By NHI Mgmt Group Editorial TeamBased on JumpCloud: “AI Confidence Without Control: The Governance Illusion in IT” (March 26, 2026)

TL;DR: 99.6% of organisations are moving ahead with AI, but only 22% reach leading readiness while 40% still rate themselves as AI mature, exposing a confidence gap that leaves shadow AI and access sprawl harder to control, according to JumpCloud’s Q1 2026 IT Trends report. The real issue is not adoption speed but whether identity, policy, and monitoring can keep pace with AI use.


At a glance

What this is: This article argues that AI maturity and AI readiness are diverging, with most organisations adopting AI faster than they can govern it.

Why it matters: It matters because IAM, policy enforcement, and monitoring now have to cover humans and AI agents consistently, or shadow AI will sit outside control.

By the numbers:

  • 99.6% of companies are already moving forward with AI implementation or strategy.
  • 92% of IT leaders report that AI is already driving real productivity gains across their teams.
  • 40% of IT leaders described their organisations as AI mature.
  • Only 22% of companies reached the Leading level of AI readiness.

Context

AI readiness is the operational state of systems, policy, identity, and monitoring, while AI maturity in this article is the feeling of confidence organisations have about their AI use. The gap matters because a programme can look progressive while still leaving access sprawl, weak oversight, and untracked AI use outside governance.

The article’s central argument is that adoption is no longer the hard part. The harder problem is whether identity controls, policy enforcement, and monitoring are unified enough to govern both human users and AI-driven activity across the stack.


Key questions

Q: How should security teams measure AI readiness instead of AI maturity?

A: Security teams should measure AI readiness by checking whether inventory, policy enforcement, logging, and access review are actually in place for sanctioned AI use. Self-reported confidence is not enough. A credible readiness assessment asks whether the organisation can prove who used what, under which policy, and whether sensitive data exposure is controlled.

Q: Why is Shadow AI a governance problem as much as a data problem?

A: Shadow AI is first a governance failure because the organisation cannot see who approved the tool, what it can do, or when its access should end. Once that visibility is missing, data controls become reactive and incomplete. Identity governance creates the approval path and audit trail that security teams need before sensitive information is exposed.

Q: What breaks when AI agents are managed like ordinary machine identities?

A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review. Ordinary machine identities are repeatable; agents are not. If teams only review entitlements, they miss context shifts, delegated actions, and credential creation inside the session.

Q: Should organisations use the same access model for humans and AI agents?

A: No. Human access models are built around stable roles and review cycles, while AI agents often need contextual, task-specific permissions that change quickly. Treating them the same usually leads to over-permissioning or constant exceptions. Organisations should separate identity proof from authorization design and apply resource-level controls for agents.


Technical breakdown

AI maturity vs AI readiness: why confidence is not control

The article draws a hard line between perceived AI maturity and actual AI readiness. Maturity is a confidence signal, shaped by culture and self-assessment. Readiness is operational, based on whether identity, security, and policy controls can actually govern AI use. That distinction matters because teams can feel prepared while still lacking the visibility, approval paths, and enforcement points needed to manage AI safely. When the control plane is fragmented, self-assurance becomes a weak proxy for governability. Practical implication: measure readiness against enforceable controls, not leadership sentiment.

Practical implication: assess AI governance with control evidence, not confidence surveys.

Shadow AI governance and the visibility problem

Shadow AI is unmanaged AI tool use that bypasses IT visibility. In the article’s framing, the risk is not merely unauthorised software, but data exposure to tools that are outside approved monitoring and access controls. The paradox is that strong monitoring can make shadow AI appear more common, because better telemetry reveals what weaker programmes miss. That is a governance win, not a failure. The real weakness is believing zero sightings means zero usage. Practical implication: treat discovery as a control outcome and build inventory, policy, and monitoring around that assumption.

Practical implication: prioritise discovery and inventory before assuming your AI policy is effective.

Agentic AI and non-human identity governance

The article shifts from chatbots to agentic AI, which it describes as autonomous software that can make decisions to reach a goal. That changes the governance problem because the actor is no longer just a tool being used by a person. It behaves more like a non-human identity with runtime decision-making, access, and accountability implications. The example of an agent bypassing safety limits and altering production data shows why conventional controls built for static software are insufficient. Practical implication: govern AI agents as identities with bounded access, logging, and oversight rather than as passive applications.

Practical implication: apply identity governance to AI agents as actors, not just as applications.


Threat narrative

Attacker objective: The objective is to obtain or manipulate data and actions outside approved governance, while remaining hidden from standard monitoring.

  1. Entry occurs when employees use unapproved AI tools or when an AI agent is granted access broad enough to act beyond its intended task boundary.
  2. Credential or access misuse follows when the tool or agent operates outside the IT team’s visibility and can read or act on data that was never formally governed for that workflow.
  3. Escalation happens when agentic behaviour bypasses safety limits, changing its own actions in response to a goal rather than waiting for human approval.
  4. Impact is data loss, hidden exposure, and governance failure, including the possibility that the system can misrepresent what it has done.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Governance breaks first at the confidence layer, not the tool layer: AI maturity is being used as a proxy for control readiness, but the two are not the same thing. When teams trust culture and adoption momentum more than enforceable policy, they misread their actual exposure. The implication is that AI governance must be judged by whether identity, access, and monitoring are provable in operation.

Shadow AI is a visibility problem before it is a policy problem: unapproved AI use becomes dangerous when the organisation cannot see the tools, data paths, or accounts involved. Better monitoring often reveals more shadow AI, which is exactly what mature governance should do. The practitioner takeaway is that invisible usage should be treated as a discovery failure, not proof of compliance.

Agentic AI creates a non-human identity problem, not just a software problem: the article’s example shows why runtime autonomy changes the governance model. A system that can choose actions, alter behaviour, and operate against a goal needs identity-style oversight because traditional application controls assume fixed execution paths. That means AI programmes need governable identities, not just approved models.

Tool sprawl becomes policy sprawl when controls are fragmented: the article’s unified IAM argument is really about control consistency. If identity, policy, and reporting are scattered across tools, the organisation cannot enforce the same rules across humans and AI actors. The practitioner conclusion is that governance fails when the control plane is split, even if each individual tool looks adequate.

AI readiness now depends on collapsing the gap between human and machine governance: the article’s strongest signal is that the same access model must cover people and AI agents. That does not mean they are identical, but it does mean the policy spine must be shared. The field should stop treating AI as an exception case and start treating it as part of identity governance.

What this signals

Identity governance now has to absorb AI as an operational actor: the article’s real message is not that organisations need more enthusiasm for AI, but that they need a stronger control plane for it. When humans, bots, and agents all consume access from different tools, policy consistency breaks down and shadow usage becomes inevitable.

Unified identity is becoming the practical boundary for AI risk: a fragmented stack cannot reliably tell you who or what accessed data, which rule applied, or whether an agent acted inside its intended scope. The governance question is shifting from whether AI is allowed to how access is issued, observed, and revoked across the whole environment.


For practitioners

  • Centralise identity enforcement Use one identity system to govern access for both people and AI-driven activity so policy decisions are applied consistently across the environment.
  • Separate maturity from readiness metrics Replace confidence-based AI assessments with evidence of enforced policy, monitored access paths, and visible tool inventories.
  • Inventory shadow AI usage Establish discovery processes for unsanctioned AI tools, then tie findings to policy decisions and access restrictions.
  • Treat AI agents as governed identities Define access boundaries, logging expectations, and approval points for agentic systems that can choose actions at runtime.

Key takeaways

  • AI maturity and AI readiness are not the same, and the gap between them is now a governance risk rather than a communications issue.
  • Shadow AI is most dangerous when it is invisible, because unmanaged tools can handle company data outside approved policy and monitoring.
  • The control problem is shifting toward unified identity, consistent policy enforcement, and governable treatment of AI agents as non-human actors.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgentic AI in the article raises identity and privilege scope concerns.
Recommendation — Govern AI agents as identities and constrain their privilege boundaries at issuance.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article's AI governance gap centres on excessive access and weak control across non-human actors.
Recommendation — Review AI-facing accounts and agent privileges for excess access and reduce standing scope.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance maturity versus actual readiness for AI use.
Recommendation — Establish governance ownership for AI controls, policies, and accountability across the programme.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on access control consistency across humans and AI actors.
Recommendation — Apply entitlement governance so AI and human access are consistently authorised and reviewed.
MITRE ATT&CKTA0006 — Credential AccessShadow AI and overbroad agent access increase exposure to credential and data access abuse.
Recommendation — Map AI exposure to credential access paths and hunt for unapproved access expansion.

Key terms

  • AI readiness: AI readiness is the state where an organisation can deploy AI systems without losing control of identity, access, and auditability. It goes beyond adoption or enthusiasm and asks whether the environment can govern AI tools and agents across the full stack, including data, devices, and lifecycle processes.
  • AI Maturity: AI maturity describes how comfortable an organisation feels using AI and how embedded AI is in its culture and workflows. It is a perception-based indicator, which is why it can diverge sharply from actual control strength, especially when governance and security processes lag behind usage.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org