By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Noma SecurityPublished October 10, 2025

TL;DR: ChatGPT Apps lower the barrier to third-party integration by letting users connect external services through prompts, while OpenAI’s Apps SDK turns any MCP server into a deployable app with contextual data-sharing and autonomous actions, according to Noma Security. The governance problem is no longer connector setup, but visibility, privilege scope, and control over AI-mediated access paths.


At a glance

What this is: ChatGPT Apps make third-party integrations conversational, which accelerates adoption and expands the number of external endpoints receiving context from AI workflows.

Why it matters: IAM, PAM, and NHI teams need to treat conversational app adoption as a governance problem because permissions, identity scope, and data sharing now move through AI-mediated paths rather than explicit admin workflows.

👉 Read Noma Security's analysis of ChatGPT Apps, MCP sprawl, and AI integration risk


Context

ChatGPT Apps create a governance gap because users can connect external services through natural language rather than centrally approved configuration. That shifts the control problem from traditional app onboarding to AI-mediated access, where the organisation may not see what was connected, what identity was used, or what context left the environment.

The identity angle is real because every app connection inherits some combination of user permission, service account scope, or remote MCP access pattern. In practice, that means IAM, PAM, and NHI governance must extend to conversational integrations, not just dashboards and APIs. The starting position described in the article is increasingly typical of how AI adoption spreads, which is why visibility and lifecycle control matter early.


Key questions

Q: How should security teams govern ChatGPT Apps that connect to external services?

A: Treat ChatGPT Apps as governed integrations, not simple productivity add-ons. Require approval before deployment, bind each app to a managed identity, and track what data it can access through conversation context. If the app can act on behalf of users or systems, it needs lifecycle controls, revocation, and auditability just like any other third-party access path.

Q: Why do conversational AI systems create new identity and access risks?

A: Because they can combine data retrieval, decision-making, and execution in a single interaction. That collapses the gap between information access and business action, which traditional IAM and security tools were not built to manage. The result is higher exposure when the system can modify records or disclose sensitive guest data.

Q: What breaks when AI apps are allowed to run under broad credentials?

A: Least privilege breaks first, because the app can access more than the initiating user should reach directly. Then traceability weakens, because security teams can no longer tell whether the action came from the user, the model, or the integration. Broad credentials turn a convenience layer into a delegated control plane.

Q: Who is accountable when a ChatGPT App leaks data or triggers the wrong action?

A: Accountability should sit with the business owner of the integration, the security team that approved the access model, and the platform team that manages the identity behind it. If no one can revoke the app, review its scope, or prove what context it received, governance has failed even if the underlying model behaved as designed.


Technical breakdown

How ChatGPT Apps change integration mechanics

ChatGPT Apps shift the integration model from explicit connector setup to prompt-mediated invocation. Instead of a user navigating an admin console, the model interprets intent, selects a relevant app, and passes conversational context to an external endpoint. That makes the app layer both a tool interface and a data conduit. The security consequence is that the organisation no longer controls every handoff directly, because the model decides what context is relevant enough to share. Practical governance has to account for discovery, authorisation, and the boundary between model reasoning and external execution.

Practical implication: inventory every prompt-accessible integration path and require pre-deployment review for app-to-data access.

Why remote MCP endpoints create identity and trust ambiguity

Remote MCP connections make the trust boundary harder to define because the endpoint may sit outside the organisation while still receiving conversation context and tool requests. In identity terms, the question is not only who authenticated, but which identity or privilege set the remote system is effectively acting under. If a developer account, user credential, or over-broad service identity is embedded in the flow, the resulting access path can exceed what the end user should ever have reached directly. That is why traditional app inventory is not enough.

Practical implication: map each MCP endpoint to the identity it actually exercises and remove any identity that can outscope the user.

Why shadow AI becomes a control-plane problem

Shadow AI is not just undiscovered usage of a chatbot. In this pattern it becomes unmanaged application distribution, because users can add apps that interact in real time, exchange context, and invoke actions without central oversight. The control-plane issue is lifecycle governance: who approved the integration, who can revoke it, and how access is removed when the business need changes. Without those answers, the organisation is left with app sprawl that behaves like both SaaS sprawl and delegated machine access at once.

Practical implication: define approval, revocation, and review workflows for AI apps exactly as you would for privileged third-party access.


Threat narrative

Attacker objective: The attacker aims to gain access to conversational context and use trusted AI-mediated integrations to exfiltrate data or trigger actions beyond normal user intent.

  1. Entry occurs when a user installs or invokes a ChatGPT App through natural language, often without recognising it as a new integration path.
  2. Escalation happens when the app receives conversation context and acts through a user credential, service account, or over-permissive MCP identity that exceeds intended scope.
  3. Impact follows when the integration is used for data leakage, cross-app manipulation, or unintended execution across multiple external endpoints.

NHI Mgmt Group analysis

AI apps are becoming a new identity surface, not just a usability feature. When users can activate external services by conversation, the control question moves from interface design to access governance. That means app approval, identity scope, and revocation must be treated as first-class security controls, especially where the app can act under broader privileges than the user. Practitioners should treat conversational integrations as governed identities, not convenience features.

ChatGPT Apps create a compounding access problem because adoption, variety, and remote endpoints grow together. The risk is not merely more integrations, but more identities and more data paths created faster than security teams can review them. This is where NHI governance intersects with AI governance: each app may represent a delegated runtime identity that needs lifecycle control, not a one-time approval. Practitioners should assume sprawl unless they can prove otherwise.

Shadow AI now includes unmanaged delegated access, which is a control gap that conventional app security does not close. Traditional scanners can inspect code or malware, but they do not answer whether a conversational app is acting with excessive privilege or sharing context outside the security boundary. That makes governance models such as NIST CSF, NIST SP 800-53, and OWASP NHI relevant where AI apps touch identities, tokens, and service accounts. Practitioners should align AI app review to existing identity governance rather than inventing a separate exception process.

Named concept: conversational integration sprawl. This is the rapid spread of AI-triggered third-party connections across an organisation, where discovery, privilege scope, and data sharing all expand at once. The term matters because it captures why linear connector governance breaks when users can deploy apps through prompts and models can route context automatically. Practitioners should measure app sprawl as both an access-control and data-exposure problem.

The decisive governance issue is not whether AI apps exist, but whether their access can be constrained to the minimum identity necessary. If an app runs under author credentials, broad service permissions, or hidden remote MCP trust, the organisation has effectively outsourced access decisions to the model. That is a PAM and NHI problem as much as an AI problem. Practitioners should require least privilege, traceability, and offboarding for every conversational integration.

What this signals

Conversational app adoption will force identity teams to treat AI integrations as lifecycle-managed access objects. The practical shift is from one-time connector approval to continuous review of what an app can see, do, and delegate. The NHI lifecycle problem now includes prompt-triggered tools, so the control model needs to move closer to the Ultimate Guide to NHIs and away from ad hoc exception handling.

Conversational integration sprawl will become a measurable governance issue once organisations start tracking how many AI-enabled endpoints are connected, who approved them, and which identities they use. That is where NIST SP 800-53 Rev 5 Security and Privacy Controls becomes relevant for access control and auditability, while OWASP NHI guidance helps frame delegated machine access.

The programme signal is clear: if the organisation cannot answer which AI apps are deployed, what data they receive, and how to revoke them, then the AI governance layer is already behind the access layer. Teams should prepare for a larger review burden, more privilege mapping, and stronger source-code or build-time discovery of app-like MCP servers before a marketplace makes the problem scale faster.


For practitioners

  • Inventory every conversational integration path Catalogue ChatGPT Apps, remote MCP endpoints, and any app connections that can be triggered from prompts. Include who can deploy them, what data they can see, and which identity they execute under. Use the same inventory discipline you would apply to privileged third-party access.
  • Bind each app to a managed identity Require every AI app or MCP server to run under a clearly defined service account or equivalent machine identity rather than hidden author credentials. Enforce least privilege, scoped tokens, and revocation records so access can be removed without waiting for the app owner.
  • Review data-sharing boundaries before rollout Assess what conversation context can leave the environment, which fields are sensitive, and whether the external endpoint is allowed to receive them. Block or segment apps that cannot prove data minimisation, especially where the model can infer more than the end user intended.
  • Add approval and offboarding controls for AI apps Create a lifecycle process for AI app onboarding, periodic review, and removal that mirrors third-party access governance. When the business need ends or the risk changes, revoke the integration and its credentials immediately rather than leaving dormant connections in place.

Key takeaways

  • ChatGPT Apps turn conversational interfaces into an access-governance problem, because users can now activate third-party tools without the friction that once limited sprawl.
  • The core risk is not only more integrations, but unmanaged identity scope, remote endpoints, and data-sharing decisions that move through the model rather than explicit admin control.
  • Security teams should govern AI apps like delegated access paths, with lifecycle review, least privilege, revocation, and visibility built in before marketplace adoption expands the problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The article centres on exposed machine credentials and delegated AI access paths.
OWASP Agentic AI Top 10The topic involves AI apps that can invoke tools and share context autonomously.
NIST CSF 2.0PR.AC-4The risk is uncontrolled access expansion through AI-mediated integrations.
NIST SP 800-53 Rev 5AC-6Least privilege is directly implicated by over-broad app permissions and hidden identities.
NIST AI RMFGOVERNAI governance and accountability are central to approving and revoking these integrations.

Map conversational integrations to NHI-03 and block any app that cannot prove least-privilege identity scope.


Key terms

  • ChatGPT App: A ChatGPT App is a third-party integration that can be invoked through conversation and used to pull data, trigger actions, or present results inside the chat experience. Security teams should treat it as an access path, because it can move information and decisions across systems without a traditional admin workflow.
  • Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
  • Conversational integration sprawl: Conversational integration sprawl is the uncontrolled growth of AI-connected tools that are added through prompts, user action, or marketplace discovery rather than central administration. It becomes a governance problem when teams cannot track which identities, permissions, and data paths each integration introduces.
  • Delegated Machine Access: Access exercised by a non-human actor on behalf of a human or another system. The important issue is not only who requested the access, but how far the delegated actor can chain actions once runtime execution begins.

What's in the full article

Noma Security's full article covers the operational detail this post intentionally leaves for the source:

  • Discovery and build-time scanning methods for MCP servers in source code repositories.
  • Examples of destructive-capability checks and over-permission analysis for AI apps.
  • Operational guidance on when to allow, segment, or block third-party conversational integrations.
  • The vendor's platform workflow for identifying apps before production rollout.

👉 The full Noma Security post covers discovery, build-time checks, and control points for conversational app rollout.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, agentic AI identity, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to emerging AI integration patterns.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org