By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: ArmorCodePublished March 23, 2026

TL;DR: Purple Book Community’s survey of 650+ senior cybersecurity leaders across seven industries finds a wide gap between claimed AI visibility and operational control, according to ArmorCode, with 59% still admitting shadow AI and 70% seeing AI code vulnerabilities reach production. The report shows why inventory alone is not governance, and why control, remediation, and policy enforcement now matter more than awareness.


At a glance

What this is: This is a research report on AI risk management that finds security leaders are more confident in their AI governance than their operational controls justify.

Why it matters: It matters to IAM practitioners because AI systems, shadow AI, and AI-assisted development create governance gaps that intersect with identity, access, and control enforcement across human and non-human programmes.

By the numbers:

👉 Read ArmorCode's analysis of the AI risk management confidence gap


Context

AI governance is increasingly being measured by whether organisations can translate visibility into control, not by whether they can produce an inventory. The central problem in this report is that security teams often believe their AI programmes are governed while shadow systems, AI-generated code, and tool fragmentation continue to outpace enforcement.

For identity and access teams, the practical issue is that AI programmes inherit the same lifecycle problems seen in other control domains: unclear ownership, weak approval boundaries, and limited runtime oversight. When AI is allowed to move from experimentation into production without governance discipline, it becomes a management problem as much as a technical one.


Key questions

Q: How should security teams govern AI agents without creating a manual review bottleneck?

A: Use policy, automation, and class-based controls so agents are provisioned through deployment pipelines, not ticket queues. Every agent should have a unique identity, a named owner, and a bounded scope. Human review should focus on exceptions, anomalous behavior, and changes in business context, not on approving each routine action.

Q: Why do complete AI inventories still miss shadow AI in practice?

A: Because discovery and governance are not the same thing. An inventory can be complete on paper while unsanctioned models, copilots, or integrations continue operating outside ownership, approval, and runtime monitoring. Organisations need lifecycle control, not just discovery snapshots, if they want to stop shadow AI from becoming a permanent blind spot.

Q: What do security teams get wrong about AI-generated code risk?

A: They often focus on catching insecure output after code is written, which is too late for AI-native workflows. The more important control point is the moment the agent is allowed to initiate the action. If that step is not governed, testing becomes a detection layer rather than a prevention layer.

Q: How can organisations tell whether AI governance is actually working?

A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.


Technical breakdown

Why complete AI inventory can still miss shadow AI

An AI inventory is only useful if it reflects what is actually operating, not what teams think is present. Shadow AI appears when tools, models, or automation paths are introduced outside approved governance, often through development workflows, embedded copilots, or unsanctioned integrations. A complete inventory claim can coexist with unmanaged systems if discovery is periodic, partial, or disconnected from operational ownership. The key failure is treating visibility as a one-time discovery exercise rather than an ongoing control process.

Practical implication: tie discovery to continuous ownership checks, approval workflows, and runtime monitoring so shadow AI cannot persist between reviews.

Why AI-generated code creates a governance blind spot

AI-assisted development changes the control problem because code can move from suggestion to production faster than normal review cycles can absorb. The issue is not just whether a vulnerability scanner exists, but whether the organisation can prove that generated code is being validated before deployment and after changes propagate. If leaders trust detection tooling but still see vulnerabilities land in production, the problem is usually process latency, exception handling, or weak release gating rather than tool absence.

Practical implication: enforce release gates and exception handling around AI-generated code, with explicit ownership for review, approval, and rollback.

What tool sprawl does to AI governance

Tool sprawl fragments responsibility across overlapping products, dashboards, and teams, which weakens remediation even when teams can see the risk. In governance terms, this creates a coordination failure: alerts arrive, but no single workflow owns prioritisation, assignment, and closure. For AI risk, that matters because vulnerabilities, shadow systems, and policy exceptions all require different responses but compete for the same finite security capacity. Governance breaks when control signals do not map cleanly to action.

Practical implication: consolidate AI risk triage into a single operating model with named owners and a clear path from finding to remediation.


Threat narrative

Attacker objective: The objective is to exploit governance gaps in AI adoption so that unreviewed code, unmanaged tooling, or ungoverned access creates operational exposure at scale.

  1. Entry occurs when AI tools, code assistants, or shadow systems are introduced outside formal governance channels and become part of the production environment.
  2. Escalation follows when those unmanaged AI paths generate code, decisions, or integrations that bypass review and introduce vulnerabilities or unapproved access paths.
  3. Impact emerges when vulnerable AI-generated code reaches production or shadow AI remains ungoverned, creating a durable control gap across the enterprise.

NHI Mgmt Group analysis

The confidence gap is now a governance problem, not an awareness problem. Security leaders in this survey already know AI is spreading, yet the data shows that knowledge is not translating into control. That distinction matters because governance failure is usually caused by missing ownership, weak enforcement, or unclear decision rights, not lack of visibility. Practitioners should treat AI governance as an operating model issue, not a reporting exercise.

Shadow AI is the clearest sign that discovery and control have been decoupled. Organisations can claim full inventory while still carrying unmanaged AI because discovery is not the same as lifecycle governance. The same pattern appears in identity programmes when assets are known but not owned, reviewed, or decommissioned. For AI security, the named failure mode is a visibility-to-control gap, and it should be managed as a lifecycle problem.

AI-generated code forces security teams to confront a new control latency problem. If 70% of leaders have already seen generated-code vulnerabilities reach production, the issue is not whether detection exists but whether approval and enforcement happen quickly enough to matter. This is where AI governance intersects with IAM and PAM discipline, because review rights, release rights, and exception rights all shape what reaches production. Practitioners should align control speed with development speed.

Tool sprawl is becoming a prioritisation tax on AI risk management. The more teams split AI risk across separate dashboards, scanners, and workflow owners, the harder it becomes to turn findings into remediation. That creates governance debt: an accumulation of unresolved exceptions, duplicated alerts, and blurred accountability. Security teams should reduce control fragmentation before expecting meaningful improvement in AI risk outcomes.

AI governance will increasingly resemble identity governance for dynamic systems. AI systems are being embedded into operational workflows fast enough that static review models will struggle to keep up. The useful analogy is not just cloud security but lifecycle control: who owns the system, what it can do, when it is reviewed, and how quickly it is retired. Practitioners should expect AI governance to converge with identity and access governance patterns.

What this signals

Confidence is becoming a poor proxy for control in AI programmes. Security teams should assume that visibility dashboards and detection claims may overstate actual governance maturity, especially where change is happening faster than policy enforcement. The operational priority is to close the gap between discovery and control, not to add another reporting layer.

AI governance will increasingly depend on identity-style ownership models. As AI systems become more embedded in delivery pipelines, teams will need named owners, approval boundaries, and lifecycle controls that look closer to IAM than traditional project oversight. That shift is already visible in the rise of unmanaged AI and the pressure it places on access governance.

The control question is shifting from whether AI exists to whether it can act without accountability. For practitioners, that means continuous review of AI access paths, exception handling, and release governance, supported by controls aligned to NIST Cybersecurity Framework 2.0 and NIST AI Risk Management Framework.


For practitioners

  • Establish continuous AI inventory controls Move beyond periodic discovery by tying asset ownership, approval status, and runtime validation to a continuous control process that can detect shadow AI after deployment.
  • Gate AI-generated code before production Require explicit review, approval, and exception handling for generated code before release, and ensure rollback ownership is assigned when vulnerabilities bypass normal checks.
  • Reduce AI risk tool fragmentation Create a single triage workflow that assigns findings, prioritises remediation, and records closure so separate scanners do not dilute accountability.
  • Map AI governance to identity ownership Assign named owners for AI systems, their access paths, and their exceptions so governance mirrors the way identity programmes track entitlement, approval, and lifecycle states.
  • Measure control latency, not just coverage Track the time between AI risk discovery and enforcement action, because a complete inventory does not matter if remediation arrives after production impact.

Key takeaways

  • The report shows that AI security confidence is outpacing operational control, creating a governance gap that is already visible in production risk.
  • Shadow AI, AI-generated code, and tool sprawl are the three clearest signs that visibility alone is not enough to govern AI safely.
  • Practitioners should shift from inventory-based assurance to lifecycle ownership, release gating, and control-latency measurement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNThe report centres on accountability and governance for AI risk management.
NIST CSF 2.0GV.RR-01AI risk becomes a governance and risk-management issue under CSF 2.0.
OWASP Agentic AI Top 10Shadow AI and generated-code risk overlap with agentic application control gaps.
NIST SP 800-53 Rev 5CM-8AI inventory claims map directly to system component tracking and governance.
MITRE ATT&CKTA0003 , Persistence; TA0009 , Collection; TA0010 , ExfiltrationShadow AI and ungoverned AI code can support persistent access and data movement paths.

Use CSF governance and risk functions to tie AI inventory, approvals, and remediation into one operating model.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Control Latency: Control latency is the delay between an identity change and the point at which governance reflects that change. In practice, long latency means revocations, approvals, and policy enforcement happen after risk has already increased, which weakens both security and audit confidence.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.

What's in the full report

ArmorCode's full report covers the operational detail this post intentionally leaves for the source:

  • Cross-tab analysis of the confidence gap by survey segment and industry
  • The report's full breakdown of shadow AI, detection trust, and tool-sprawl effects
  • Survey methodology and respondent profile for the 650+ senior security leaders
  • The complete set of research charts and data slices behind the executive summary

👉 ArmorCode's full report covers the survey cross-tabs, methodology, and control-gap detail behind the findings.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and lifecycle control. It gives practitioners a practical foundation for applying identity discipline to dynamic systems and production access decisions.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org