TL;DR: Claude Desktop active users grew 1,233% between January and June 2026, according to Cyberhaven, while GenAI SaaS adoption only rose from 34.2% to 37.7% and data movement into and out of GenAI SaaS climbed 80% year over year. The shift shows AI governance is moving from app inventory to workflow visibility, because endpoint agentic tools can act on files and data with local system access.
At a glance
What this is: This is a Cyberhaven analysis of how AI adoption is shifting from browser-based GenAI SaaS to endpoint agentic tools, with Claude Desktop showing explosive growth.
Why it matters: It matters because identity, access, and data governance teams need to track not just which AI tools are installed, but which tools can act on local files, data, and workflows with endpoint-level access.
By the numbers:
- Employee adoption of GenAI SaaS applications rose from 34.2% in December 2025 to 37.7% in June 2026.
- Data movement events into and out of GenAI SaaS grew 80% year over year between June 2025 and June 2026.
👉 Read Cyberhaven's analysis of Claude Desktop adoption and AI workflow risk
Context
Agentic AI adoption is changing the governance problem from simple software visibility to control over tools that can act directly on endpoints. In this article, the primary issue is not whether employees are using AI, but whether security teams can see which AI systems can read local files, execute actions, and move data with system access.
That shift matters for identity and access management because endpoint AI tools behave more like privileged workflows than passive applications. For IAM, PAM, and NHI programmes, the question is whether access models and monitoring can keep pace with software that can operate on behalf of a user and touch sensitive data outside the browser.
Key questions
Q: How should security teams govern local AI agents that run on developer endpoints?
A: Treat them as NHIs with identity, access, and lifecycle ownership. Inventory each agent, define which user context it inherits, limit its reachable systems, and require approval for commands that modify code, secrets, or network state. If the agent can execute in the same context as the developer, it needs the same level of governance as other privileged machine identities.
Q: Why is adoption percentage a weak measure of AI security risk?
A: Adoption percentage shows how widely a tool is used, but not how much sensitive data it handles or what level of privilege it carries. A small number of highly active agentic tools can create more exposure than a larger number of lightly used ones. Security teams need workflow-level metrics, not seat counts alone.
Q: What do security teams get wrong about AI visibility?
A: They often assume licence data or static configuration data is enough to understand AI risk. In practice, the important question is what identities actually do at runtime, which services they reach, and what data they share. If you cannot observe that behaviour, you cannot govern it reliably.
Q: How can organisations tell whether AI governance is actually working?
A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.
Technical breakdown
Endpoint agentic AI versus browser-based GenAI SaaS
Endpoint agentic AI runs locally on a user device and can interact with operating system resources, local files, and installed applications. Browser-based GenAI SaaS typically sits behind a web interface, which constrains what it can access unless a user explicitly uploads or pastes data. That difference changes the control surface. Local execution means the AI tool inherits more of the endpoint trust boundary, including the user's active session, cached data, and file permissions. In practice, the risk is not just prompt content. It is the AI application's ability to chain action, access, and data movement inside the same device context.
Practical implication: inventory endpoint AI tools separately from browser GenAI and assess them with endpoint control models, not just SaaS approval workflows.
Why adoption rate misses agentic AI exposure
Adoption rate tells you how many employees use a tool, but not how much data it touches or what level of access it has. A small cohort of endpoint agentic tools can create disproportionate exposure if those tools operate with local file access, clipboard access, or command execution. That is why a stable adoption percentage can still hide growing risk. Security teams need to think in terms of intensity, privilege, and workflow reach, not just seat counts. When AI tools consolidate around a few high-use applications, the governance problem shifts from discovery to containment and observability.
Practical implication: measure AI risk by workflow reach, data movement, and local privilege, not by installation counts alone.
Data lineage and identity context for AI workflows
Data lineage tracks how information moves across systems, users, and applications, while identity context shows which user or workload initiated that movement. Together, they create a governance model that can distinguish normal collaboration from risky AI-assisted transfer. In agentic environments, this matters because the AI tool may be acting within a human session but beyond the human's direct awareness. The control challenge is not only preventing exfiltration. It is understanding which AI-assisted actions should be attributed to which identity and under what authority. That is a classic governance problem with a new execution layer.
Practical implication: pair data lineage with identity-aware telemetry so AI-assisted actions can be reviewed, attributed, and constrained.
NHI Mgmt Group analysis
Agentic AI adoption is becoming an identity governance problem, not just a software adoption problem. When AI tools can act inside endpoint sessions, they inherit user context, local files, and workflow permissions that traditional SaaS governance does not capture. That creates a control gap between what an organisation approved and what the application can actually do. Practitioners should treat endpoint AI as a governed identity surface, not a discretionary productivity tool.
Adoption metrics are now a weak proxy for risk because workflow intensity matters more than seat count. Cyberhaven's figures show GenAI SaaS adoption barely moved while data movement rose sharply, which is the pattern security teams should expect when a smaller number of tools absorb more activity. This is a form of workflow concentration risk: fewer tools handling more sensitive movement, making policy blind spots more consequential. Practitioners should re-baseline risk on data paths and privilege, not just usage.
Identity controls for AI must extend from account governance to action governance. The important question is no longer only who signed in, but what the AI system could access, modify, or move once it was running. That intersects directly with IAM, PAM, and NHI governance because an AI application can function like a high-trust non-human actor inside a human session. Teams should align AI oversight with least privilege, session context, and data handling rules.
Endpoint AI is forcing security programmes to collapse the old boundary between user identity and machine action. That boundary used to support clean approval models, but agentic tools can blur it by taking actions that are not easily distinguishable from human activity. The result is governance debt that accumulates when organisations track users but not the software acting alongside them. Practitioners should prepare for hybrid identity models that govern both the person and the tool chain.
OWASP NHI Top 10 is relevant here because AI tools with local authority can behave like unmanaged non-human identities. The governance challenge is not just access, but uncontrolled action scope and unclear lifecycle oversight. As agentic tools spread, identity teams need a common language for privilege, credential use, and runtime behaviour across both human and non-human actors. Practitioners should map endpoint AI governance to established NHI risk patterns rather than treating it as a separate category.
What this signals
Workflow concentration risk is the pattern to watch over the next planning cycle. As agentic tools absorb more activity into fewer applications, teams will need to shift from application approval to action-level visibility, especially where endpoint software can move data without a browser boundary.
The governance implication for IAM and PAM teams is clear: endpoint AI should be reviewed as a privileged runtime surface. That means tighter alignment between identity, device posture, and data controls, with attention to whether a tool is acting within the authority of the user or extending it in ways the programme never intended.
Security leaders should expect the next wave of AI oversight to be built around runtime evidence rather than adoption dashboards. Programmes that can attribute AI-assisted actions to identities and data paths will be able to respond faster than those still counting seats and sanctioned apps.
For practitioners
- Separate endpoint AI from browser AI in inventory Track desktop agentic tools, coding assistants, and browser GenAI applications as distinct classes because they carry different access and data exposure profiles. Endpoint tools should be reviewed against local file access, command execution, and session context. This is where the real control boundary sits.
- Measure AI risk by data movement intensity Report on uploads, downloads, copy-paste events, and file-touch frequency alongside adoption counts so the security team can see which tools are carrying the most sensitive activity. A tool used by fewer employees may still dominate exposure if it moves more data.
- Apply least privilege to agentic AI workloads Limit the files, directories, and application scopes that AI tools can touch, and review whether they need access to local resources at all. Where possible, constrain their actions to task-scoped workflows and monitor for privilege creep over time.
- Pair identity telemetry with data lineage Correlate the user or workload identity that initiated an AI action with the data objects that moved as a result. That makes it possible to distinguish approved assistance from risky propagation, and it improves investigation quality when AI tools are involved.
Key takeaways
- Endpoint agentic AI changes the control problem because it can act on local files and workflow state, not just generate content in a browser.
- Cyberhaven's data shows adoption and risk are diverging, with Claude Desktop growing 1,233% while GenAI SaaS adoption barely moved and data movement rose 80%.
- IAM, PAM, and NHI programmes need workflow-level visibility, least privilege, and identity-aware data lineage to govern AI tools that behave like non-human actors.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Endpoint AI behaving like a high-trust actor aligns with unmanaged non-human identity risk. |
| OWASP Agentic AI Top 10 | Agentic tools that can act on files and execute actions fit agentic AI governance risks. | |
| NIST AI RMF | GOVERN | The article centers on governance gaps for AI systems operating in enterprise workflows. |
| NIST CSF 2.0 | PR.AC-4 | Least privilege and access governance are central to endpoint AI risk management. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is the most direct control for tools that can act on local files and workflows. |
Review AI tool permissions against least-privilege access rules and remove unnecessary local authority.
Key terms
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Workflow concentration risk: A security condition where fewer applications carry a growing share of sensitive data movement or operational activity. The risk is not only the number of tools in use, but the amount of trust, data, and action authority concentrated in a small set of high-use systems.
- Data Lineage: The record of how data moves across systems, applications, and workflows. In security operations, lineage shows where sensitive data propagates, which identities touch it, and how a compromise could spread across connected environments.
- Endpoint authority: The practical level of access a tool has when it runs on a user device. This includes local files, active sessions, clipboard content, and other device resources that can widen the impact of an AI application beyond what a browser-based tool can reach.
What's in the full report
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- The raw measurement methodology behind the 1,233% Claude Desktop growth figure and the enterprise data set it came from.
- Month-by-month adoption comparisons across Claude Desktop, ChatGPT Desktop, and Microsoft Copilot Desktop.
- The underlying data movement metrics for GenAI SaaS, including uploads, downloads, and copy-paste events.
- The vendor's explanation of how Cyberhaven traces data lineage across human and agentic workflows.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, agentic AI identity, machine identity security, and secrets management. It is designed for practitioners who need to extend identity control into AI-enabled workflows and non-human access paths.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org