By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Grip SecurityPublished August 10, 2026

TL;DR: Mature governance depends on connecting AI visibility to identity context, enforcement, and continuous control, because policies alone do not constrain AI applications, agents, OAuth grants, or the data they can reach, according to Grip Security. The practical shift is from inventory management to operational control over access and drift.


At a glance

What this is: This is Grip Security’s five-stage AI governance maturity model, and its key finding is that governance only becomes real when AI visibility is connected to identity, permissions, access, and continuous control.

Why it matters: It matters because IAM, NHI, and security teams need to govern AI systems as access-bearing entities, not just as applications on an approved list.

By the numbers:

👉 Read Grip Security's AI governance maturity model for visibility and continuous control


Context

AI governance fails when organisations treat policies as the control, rather than the mechanism that must be enforced across identities, permissions, OAuth grants, integrations, and data access. In practice, the primary challenge is not whether AI exists, but whether teams can govern what AI can do once it is embedded in SaaS and workflow systems.

That makes this topic directly relevant to IAM and NHI programmes. Human identities, AI agents, and other non-human identities increasingly sit inside the same access graph, so governance maturity now depends on identity context, lifecycle awareness, and enforceable controls rather than periodic review alone.


Key questions

Q: How should security teams govern AI features embedded in SaaS applications?

A: Treat embedded AI as a machine identity problem with data access implications. Inventory the feature, map the connected permissions, define what data it may use, and monitor retention and sharing paths. If the AI feature can read corporate content, it needs explicit approval, logging, and periodic review like any other privileged integration.

Q: Why do AI agents complicate existing IAM and NHI controls?

A: They complicate control design because they can select actions at runtime, call multiple APIs, and move authority across systems without a human session boundary. That breaks assumptions built into static entitlements and traditional service account management. Governance has to account for delegated action, changing context, and auditability across the full execution chain.

Q: What breaks when organisations stop at AI inventory and do not enforce policy?

A: The gap is between knowing AI exists and being able to change what it can access. Without enforcement, approved-use policies remain advisory, excessive permissions stay live, and risky integrations keep operating. The result is governance theatre, where the organisation can describe AI risk but cannot reduce it.

Q: Who should own AI governance when AI touches identity and access?

A: Ownership should sit with the team that can explain the AI system’s access, purpose, and operating boundaries end to end. In practice, that means AI governance must connect security, IAM, data, and engineering accountability so the system is not treated as a floating experiment. If ownership is unclear, lifecycle control will be inconsistent.


Technical breakdown

Why AI governance maturity starts with visibility

Visibility is the discovery layer for AI governance. It answers where AI is operating across applications, embedded features, browser-based tools, and SaaS-to-SaaS workflows. Without that inventory, teams cannot tell whether they are governing sanctioned AI only or also shadow AI that entered through ordinary user behaviour. Visibility is necessary, but it is not a control because discovery does not constrain permissions, access paths, or data exposure.

Practical implication: build continuous discovery before trying to automate policy enforcement.

Identity context, OAuth grants, and AI agent permissions

Context is where AI governance becomes an identity problem. Security teams need to map AI applications and AI agents to the human and non-human identities that operate through them, then examine OAuth scopes, integrations, ownership, and the data those relationships can reach. A discovered AI tool with minimal permissions is a different risk object from an AI agent with broad delegated access into enterprise SaaS.

Practical implication: inventory OAuth grants and ownership alongside AI applications, not separately.

Continuous control for changing AI environments

Continuous control means governance decisions survive environmental change. New AI features appear inside SaaS products, users grant fresh integrations, permissions drift, and non-human identities persist after their original purpose has ended. The technical challenge is shortening the gap between change, detection, decision, and remediation. That is why maturity ends with monitoring, drift detection, and ongoing remediation rather than a one-time policy decision.

Practical implication: link detection, review, and remediation so AI access changes are acted on immediately.


NHI Mgmt Group analysis

AI governance maturity is really identity governance maturity in disguise. The model is useful because it shows that policy quality is not the limiting factor once AI starts operating through delegated access, persistent permissions, and non-human identities. The field should stop treating AI governance as a documentation exercise and start treating it as an access-control and lifecycle problem. Practitioners should evaluate AI governance through identity context, not committee count.

Visibility without enforcement creates governance theatre. Discovery can map the surface area of AI use, but it does not change what those systems can reach. That distinction matters because many organisations believe inventory equals control, when in fact the real risk sits in unmanaged permissions and stale access paths. The practical conclusion is that visibility should be judged by how quickly it feeds enforcement.

Continuous control is the named concept this maturity model sharpens. It describes the ability to keep governance decisions aligned with a moving AI estate as permissions, integrations, and identities change. This is especially relevant where AI agents and other non-human identities retain access after the original business purpose has passed. Practitioners should use this lens to measure drift, not just policy coverage.

Shadow AI changes the governance baseline for enterprise SaaS. The article’s point that AI is becoming embedded in ordinary applications means governance cannot rely on approved app lists alone. AI functionality can appear inside systems already trusted by users and admins, which compresses the time between adoption and exposure. Teams should treat embedded AI as a discovery and entitlement problem, not just an AI policy issue.

The maturity model validates identity context as the control plane for AI risk. Human identities, OAuth grants, and AI agents now form one operational chain, and governance fails if any part of that chain is invisible. That makes IAM, IGA, and NHI teams central to AI governance programmes, not supporting functions. Practitioners should align ownership of AI controls with identity governance operations.

What this signals

Continuous control will become the baseline expectation for AI governance programmes. As AI features spread through ordinary SaaS, periodic review will miss too much. Teams need to unify discovery, entitlement data, and remediation workflows so AI risk can be managed at the pace of change, not the pace of committee cycles.

Identity governance teams should expect AI agent oversight to join workload and service account oversight. Once AI agents hold permissions and OAuth grants, they need the same lifecycle discipline as other non-human identities. The practical shift is from approving AI use to continuously proving that the access still fits the business purpose.

The next maturity step for most organisations is not more policy language but tighter linkage between identity systems, SaaS posture data, and remediation controls. That is where governance becomes operational and where risk starts to move.


For practitioners

  • Build continuous AI discovery Track standalone AI tools, embedded SaaS AI features, browser-based AI use, and AI-enabled workflows in one inventory so shadow AI does not sit outside governance.
  • Map AI access to identity context For each AI application or agent, record the associated human identity, non-human identity, OAuth grants, integrations, and data reach so governance decisions are based on actual exposure.
  • Operationalise enforcement paths Define how excessive permissions, risky OAuth grants, and ownership gaps will be reduced, revoked, or escalated so policy violations produce a measurable change in access.
  • Monitor for permission drift Set alerts for new AI features, changed scopes, new integrations, and persistent non-human identities so remediation happens when the environment changes, not at the next review cycle.

Key takeaways

  • AI governance fails when organisations confuse visibility with control, because discovery alone does not change permissions or data reach.
  • The strongest signal in this model is the identity bridge, where human identities, AI agents, OAuth grants, and SaaS integrations form one governable access chain.
  • Continuous control is the maturity destination because AI environments change faster than periodic reviews can safely absorb.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article centers on AI agents, delegated access, and governance of their permissions.
OWASP Non-Human Identity Top 10NHI-01AI agents and OAuth-connected automations behave like non-human identities with governed access.
NIST AI RMFGOVERNThe article is a governance maturity model, so accountability and oversight are central.
NIST CSF 2.0PR.AC-1The model ties AI governance to identity context, access, and enforcement.
NIST Zero Trust (SP 800-207)Continuous verification and dynamic access decisions fit the model's continuous control stage.

Use agentic AI guidance to map agent permissions, owners, and lifecycle controls before expanding deployment.


Key terms

  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • OAuth Grant: An OAuth grant is the delegated permission an application receives to act on a user's behalf without storing the user's password. In NHI governance, it should be treated as a standing identity relationship with scope, ownership, and revocation requirements, not as a one-time setup detail.
  • Continuous Control: A continuous control is a governance mechanism that operates on current state instead of waiting for periodic checkpoints. For access review, that means feeding current entitlement data into review decisions and closing the loop with automatic revocation or follow-up when access is no longer justified.

What's in the full article

Grip Security's full post covers the operational detail this analysis intentionally leaves for the source:

  • The five-stage maturity table with stage-by-stage primary questions and core capabilities.
  • The seven self-assessment questions teams can use to locate their current maturity stage.
  • The operational barriers that slow progression from governance to enforcement and continuous control.
  • The full explanation of how AI governance becomes an identity problem as permissions, OAuth grants, and ownership expand.

👉 Grip Security's full post expands the maturity stages, assessment questions, and enforcement gaps in detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to turn identity controls into measurable security outcomes across modern enterprise environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org