By NHI Mgmt Group Editorial TeamBased on C1.ai: “Your AI Strategy Has a Blind Spot” (March 8, 2026)

TL;DR: C1.ai reports that knowledge workers are already using AI tools at scale, but only 18% know their company’s AI policy and 78% are bringing their own tools. The deeper failure is not model quality but the lack of identity, policy, and lifecycle controls that make governed AI easier than shadow AI.


At a glance

What this is: This post argues that enterprise AI governance breaks down when identity, policy, and lifecycle controls cannot keep pace with how employees actually adopt tools.

Why it matters: IAM, NHI, and AI governance teams need to treat AI access as an identity problem, because slow provisioning and weak enforcement push users toward shadow AI paths.

👉 Read C1.ai's analysis of AI governance, identity controls, and shadow AI


Context

AI governance is not just a model-quality problem. It is an access and identity problem when workers can get to tools faster through unmanaged paths than through approved ones.

The article describes a common enterprise pattern: governed AI access is slowed by manual setup, credential handling, approval steps, and fragmented policy controls, while shadow AI becomes the practical default. That makes lifecycle control, visibility, and enforcement the real governance battleground for AI adoption.


Key questions

Q: How should teams stop shadow AI from becoming the default access path?

A: Make the governed path faster and simpler than bypasses. Use self-service requests, risk-based auto-approval, and central policy enforcement so employees can obtain approved AI tools quickly without resorting to consumer accounts or ad hoc integrations.

Q: Why do AI agents need identity and access governance if the model is already strong?

A: Because model strength does not control who or what the agent can touch in production. The real risk comes from standing permissions, weak supervision, and access to tools and data that the task does not require. Governance has to define runtime authority, not just model output quality.

Q: What breaks when AI access still depends on manual setup and approvals?

A: Users bypass the approved route. Slow provisioning creates shadow AI, hides tool usage from IT, and leaves organisations unable to enforce policy where work is actually happening.

Q: When should organisations require human approval for an AI agent action?

A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse. Approval is also warranted when the agent’s decision depends on ambiguous input or external data that cannot be trusted at face value. High-consequence actions need a human stop point.


Technical breakdown

Why AI tool access becomes shadow AI when provisioning is slow

When a legitimate path to AI access takes days, users route around it. That is not a model limitation. It is an identity and governance failure created by slow provisioning, manual approvals, and poor policy execution. The article shows that workers will adopt consumer tools, browser-based assistants, and unmanaged integrations if the approved route is too hard to use. In practice, AI governance succeeds only when the governed path is easier than the ungoverned one.

Practical implication: reduce AI access friction so approved requests are faster than bypasses.

How agent identity changes the governance model for AI tools and MCP servers

The article treats AI agents as first-class identities with credentials, policies, ownership, and lifecycle states. That matters because agent access is not the same as human SaaS access. Agents can call tools, accumulate context, and act through delegated authority, so the control plane must understand who or what is calling the tool, what it can do, and when approval is required. MCP connections make that identity boundary explicit because they expose tool-level permissions that must be governed centrally.

Practical implication: govern AI agents and MCP connections as identities, not as generic application integrations.

Why delegated consent and step-up approval are central to AI governance

Not every AI action deserves the same trust. The article distinguishes low-risk reads from privileged operations such as deleting repositories or rotating credentials. That is a classic delegated-authority problem: some actions can be pre-authorised, while others need just-in-time human confirmation. Without that distinction, organisations either over-restrict useful work or under-protect sensitive operations. The governance issue is not whether an agent can act, but which actions remain bound to human approval at the moment of execution.

Practical implication: tier AI actions by risk and require step-up approval for privileged operations.


Threat narrative

Attacker objective: The objective is to gain useful AI access outside governed controls while keeping identity, policy, and audit visibility weak enough to avoid enforcement.

  1. Entry happens when employees bypass the governed route and adopt personal AI tools, browser assistants, or third-party agents without visibility from IT.
  2. Credential access and tool linkage occur when users create local service accounts, OAuth credentials, or MCP connections to make AI tools work outside managed systems.
  3. Escalation follows when those tools can call sensitive data sources or execute privileged operations without fine-grained policy enforcement or real-time approval.
  4. Impact is shadow AI use with unaudited data access, uncontrolled context sprawl, and governance processes that no longer reflect how work is actually being done.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity, not model quality, is the governance bottleneck in enterprise AI. The article’s core insight is that workers already want AI access, but the approved path is too slow and technical to compete with shadow adoption. That means governance fails at issuance, approval, and enforcement, not at model selection. Practitioners should treat AI adoption as an identity workflow problem first.

Governed AI only works when the access path is faster than the bypass path. Manual provisioning, back-and-forth approvals, and credential juggling create the conditions for shadow AI. Once employees can self-serve unmanaged tools in minutes, governance built for multi-day setup is structurally obsolete. Practitioners need to measure AI control effectiveness by whether approved access beats the convenience of consumer tooling.

Agent identity management is now part of mainstream IAM scope. The article shows that AI agents need identities, ownership, policies, and lifecycle states, not just prompts and model access. That expands identity governance from human accounts and SaaS connectors into tool-level control for agents and MCP servers. Practitioners should reclassify agent access as an identity estate, not a novelty integration layer.

Delegated consent creates a new privilege boundary that traditional IGA does not model well. The article separates low-risk reads from privileged operations such as repository deletion or credential rotation. That is a governance boundary, not a UX detail. The practical implication is that approval logic must move closer to execution time and account for action risk, not just who requested access.

Ephemeral access governance: AI access paths are short, contextual, and often assembled on demand, which means static review cycles miss the real control point. The implication is that identity teams must govern issuance, tool permissioning, and revocation as one continuous workflow.

From our research library:

What this signals

AI governance is becoming an access-control issue, not a model-selection issue. If workers can reach consumer tools more easily than approved ones, identity teams will keep losing the adoption race. The control point shifts to request flow, policy enforcement, and revocation, because those determine whether governed AI is usable enough to matter.

Shadow AI exposes a governance gap that spans human users and AI agents. Humans start the bypass, but agents inherit the consequences when they are granted tool access without ownership, scope, or review. The programme implication is that identity teams need one control plane for both user-scoped assistants and enterprise agents.

Ephemeral access governance: AI access is often assembled for a task and discarded after use, so review cycles that assume stable entitlements miss the real risk window. The practical response is to govern issuance and approval at the moment of access, not after the fact.


For practitioners

  • Map shadow AI entry points Inventory personal assistants, browser-based AI tools, MCP connections, and locally created credentials that bypass formal request workflows.
  • Classify AI agents as governed identities Assign ownership, lifecycle states, and scoped permissions to enterprise agents and user-scoped assistants instead of treating them as unmanaged integrations.
  • Separate low-risk from privileged AI actions Define which tool calls can be auto-approved and which operations require step-up human approval at execution time.
  • Collapse credential handling into central vaulting Keep service accounts, OAuth credentials, and other AI-related secrets out of laptops and local configuration files, and revoke them instantly when no longer needed.
  • Measure whether governed access is faster than bypass Track request-to-access time for approved AI tools and compare it with the effort required to adopt unmanaged alternatives.

Key takeaways

  • AI adoption becomes a governance failure when the approved path is slower and more technical than the shadow path.
  • The article ties enterprise AI use to identity, policy, lifecycle, and audit controls rather than to model quality alone.
  • Practitioners should focus on self-service access, risk-based approval, and central secret handling to keep AI use visible and governable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on AI agents acting with delegated authority and scoped permissions.
Recommendation — Treat AI agents as governed identities and limit privilege to the minimum action scope.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about organisational AI governance, ownership, and accountability structures.
Recommendation — Define clear AI governance ownership and approval boundaries before broad deployment.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationAI tools, MCP servers, and service accounts rely on identity-bound authentication patterns.
Recommendation — Centralise authentication for AI tools and remove local credential handling from endpoints.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article emphasises fine-grained permissions for AI tool calls and delegated access.
Recommendation — Apply least-privilege access permissions to AI tool calls and delegated operations.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article highlights credential management, rotation, and revocation for AI access.
Recommendation — Use authenticator management to rotate and revoke AI-related credentials centrally.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
  • Delegated Consent: The authorisation a user or administrator gives to an application to act on their behalf. Once granted, that consent can outlive a password reset or even off-boarding unless it is explicitly reviewed and revoked, creating long-lived access that security teams must govern.
  • MCP Connection: An MCP Connection is the live link between an AI agent and an external tool, data source, or service using the Model Context Protocol. It defines how the agent discovers capabilities, exchanges context, and requests actions. Security controls should govern authentication, authorization, scope, logging, and revocation for each connection.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • The step-by-step access flow for governed AI provisioning, including Slack approval and policy-based auto-approval
  • The operational distinctions between personal assistants and enterprise agents, including ownership and lifecycle handling
  • The credential vaulting and audit workflow behind tool-level enforcement for AI access
  • The practical comparison between manual setup for MCP access and a governed access path

👉 The full C1.ai post covers the setup friction, governance workflow, and access model in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org