TL;DR: Automated discovery typically reveals an AI footprint 30 to 50 percent larger than leadership expects, exposing shadow AI, duplicated tools, hidden workflows, and unmanaged third-party features that undermine governance assumptions, according to Holistic AI. Discovery is the control that makes inventory, classification, monitoring, and compliance operational rather than theoretical.
At a glance
What this is: This article argues that enterprise AI governance fails when organisations cannot first discover the AI systems, workflows, and third-party features already in use.
Why it matters: For IAM, NHI, and governance teams, the message is that visibility is the prerequisite for accountability, risk classification, and control assignment across both human and machine-mediated AI usage.
By the numbers:
- The true AI footprint is typically 30–50% larger than leadership expects when automated discovery is applied.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, making poorly scoped AI access 4.5x more likely to end in an incident.
👉 Read Holistic AI's analysis of why AI discovery must come before governance
Context
AI governance starts with an inventory problem. If organisations cannot see which AI tools, embedded features, hidden workflows, and sandboxed experiments are already active, every downstream policy becomes an assumption rather than a control. That is especially important for AI governance, because the AI system itself may be created, copied, or delegated outside formal review.
Holistic AI’s central claim is that discovery must come before classification, monitoring, and compliance. That framing is consistent with identity governance more broadly: you cannot assign ownership, privilege, or lifecycle controls to systems you have not identified. In practice, shadow AI usually emerges through everyday user behaviour, shadow integrations, and untracked development activity, which means the starting state is often less controlled than leaders assume.
Key questions
Q: How should organisations govern AI systems that cannot verify themselves?
A: They should treat self-checks as advisory only and require an external validation layer for any output that affects security, access, or operational decisions. That usually means separate evaluation pipelines, human escalation for exceptions, and logging that preserves the evidence used to approve a decision. The goal is to prevent the model from becoming its own judge.
Q: Why do hidden AI tools create a governance risk beyond ordinary software sprawl?
A: Hidden AI tools can process sensitive data, call external services, and change outputs or decisions without leaving a clear ownership trail. That makes them different from ordinary application sprawl, because the risk includes data exposure, untracked delegation, and incomplete auditability. The control problem is visibility first, not policy wording.
Q: What do security teams get wrong about AI governance inventories?
A: They often inventory only the AI they built themselves and miss embedded AI inside vendor platforms and other shadow AI. That creates a false sense of control because the real decision surface is broader than the visible project list. A useful inventory must cover models, use cases, agents, owners, and the approvals attached to each one.
Q: Who is accountable when shadow AI creates spend and compliance risk?
A: Accountability should sit with the business owner of the workflow, the identity that initiated the activity, and the governance function that approved or failed to detect it. If no one can trace an AI interaction back to a named owner, the organisation has already lost control of both spend and policy enforcement.
Technical breakdown
Why AI discovery has to precede inventory
Discovery is the process of finding AI-related artefacts across cloud, code, data, endpoint, and collaboration systems. Inventory is the next step, where those artefacts are turned into governed assets with ownership, classification, and lifecycle metadata. Without discovery, the inventory is incomplete by definition, and governance functions such as risk assessment, compliance review, and monitoring all inherit that gap. This matters because modern AI often appears as embedded features, experimental notebooks, RAG components, or third-party copilots rather than a single sanctioned application.
Practical implication: build continuous discovery first, then attach ownership and risk treatment only after the AI footprint is visible.
What shadow AI looks like in real environments
Shadow AI is not just an unapproved chatbot. It includes employees pasting sensitive content into public tools, developers using unvetted coding assistants, SaaS copilots enabled without review, and internal prototypes built outside model-risk controls. These behaviours are hard to catch because they often look like ordinary productivity work. The governance problem is that each use case can create a separate data, access, or compliance exposure without ever being recorded in a central register.
Practical implication: monitor for hidden AI through SaaS settings, code repositories, cloud accounts, and collaboration platforms rather than relying on self-reported inventories.
Why ontology matters after discovery
An AI ontology links datasets, prompts, pipelines, endpoints, and applications so teams can understand how AI components relate to one another. That relationship layer matters because governance failures often come from broken dependency visibility rather than a single bad asset. If a prompt, dataset, or deployment endpoint changes, the organisation needs to know what downstream systems are affected and who owns the change. In identity terms, this is the difference between knowing a system exists and knowing how it behaves in a controlled lifecycle.
Practical implication: map AI relationships as well as assets, so approvals, testing, and incident response can follow the full dependency chain.
Threat narrative
Attacker objective: The objective is not necessarily external theft but uncontrolled AI use that expands data exposure, decision risk, and compliance failure beyond what governance can see.
- Entry occurs through shadow AI adoption, including unreviewed chatbots, embedded copilots, and informal RAG experiments that bypass formal intake.
- Escalation follows when those tools process sensitive data, access internal content, or connect to cloud services without logging, ownership, or policy controls.
- Impact is governance blind spots, delayed approvals, duplicated tooling, and exposed data that cannot be monitored or audited reliably.
NHI Mgmt Group analysis
Discovery is the real control boundary for AI governance. Governance frameworks assume an accurate asset picture, but AI changes too quickly for spreadsheets and annual reviews to keep pace. When discovery is missing, classification, monitoring, and audit all operate on stale assumptions. Practitioners should treat visibility as the first enforceable control, not an administrative cleanup step.
Shadow AI creates an identity problem as much as a data problem. Every hidden chatbot, copilot, or agentic workflow has some form of identity, access path, or delegated authority, even if nobody documented it. That means AI discovery is also a machine identity discovery problem when AI systems use API keys, tokens, service accounts, or third-party integrations. The governance gap is not just unapproved software, but unowned access.
AI governance debt: the longer discovery is delayed, the more controls accumulate on false assumptions. The article correctly shows that approval, compliance, and monitoring all slow down when the asset base is unknown. In identity programmes, this mirrors the failure mode where access reviews are performed against incomplete inventories. Practitioners should expect remediation to get harder, not easier, the longer shadow AI remains invisible.
The inventory problem is becoming a policy problem. Regulations and governance frameworks increasingly assume organisations can explain what AI exists, why it exists, and who is accountable for it. That pressure is shifting AI discovery from a technical nice-to-have into a prerequisite for defensible governance. Teams that cannot produce a trustworthy AI inventory will struggle to evidence control ownership when auditors or regulators ask.
AI ontology is where discovery becomes operational. A list of assets is useful, but a governed AI estate requires relationship mapping across datasets, prompts, pipelines, endpoints, and applications. That is the point where AI governance starts to resemble mature identity governance, because ownership, dependency, and lifecycle control become visible together. Practitioners should design for connected governance, not isolated inventory.
What this signals
AI discovery will increasingly become the gating control for every downstream governance decision. Teams that cannot see the full AI estate will struggle to classify data use, assign ownership, or prove compliance, no matter how mature their policy framework looks on paper. That makes continuous discovery a programme-level priority rather than a tooling choice.
Shadow AI also changes the identity workload for security teams. Hidden copilots, agents, and embedded services often rely on service accounts, API keys, or delegated tokens, which means discovery findings should feed directly into access review and secrets governance. The strongest response is not just to catalog AI, but to identify how it authenticates and what it can reach.
The practical signal for practitioners is that AI governance will converge with machine identity governance as agents, workflows, and embedded features spread across the enterprise. Teams that pair discovery with access-path review, such as the Top 10 NHI Issues, will be better positioned to prevent unmanaged AI from becoming unmanaged access.
For practitioners
- Implement continuous AI discovery Scan cloud accounts, repositories, data platforms, collaboration tools, and internal SaaS settings on an ongoing basis so new AI artefacts are detected as they appear.
- Classify hidden AI by ownership and risk Turn discovered tools, prompts, datasets, and workflows into governed records with named owners, lifecycle status, and data sensitivity labels.
- Map AI dependencies across the estate Link prompts, pipelines, endpoints, and connected datasets so a change in one AI component can be traced to the systems it affects.
- Review access paths behind AI features Check whether copilots, plugins, agents, and internal experiments use service accounts, API keys, or delegated tokens that bypass standard review.
- Use discovery results to reset governance Rebuild approval, monitoring, and compliance processes around the assets you can actually see, then retire controls that assume a complete manual inventory.
Key takeaways
- AI governance fails early when organisations cannot see the AI already in use across cloud, code, and collaboration systems.
- Discovery findings become more valuable when they are tied to ownership, dependency mapping, and identity-aware access review.
- Shadow AI is now a governance and machine identity issue, not just an inventory problem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF and NIST AI 600-1 set the technical controls, and ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN | The article centres on accountability and governance for AI discovery and oversight. |
| NIST AI 600-1 | AI inventory and lifecycle visibility align with GenAI profile expectations. | |
| ISO/IEC 27001:2022 | A.5.9 | Asset inventory controls are directly relevant to unknown AI systems and hidden workflows. |
| GDPR | Art.32 | Shadow AI may process personal data without appropriate security controls or oversight. |
| OWASP Agentic AI Top 10 | Hidden agents and copilots create unmanaged runtime behaviour and tool access risks. |
Assess hidden AI tools for personal data exposure and apply security safeguards where processing occurs.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- AI Discovery: AI discovery is the process of automatically finding AI tools, embedded features, agents, and integrations operating in an environment. It provides the first visibility layer for governance, but it does not by itself explain ownership, permissions, or risk.
- AI Ontology: A structured map of relationships between AI assets such as datasets, prompts, pipelines, applications, and deployment endpoints. It helps teams understand dependencies, ownership, and downstream impact, which turns a static inventory into a governed and queryable view of the AI estate.
- Model Risk Control: A governance control that defines how AI systems are approved, tested, monitored, and retired based on their intended use and potential impact. In practice, it is the mechanism that ensures AI does not operate outside the level of oversight required for its risk profile.
What's in the full article
Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:
- A deeper walk-through of the discovery to inventory to ontology pipeline used to build a governed AI graph.
- Examples of the cloud, code, data, document, and agent platforms that continuous discovery can scan.
- Operational detail on how hidden AI artefacts are turned into ownership records and risk classifications.
- The article's own explanation of why full-stack discovery is different from static inventory checks.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader governance problems that AI sprawl creates.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org