TL;DR: AI-generated deepfakes, hallucinations and shadow AI are pushing organisations toward continuous verification of identities, devices and actions rather than default trust, according to Commvault. The governance lesson is clear: responsible AI adoption succeeds when policy, guardrails and approved tools reduce blind trust without blocking productivity.
At a glance
What this is: This is a Commvault discussion of AI trust, zero trust and shadow AI that argues organisations should verify identities and actions continuously as AI becomes more convincing and more embedded in daily work.
Why it matters: It matters because IAM, NHI and AI governance teams now need controls that handle human users, AI tools and agentic workflows under the same verification model, rather than assuming one login or one approval is enough.
👉 Read Commvault's discussion of AI trust, zero trust and shadow AI
Context
AI trust is no longer just a question of whether a system is accurate. It is a governance problem about whether identities, devices and actions can be verified continuously when AI can imitate people, generate convincing content and accelerate shadow AI adoption. For IAM teams, that shifts the conversation from one-time authentication to ongoing trust evaluation across human and machine activity.
The article is strongest where it connects AI adoption to operational controls rather than abstract concern. The boundary between human identity, digital trust and non-human identity is becoming more visible as employees use approved and unapproved AI tools, and as organisations try to decide what should be trusted, monitored or blocked. That makes the zero trust model more relevant to AI governance than to simple access control.
Key questions
Q: How should organisations govern AI usage when employees use unapproved tools?
A: Organisations should start with visibility, not enforcement. If teams cannot see which apps, agents, or workflows are being used, they cannot assess data exposure or apply meaningful controls. Once usage is mapped, policy can shift from blanket bans to context-based decisions that reflect sensitivity, role, and business purpose.
Q: Why do deepfakes change identity verification requirements?
A: Deepfakes change requirements because they let attackers create believable but false evidence that can pass weak visual checks. Identity verification must therefore move from judging what looks real to verifying whether the entire evidence chain is trustworthy. That includes media authenticity, capture integrity, and stronger assurance criteria for higher-risk transactions.
Q: What breaks when organisations trust AI outputs too quickly?
A: Decision quality breaks first, followed by governance and accountability. If teams accept outputs without verifying source, context or policy, AI can accelerate bad decisions just as easily as good ones. The fix is not to slow every workflow, but to add stronger checks where the business impact is highest.
Q: Who is accountable when shadow AI creates spend and compliance risk?
A: Accountability should sit with the business owner of the workflow, the identity that initiated the activity, and the governance function that approved or failed to detect it. If no one can trace an AI interaction back to a named owner, the organisation has already lost control of both spend and policy enforcement.
Technical breakdown
Why continuous verification matters in AI-driven trust models
Zero trust in an AI environment means trust is never permanent. A user, device or application may pass one check and still need to be revalidated when context changes, such as a new session, sensitive action or anomalous request. That matters because AI can produce plausible but false outputs, imitate human patterns and accelerate decisions faster than manual review can keep up. The model is less about distrusting people and more about limiting how far a single successful login can carry an actor, whether human or machine.
Practical implication: move from static access approval to contextual checks that re-evaluate risk at each sensitive action.
Shadow AI as an identity governance problem
Shadow AI is not only a software procurement issue. It is an identity and governance problem because unmanaged tools create unclear data paths, unclear ownership and unclear accountability for who or what is acting. If employees can spin up AI services without oversight, organisations lose visibility into credentials, data access and delegated behaviour. That is especially important where AI systems can be connected to internal tools, because the organisation may be granting machine-like access without treating those tools as governed identities.
Practical implication: inventory approved and unapproved AI tools as governed access paths, not just as applications.
Why deepfakes raise the bar for trust decisions
Deepfakes change the trust model because the old visual or auditory cues used in human verification can no longer be relied on. A convincing voice, image or video may be enough to trigger unsafe decisions if the organisation depends on informal human judgement. That does not mean every interaction needs heavy friction, but it does mean sensitive approvals, fund transfers and identity recovery processes need stronger verification than a call or a message. The article points toward a broader principle: authenticity must be proven, not assumed.
Practical implication: strengthen out-of-band verification for high-risk requests and identity recovery flows.
Threat narrative
Attacker objective: The objective is to manipulate decisions, impersonate trusted parties or gain ungoverned access through AI-enabled trust abuse.
- Entry occurs when employees adopt approved or shadow AI tools and begin trusting outputs, prompts or interactions that appear legitimate.
- Escalation happens when AI systems are given access to sensitive workflows, data or approvals without sufficient contextual verification or governance.
- Impact appears when fake content, impersonation or unmanaged AI use leads to poor decisions, data exposure or loss of trust in internal processes.
NHI Mgmt Group analysis
Continuous verification is becoming the operating model for AI trust. The article reinforces a structural shift: organisations can no longer treat identity assurance as a one-time event. When AI can imitate people, generate content and act inside workflows, trust has to be re-established at the point of action. That aligns with zero trust architecture and with the broader move toward contextual identity decisions in both human and machine workflows. Practitioners should treat every sensitive AI-enabled interaction as a re-verification moment.
Shadow AI is really shadow access. Unapproved AI tools are not just policy exceptions, they are unmanaged pathways into data, systems and decision processes. Once those tools connect to internal content or automation, they behave like non-human identities with unclear lifecycle ownership. That is where identity governance, secrets control and approval workflows intersect. The practical conclusion is that AI inventory and access inventory must be managed together.
Trust in AI depends on stronger assurance, not broader suspicion. The article avoids the common trap of framing zero trust as distrust of people. That distinction matters for governance because the goal is to reduce false confidence, not employee autonomy. The right pattern is to combine policy, verification and user enablement so that AI adoption stays productive while risky actions receive more scrutiny. Practitioners should see trust as a control objective, not a sentiment.
Deepfake resilience now belongs in identity recovery and approvals design. Synthetic audio and video make social engineering more scalable and more convincing, especially in workflows that rely on human familiarity. The governance gap is not just user awareness, but the assumption that a familiar voice or face is enough evidence. Organisations should redesign high-risk approval and recovery paths so that authenticity is confirmed through stronger controls, not social recognition.
Verification trust gap: AI adoption is exposing the gap between what organisations assume they can trust and what they can actually verify. That gap spans human identity, machine identity and AI-generated content. The longer organisations leave that gap unmanaged, the more they will rely on informal judgement in places where repeatable assurance is required. Practitioners should close the gap with explicit policy, telemetry and stronger identity proofing.
What this signals
AI governance teams should expect the trust conversation to shift from authentication to assurance. The practical change is not simply tighter login policy. It is broader lifecycle control over AI tools, richer telemetry on sensitive actions and better separation between approved automation and unmanaged shadow AI.
Verification trust gap: the more AI systems can imitate humans, the more organisations need evidence-based identity assurance. That means stronger recovery paths, better approval design and more explicit ownership of machine-like access. For IAM and NHI programmes, the next maturity step is to manage AI-enabled trust decisions as governed access, not informal judgement.
For practitioners
- Map AI tools to governed access paths Inventory approved and shadow AI tools alongside the identities, data sets and internal systems they can reach. Treat each connection as an access path that needs ownership, logging and lifecycle control, not as a simple software install.
- Add contextual checks to high-risk AI actions Require additional verification when AI-enabled workflows touch finance, identity recovery, privileged approvals or data export. Pair step-up verification with policy-based restrictions so the system re-checks trust at the moment of impact.
- Redesign identity recovery for deepfake resistance Move high-risk recovery and approval flows away from voice-only or chat-only confirmation. Use out-of-band validation, enforced callback procedures and secondary approver rules for requests that would change access or move funds.
- Govern shadow AI as a lifecycle issue Build a process to approve, monitor and retire AI tools just as you would other access-bearing systems. Include data handling review, owner assignment and offboarding so unmanaged tools do not persist after their business use has ended.
Key takeaways
- AI trust is becoming a verification problem, not a default assumption problem.
- Shadow AI and deepfakes both expose the same governance weakness: organisations trust too much without enough proof.
- The right response is continuous verification, stronger approval design and explicit lifecycle control for AI tools.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN | The article is about trust, accountability and governance for AI use. |
| NIST Zero Trust (SP 800-207) | Section 2.1 | Continuous verification is the article's core operating model. |
| NIST CSF 2.0 | PR.AC-4 | The post focuses on access control and continuous identity validation. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is directly relevant to governing approved and shadow AI tools. |
| OWASP Agentic AI Top 10 | The article touches AI systems that imitate people and act in workflows. |
Assign governance ownership for AI tools and require policy-backed approval for high-risk use.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Continuous Verification: A Zero Trust practice that re-evaluates trust during the session instead of relying on a single successful login. The control is stronger when context signals are available in real time and when the identity programme can act on those signals without creating excessive exceptions.
- Deepfake: Synthetic or altered media created with AI or machine learning so that a person appears to say or do something they never did. In security terms, deepfakes are trust attacks that can distort identity verification, approval workflows, and fraud detection.
- Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
What's in the full article
Commvault's full article covers the conversational framing, examples and episode context this post intentionally leaves for the source:
- The full episode discussion with Diana Kelley on how trust changes as AI systems imitate people and make decisions.
- The practical examples used to explain zero trust, shadow AI and continuous verification in a business setting.
- The broader Ready. Or Not. episode context that links agentic AI, cyber resilience and data management.
- The original FAQ-style answers on digital trust, deepfakes, zero trust and shadow AI.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security and secrets management. It is designed for practitioners who need a consistent way to govern human, machine and AI-enabled access.
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org