By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: C1.aiPublished August 20, 2026

TL;DR: The first useful step in AI transformation is an executive meeting to establish what is already running, what has failed before, and where control is either too tight or too loose, according to C1.ai. The real governance problem is not model selection but shadow AI, unclear attribution, and program charters that do not reflect operational reality.


At a glance

What this is: This is an opinion-style blog post arguing that AI transformation should begin with an executive truth-finding meeting and a governance charter, not a build decision.

Why it matters: It matters because IAM, NHI, and AI governance teams need a shared starting point for discovering shadow AI, ownership gaps, and control tensions before programs scale.

By the numbers:

👉 Read C1.ai's analysis of the ADAPT phase and AI governance starting points


Context

AI transformation programmes often fail before implementation because leaders cannot agree on the current state of identity, access, and operational ownership. In practice, that means the organisation is guessing about what agents, service accounts, and shadow systems already exist, which makes any later control design incomplete from the start.

The post frames this as a governance problem rather than a technology problem. For identity teams, the key issue is whether the organisation can answer basic questions about non-human activity, accountability, and control boundaries before it asks what to build next.

The article also reflects a familiar pattern in NHI governance: once teams lack a shared view of what is live, they drift into either over-control or under-control. That tension is not unique to AI, but AI makes the consequences visible faster.


Key questions

Q: How should organisations start governing AI agents and shadow automation?

A: Start with inventory, ownership, and traceability before you discuss architecture or use cases. If leaders cannot identify what is running, who owns it, and what it touched, later controls will be partial at best. Discovery is the governance baseline for AI agents, service accounts, and other non-human identities.

Q: Why do AI programmes often fail between innovation and control?

A: They fail when governance is either too heavy for delivery teams or too weak to constrain reuse. That creates workarounds on one side and unmanaged access on the other. A workable programme balances decision speed with clear accountability, so security does not become a bypass trigger.

Q: What do security teams get wrong about Shadow AI?

A: They often treat Shadow AI as an approval problem for software, when it is usually also an identity problem. The hidden risk can be an undocumented token, an over-permissioned service account, or an autonomous agent with unreviewed reach. Inventory the identity layer before you decide the tool is the issue.

Q: Who should own AI governance when business teams are adopting it quickly?

A: Ownership should sit with the business function using AI, supported by IAM, security, and risk teams. That model keeps accountability tied to the actual use case instead of allowing governance to drift into a shared-no-one model.


Technical breakdown

Why the first AI governance problem is inventory, not innovation

The article treats discovery as the prerequisite to any AI programme because control design depends on knowing what already exists. In identity terms, that means establishing an inventory of agents, service accounts, delegated workflows, and human owners before policy or architecture work begins. Without that baseline, governance is reactive and attribution becomes guesswork. The same applies to NHI programmes more broadly: if you cannot enumerate the identities in play, you cannot govern them consistently. This is especially true where AI systems interact with existing service accounts and shared credentials.

Practical implication: start with identity and access inventory across AI-related actors before approving use cases or control standards.

How control tension creates shadow AI and review bottlenecks

The post describes a permanent tension between too much control and too little control. Too much control pushes teams into review queues and workarounds, while too little control allows credentials, autonomy, and reuse to expand without oversight. In identity governance terms, this is a failure to align approval paths, ownership, and operating model. The problem is not that controls exist, but that they are either too detached from delivery or too weak to constrain reuse. That tension shows up in both human IAM and NHI governance when central teams cannot keep pace with operational demand.

Practical implication: design controls around decision speed, ownership, and exception handling so teams do not route around governance.

Why executive charters matter more than slide decks in AI programmes

The article argues that a written charter, not a presentation, is what makes governance durable. A charter captures who owns the programme, what failures it is meant to avoid, and when the approach should be dissolved or changed. For identity practitioners, this is the difference between policy theatre and enforceable governance. If the charter does not define accountability, kill criteria, and operating boundaries, the organisation will keep repeating the same misalignment under a new label. That applies equally to AI, NHI, and access governance programmes.

Practical implication: require a formal charter with ownership, failure history, and exit criteria before the programme moves beyond discovery.


Threat narrative

Attacker objective: The objective is to expand AI use without meaningful governance, creating shadow systems and ambiguous accountability that resist later control.

  1. Entry occurs when unmanaged AI initiatives, shadow tools, or delegated workflows are introduced without a shared inventory or ownership model.
  2. Escalation follows when weak oversight allows credentials, service accounts, and reuse patterns to spread without clear attribution back to a human originator.
  3. Impact emerges as teams lose control over reuse, governance queues stall delivery, and incidents become harder to trace because accountability has already fragmented.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI governance begins with identity truth, not model ambition. The article is right to start with an executive meeting because most programmes fail when leaders cannot agree on what is already running. For identity teams, that means the first control is not a policy or a platform, but a shared inventory of human, NHI, and AI-related access paths. If the organisation cannot name the actors, it cannot assign ownership or judge risk.

Control tension is the real operating model problem. The post correctly identifies the permanent trade-off between too much control and too little control. In practice, that tension shows up when review processes slow delivery enough that teams bypass them, or when governance is so loose that reuse spreads faster than oversight. The lesson for IAM and NHI programmes is that control design must match execution speed.

Written charters matter because governance fails when accountability stays implicit. The article’s insistence on a charter, failure history, and kill criteria is the right instinct. Programmes that do not document why they exist and when they should stop tend to survive long after they stop working. That is a lifecycle governance problem, not just a management preference.

Shadow AI is an identity problem before it is a security problem. Undiscovered agents and unmanaged workflows are just another form of identity sprawl when they can act, reuse, or trigger downstream access. The governance gap is not the novelty of the workload. It is the absence of lifecycle controls that tie activity back to a responsible owner, which is now the minimum bar for AI and NHI programmes.

Identity blast radius increases when attribution collapses. The article’s question about whether teams can trace actions back to a human originator goes to the centre of modern governance. When attribution falls back to generic service accounts, accountability becomes too coarse to support meaningful review or incident response. Practitioners should treat traceability as a first-class control, not a reporting afterthought.

From our research:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • Our research also shows that 97% of NHIs carry excessive privileges, which helps explain why unchecked reuse becomes a governance problem quickly.
  • The next step is to 52 NHI Breaches Analysis for incident patterns that show how visibility gaps become breach paths.

What this signals

Shadow AI will be governed like NHI before it is governed like AI. The operating reality is that anything with delegated access, reusable credentials, or downstream actions behaves like an identity object first. That means identity teams should plan for discovery, ownership, and offboarding as the core controls, not as follow-on tasks after a use case is approved.

With only 5.7% of organisations having full visibility into their service accounts, according to the Ultimate Guide to NHIs, most AI programmes are starting from a weaker baseline than leaders assume. The practical response is to treat traceability and owner attribution as prerequisites for scale.

The strongest programme signal is whether the charter can survive its own success. If governance cannot explain when to loosen control, when to tighten it, and when to stop the methodology, the organisation is running a management exercise rather than an identity programme.


For practitioners

  • Run an executive identity inventory meeting Bring CIO, CISO, CTO, and business leaders into one session to list known agents, service accounts, and delegated workflows, then record where ownership is unclear.
  • Document past programme failures in the charter Write down the failed AI, automation, or CoE initiatives that should not be repeated, and make that history part of the governing document.
  • Set explicit control boundaries for reuse Define where approval is mandatory, where reuse is allowed, and where teams can proceed without routing around governance.
  • Require named accountability for every non-human workflow Ensure every workflow, agent, or service account has a named human owner who can explain what it touched and why it exists.
  • Add kill criteria to the programme charter Specify the conditions that would force redesign or dissolution, including when the methodology no longer supports delivery or governance.

Key takeaways

  • The post argues that AI transformation should begin with an honest inventory of what is already running, because governance cannot be designed around guesswork.
  • Its central operational message is that control tension and unclear accountability create shadow AI, reuse sprawl, and slower incident attribution.
  • For practitioners, the practical move is to anchor AI programmes in chartered ownership, traceability, and explicit exit criteria before scaling anything further.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The post addresses AI agents and governance gaps around runtime control.
OWASP Non-Human Identity Top 10NHI-01Agent and service account inventory is central to the post's governance model.
NIST AI RMFGOVERNThe article focuses on governance, accountability, and programme ownership.
NIST CSF 2.0ID.AM-1Asset management aligns with the need to know what AI-related identities exist.
NIST Zero Trust (SP 800-207)The article's control tension and traceability themes align with zero trust assumptions.

Use OWASP agentic guidance to structure identity, approval, and delegation boundaries for AI systems.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Governance Charter: A written document that defines programme ownership, scope, decision rights, failure history, and exit criteria. In identity programmes, a charter turns governance from a vague intention into an enforceable operating model that can be reviewed, challenged, and retired.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • The exact ADAPT meeting structure and executive roles used to frame the programme.
  • The five-rung maturity ladder and how the self-assessment is expected to work.
  • The specific kill criteria language used to decide when the methodology should be dissolved or restructured.
  • The author’s full explanation of the balance between too much control and too little control.

👉 C1.ai's full post explains the executive meeting, charter structure, and kill criteria in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org