TL;DR: AI governance maturity determines whether organisations can see, govern and prove control across employees, models, applications and agents, according to WitnessAI, yet most remain in early stages and still lack policies to manage AI activity and Shadow AI. Policy exists without runtime enforcement is not maturity; it is a control gap.
At a glance
What this is: This is an analysis of AI governance maturity models and their central finding that many organisations can write policies faster than they can enforce, audit, and prove them across employees, models, applications, and agents.
Why it matters: For IAM, NHI, and AI governance teams, the issue is that governance quality now depends on visibility, runtime control, and evidence, not policy presence alone.
Context
AI governance maturity is the difference between writing AI policy and actually controlling AI behaviour. In this article, the core issue is whether an organisation can inventory AI use, apply governance consistently, and prove that governance when challenged by auditors, boards, or regulators.
The identity question is not limited to human users. As AI expands from chat tools into autonomous actions, governance has to cover employees, models, applications, and agents together, because policy-only programmes miss the runtime layer where real risk emerges.
Shadow AI is the clearest example of that gap. If organisations cannot see the systems people are using or the actions agents are taking, they cannot credibly claim maturity, even if the governance documentation looks complete.
Key questions
Q: How should organisations assess AI governance maturity in practice?
A: Assess maturity by asking whether your programme can prove control, not just describe it. A useful assessment checks inventory completeness, ownership, auditability, risk classification, runtime enforcement, and incident handling. If evidence must be assembled after the fact, the programme is still operating below mature control levels.
Q: Why do AI governance tools need shadow AI discovery?
A: Because policy cannot control what it cannot see. Shadow AI discovery identifies unmanaged applications, embedded AI features, and unsanctioned integrations before they become invisible data paths. Without that discovery layer, governance remains partial and retrospective, which leaves the most exposed systems outside control.
Q: How can organisations tell when AI governance is mature enough for scale?
A: Maturity shows up when every AI action is attributable, every agent has a named owner, and access is tied to an explicit scope that can be reviewed. If approvals still depend on manual queues or informal exception handling, the programme is not ready for broad operational scaling.
Q: How should organizations approach the governance of AI agents?
A: Organizations should adopt a governance framework that incorporates continuous visibility, adaptive IAM practices, and stringent policy-based controls. This ensures that all agent actions are tracked, authorized appropriately, and assessed for compliance.
Technical breakdown
Why policy-first AI governance stalls at runtime
A maturity model only works if it measures operational enforcement, not just written intent. Policy documents can describe acceptable use, risk tiers, and approvals, but they do not stop an employee from using an unsanctioned model or an agent from taking an action that bypasses review. The technical failure is the gap between governance design and runtime control. Mature programmes therefore need visibility, policy evaluation at execution time, audit logging, and escalation paths that are technically enforceable rather than manually remembered.
Practical implication: treat runtime enforcement and evidence generation as core maturity criteria, not optional add-ons.
How Shadow AI breaks inventory-based governance
Shadow AI is unmanaged AI use that sits outside inventory, policy, and oversight. Once users adopt external tools or hidden workflows, the organisation loses the ability to apply risk tiering, data handling rules, or approval paths consistently. This is not just a discovery problem. It is a governance integrity problem, because any maturity score that excludes unknown usage is overstating control. AI governance maturity therefore depends on continuous discovery of tools, models, and agentic workflows across the enterprise.
Practical implication: build continuous discovery and inventory into governance before attempting to score maturity.
What changes when AI systems become agentic
Agentic AI changes the governance surface because the system can take action rather than merely generate output. That adds identity attribution, tool access, and action review to the governance problem. Once an agent can call APIs or trigger workflows, policy cannot stop at acceptable-use language. The model has to cover authorisation, monitoring, and incident response for machine-initiated activity. In maturity terms, agent governance is where many organisations discover that their AI controls were designed for chat, not action.
Practical implication: extend governance to agent identity, tool permissions, and action logging before agent deployments scale.
Threat narrative
Attacker objective: The objective is to use unmanaged AI activity or agentic access to bypass governance and move or act on data without enforceable oversight.
- Entry occurs when employees or teams adopt AI tools outside governed inventory, creating Shadow AI that bypasses policy and oversight.
- Credentialed access or delegated permissions are then used by models, applications, or agents to process data and interact with internal systems.
- Escalation happens when agentic systems or unmanaged tools perform actions beyond the level of review the organisation can actually observe.
- Impact is measured in loss of control, weak auditability, and an inability to prove governance to regulators, boards, or customers.
Breaches seen in the wild
- Vercel Context.ai OAuth Supply Chain Breach: Shadow AI app Context.ai OAuth integration exposes Vercel customer data via unmanaged third-party token.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI governance maturity is now a control problem, not a policy problem. The article’s central point is that governance only counts when it can be enforced across people, models, applications, and agents. That moves the discussion from documentation to operational evidence, which is where most programmes are weakest. Practitioners should measure maturity by what they can observe, control, and prove, not by how complete the policy binder looks.
Shadow AI is the fastest way for maturity scores to become fiction. Any assessment that excludes unsanctioned tools, hidden model use, or unmanaged agent workflows is missing the part of the estate most likely to violate policy. The governance model must therefore include discovery and inventory as preconditions for credible scoring. Without visibility, every downstream control assumption is unreliable.
Agentic AI creates an assumption collapse in governance cadence. Access review and manual oversight models were designed for systems whose risk state persists long enough to be reviewed. That assumption fails when an agent can act at machine speed, use tools dynamically, and finish a task before a human control cycle even starts. Practitioners have to rethink governance as runtime attribution and decision control, not periodic certification.
Framework alignment only matters when it reaches execution. NIST AI RMF, ISO/IEC 42001, the EU AI Act, and DORA all point toward accountability, monitoring, and lifecycle control, but the differentiator is whether those requirements translate into technical enforcement. Organisations that map policy to frameworks without runtime controls are not mature, they are merely documented. The practical test is whether governance evidence exists at the moment risk occurs.
AI governance and NHI governance are converging at the control plane. Once AI systems invoke APIs, access data, and act through delegated permissions, the same governance questions that apply to service accounts also apply to agents. That does not mean the problems are identical, but it does mean identity, authorisation, auditability, and offboarding can no longer be treated as separate disciplines. Security leaders should plan for unified control over human, NHI, and agentic activity.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Agent Observability, Audit and Incident Response Guide
What this signals
AI governance maturity now lives or dies at the enforcement layer. Policies are easy to publish, but they do not prove that employees, applications, and agents are being governed consistently. The organisations that advance fastest will treat runtime controls, auditability, and incident handling as the real maturity markers, not as downstream features.
Shadow AI is a maturity test because hidden usage defeats every later control. If the estate is incomplete, risk scoring becomes fiction and accountability becomes partial. That is why discovery and inventory need to sit before classification, approval, and monitoring in any serious programme.
AI governance decision-making is moving away from the executive suite, with 52% of respondents seeing it shifting toward platform and infrastructure teams rather than the executive suite. That shift means security leaders need stronger operating models, clearer ownership, and better cross-functional governance if they want policy to survive contact with production.
For practitioners
- Implement continuous AI discovery Inventory AI systems in production, pilot, and Shadow AI use across the business so governance scoring is based on complete visibility.
- Tie maturity scoring to runtime evidence Require audit trails, policy enforcement logs, and incident records before assigning a higher maturity level.
- Assign explicit governance ownership Name a single accountable executive and a cross-functional committee with legal, compliance, security, and data science representation.
- Extend controls to agentic systems Define identity attribution, tool permissions, and action monitoring for agents that can trigger workflows or call APIs.
- Test governance against framework requirements Map controls to NIST AI RMF, ISO/IEC 42001, and any applicable regulatory obligations, then verify that implementation evidence exists.
Key takeaways
- AI governance maturity is only meaningful when controls operate across the real AI estate, including Shadow AI and agentic systems.
- The biggest gap is not policy creation but enforcement, auditability, and the ability to prove what happened when AI was used.
- Teams that want higher maturity need discovery, accountable ownership, runtime controls, and evidence that governance can withstand scrutiny.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack surface, NIST AI RMF sets the technical controls, and ISO/IEC 42001:2023 and EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about governance maturity, accountability, and evidence across AI use. |
| MEASURE — AI Risk Measurement and Monitoring | The article stresses monitoring, auditability, and measurable control outcomes. | |
| Recommendation — Map governance ownership and evidence requirements to GOVERN before scoring maturity. Use MEASURE to verify that AI controls produce observable evidence in operation. | ||
| ISO/IEC 42001:2023 | Clauses 5-10 — AI Management System Requirements | The maturity model aligns policies, execution, auditing, and continual improvement. |
| Recommendation — Build an AI management system that turns policy into documented, auditable operational practice. | ||
| EU AI Act | Art.9 — Risk management system | The article maps maturity to lifecycle risk management and continuous control expectations. |
| Recommendation — Implement lifecycle risk management that keeps AI controls continuous and iterative. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agentic systems can act through delegated permissions and require stronger identity control. |
| Recommendation — Audit agent permissions and attribution paths for identity and privilege abuse. | ||
Key terms
- AI Governance Maturity Model: An AI Governance Maturity Model is a structured framework for assessing how well an organization controls AI use across policy, risk, oversight, and operations. It typically measures progression from ad hoc practices to repeatable, monitored, and optimized governance, covering accountability, data controls, model oversight, human review, and incident response.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Runtime Enforcement: Runtime enforcement is the practice of blocking malicious behaviour while software is running, rather than only detecting it after the fact. It monitors process activity, network actions, and privilege changes so a live attack can be interrupted at the point of execution.
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or AI governance programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org