibility into who is using which tools and what data they are sending. If teams cannot answer those questions, governance is not working as intended.

Q: What is the difference between human IAM and AI workforce governance?

A: Human IAM assumes a person with a predictable session, while AI workforce governance must manage autonomous execution, delegated tool use, and variable context. That means you need tighter lifecycle controls, stronger logging, and faster revocation for agents than for typical user accounts.


Technical breakdown

AI disclosure depends on inventory, ownership and traceability

Disclosure of AI tools and agents only works when an organisation can identify what is deployed, who approved it, what data it touches and which business process it supports. That requires a current inventory, ownership metadata and traceability from system to use case. Without those three elements, disclosure becomes a policy statement with no operational proof. The governance challenge is not just cataloguing models, but linking each AI capability to an accountable human or team and to the controls that bound its use.

Practical implication: maintain an authoritative AI inventory that ties each system to an owner, use case and control boundary.

Human oversight is a control boundary, not a slogan

Human oversight only has governance value when the human reviewer can actually intervene, correct, stop or approve a materially risky AI outcome. If the review step happens after the decision has already propagated, oversight is cosmetic. The article’s findings point to a broader governance reality: high-impact AI use needs pre-defined intervention points, escalation paths and exception handling, especially where AI influences finance, healthcare or hiring. Oversight must be designed into the workflow, not added as a post hoc assurance claim.

Practical implication: define where human approval is mandatory, where review is advisory and where automated action is prohibited.

AI disclosure exposes the limits of existing identity governance

Traditional identity programmes were built around users, roles and access requests, not runtime AI behaviour that can combine data, tools and outputs in ways that are difficult to pre-classify. That means AI disclosure pressures identity teams to extend governance beyond provisioning into usage visibility and policy enforcement. The challenge is not simply who logged in, but what the AI system is allowed to see, decide and do once access is granted. This is where disclosure and identity control converge.

Practical implication: extend identity governance to cover AI runtime access, not just initial provisioning and authentication.


Threat narrative

Attacker objective: The practical objective is not theft alone but unaccountable AI-driven decisioning that bypasses governance, weakens trust and expands operational risk.

  1. Entry occurs when an AI tool or agent is introduced into a workflow without full inventory or disclosure, creating a hidden governance surface.
  2. Escalation occurs when the system receives broad delegated access to data or tools without clear human review boundaries or documented ownership.
  3. Impact occurs when AI-generated outputs influence decisions, but the organisation cannot prove oversight, traceability or accountability for those outputs.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Disclosure is becoming the new minimum governance signal for AI. The survey results show that executives are no longer satisfied with informal AI use or vague internal assurances. They want visible inventories, documented use cases and named accountability so that AI systems can be governed as part of the control plane, not treated as shadow experimentation. The practitioner conclusion is simple: if an AI system cannot be disclosed, it is not governed.

Human oversight is only meaningful when it constrains action before impact. The article’s 91% oversight figure is important because it reflects a shift away from trust in model quality alone. Oversight has to be embedded where decisions are made, where exceptions are raised and where automated action can be stopped. The practitioner conclusion is that oversight design now belongs in workflow architecture, not in policy language alone.

Data and AI literacy has become a governance prerequisite, not a training add-on. The hiring signal in the survey shows that organisations increasingly judge whether staff can recognise AI risk at all. That matters because governance fails when teams cannot distinguish acceptable automation from uncontrolled AI behaviour. The practitioner conclusion is that literacy, accountability and control design now rise or fall together.

AI disclosure creates a governance convergence point for human IAM, NHI and AI agents. Once AI tools and agents are explicitly disclosed, security teams have to decide whether they are managing a person, a service identity or an autonomous system. That decision changes how access is approved, reviewed and revoked. The practitioner conclusion is that AI governance cannot sit outside identity governance anymore; it must be mapped into it.

Transparency pressure is exposing the gap between policy intent and runtime proof. A formal disclosure requirement is easy to write and hard to evidence unless systems emit logs, ownership records and review artefacts that survive audit. The practitioner conclusion is that control design must now prioritise evidence generation as much as access restriction.

From our research library:

What this signals

AI disclosure is becoming a control design problem, not a communications problem. Once organisations have to disclose AI tools and agents, they need an inventory that links every system to an owner, a use case and a policy boundary. That makes disclosure useful only when it is tied to evidence generation and review artefacts, not marketing language.

90% support for disclosure of high-risk AI systems signals a broader governance reset. The practical implication is that AI teams will be expected to show not only that a system exists, but that its access, oversight and accountability are documented in the same language used for other security controls.

Trust boundaries are shifting from model output to governed workflow. The organisation now has to prove where AI can act, who can stop it and what happens when human review is required. That is the point where AI governance meets identity governance and becomes operational rather than aspirational.


For practitioners

  • Build a disclosed AI inventory Catalog every AI tool, embedded model and agent in use, with owner, purpose, data access and approval path. Reconcile the inventory against procurement, shadow IT and IAM records so undisclosed systems are flagged for review.
  • Define human override points Identify where AI output can be corrected, blocked or escalated before it affects customers, employees or regulated decisions. Require explicit approval for high-impact use cases and document who can intervene.
  • Map AI access to identity controls Treat AI systems as governed subjects in the identity model, with scoped permissions, monitored usage and revocation paths. Separate pilot access from production access and tie both to named accountability.
  • Require evidence for every disclosure claim Link each disclosed AI use case to logs, policy records, review artefacts and exception handling so the organisation can prove oversight. If the evidence is missing, the disclosure is incomplete.

Key takeaways

  • AI disclosure is moving from a policy preference to a governance expectation that organisations will need to evidence.
  • The real control gap is not model quality alone, but the ability to inventory AI use, assign ownership and prove human oversight.
  • IAM and AI governance are converging around runtime access, intervention points and audit-ready accountability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI disclosure issues center on delegated access, ownership and runtime authority.
Recommendation — Map disclosed AI systems to ASI03 and constrain their delegated privileges to named business purposes.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance, oversight and accountability for AI use.
Recommendation — Use GOVERN to assign accountable owners, approval paths and evidence requirements for each AI use case.
NIST CSF 2.0GV.OC-01 — Organisational ContextAI disclosure depends on knowing where AI fits into the organisation and who is responsible.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsDisclosure and oversight fail if AI systems have excessive or unclear access permissions.
Recommendation — Document AI systems, business context and ownership so disclosure and oversight can be enforced consistently. Scope AI entitlements tightly and review them against the business purpose for each disclosed system.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIAI tools and agents behave like non-human identities when they receive more access than they need.
Recommendation — Reduce AI system privileges to the minimum required for each disclosed use case.

Key terms

  • AI Disclosure: AI disclosure is the practice of documenting where AI tools and agents are used, what they can access, and who is accountable for their operation. It turns hidden or informal AI use into something governance, audit, and security teams can verify and review.
  • Human Oversight: Human oversight is the requirement that a person remains responsible for reviewing, approving, or correcting AI-driven output before it causes a material action. In governance terms, it is the control that prevents automation from becoming unowned authority.
  • Runtime Access Platform: A Runtime Access Platform is a control layer that evaluates privileged requests as they happen, rather than relying only on preassigned access. It combines identity discovery, policy enforcement, and audit visibility so organisations can approve or deny actions based on current context, task scope, and risk at the point of use.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org