TL;DR: AI adoption is expanding the identity problem from unmanaged non-human accounts to shadow AI and agentic access, while 77% of employees sharing secrets on ChatGPT shows the human, machine, and AI governance gaps are converging, according to Oasis Security. The security issue is no longer discovery alone, but whether identity control can keep pace with runtime behaviour across all three actor types.
At a glance
What this is: This is a governance analysis of how shadow AI, agentic access and employee secret-sharing expand the identity surface beyond traditional non-human account control.
Why it matters: IAM, IGA and PAM teams need to treat AI behaviour, ownership and runtime access as part of one identity programme, not separate human and machine problems.
By the numbers:
- 77% of employees sharing secrets on ChatGPT jeopardizes enterprise security.
Context
Shadow AI is what happens when AI tools, agents or workflows are used without clear inventory, ownership or governance. In practical identity terms, that means teams lose the ability to answer who or what is acting, what it can access, and under which controls.
The article frames AI adoption as a continuation of the same identity problem that already existed for non-human identities, but with higher velocity and less visibility. That matters because governance models built around human users or static machine accounts do not automatically hold when access is delegated to tools, bots or AI-driven workflows.
The article is useful because it connects employee behaviour, unmanaged AI use and runtime access into one control problem. That convergence is no longer theoretical for IAM programmes; it is the operational reality teams need to govern.
Key questions
Q: How should security teams govern shadow AI without slowing adoption?
A: Start with continuous discovery, then classify tools by data access, system connectivity, and provider trust. Use policy thresholds that allow low-risk use cases quickly while forcing review, restriction, or blocking for tools that can reach sensitive systems. The control objective is to make safe adoption fast and unsafe adoption expensive.
Q: Why do AI prompts create identity and data-security risk?
A: AI prompts create risk because they can carry sensitive content outside the original system’s protection boundary. Copy-paste and file uploads can move secrets, regulated data, or operational context into tools that may log, reuse, or connect that information elsewhere. The issue is not the prompt itself, but the identity and data path it opens.
Q: When should organisations prioritise runtime AI controls over static approvals?
A: Organisations should prioritise runtime AI controls whenever a system can generate outputs, call tools, or move data without a human approving each step. Static approvals can document intent, but they cannot stop oversharing or unsafe execution once the workflow is live. The stronger the delegation chain, the more runtime controls matter.
Q: What is the difference between human identity governance and NHI governance for AI tools?
A: Human identity governance assumes a person, a manager, and a clear employment lifecycle. NHI governance has to manage credentials, tokens, bots, and agents that can appear instantly, change scope quickly, and outlive the original use case if no one explicitly retires them.
Technical breakdown
Shadow AI discovery and identity inventory
Shadow AI refers to AI tools or agents that appear in the environment before the security team has a complete view of them. The core technical problem is inventory: if the organisation cannot map which tools exist, which identities they use, and which data sources they touch, governance starts late and usually misses the first access path. Discovery is not just asset enumeration. It is identity discovery across browser tools, SaaS integrations, API-connected assistants and agentic workflows that may inherit privileges from a person, service account or delegated token.
Practical implication: build a discovery process that inventories AI access paths as identities, not as standalone apps.
Trusted AI governance and runtime access control
Trusted AI governance moves beyond static approval and focuses on what the AI can do at runtime. That includes purpose-bound access, least privilege, just-in-time elevation and guardrails that limit tool use to the intended task. The technical shift matters because AI access can be session-based, delegated or chained through multiple tools, which makes pre-provisioned access reviews less reliable as the sole control. In identity terms, the question becomes whether the runtime authorisation boundary is enforced where the action happens, not only where the account was created.
Practical implication: enforce runtime policy at the point of action, especially for AI workflows that can reach sensitive systems.
Why employee secret sharing becomes an identity issue
When employees paste secrets into ChatGPT or similar tools, the issue is not only data leakage. It is also identity leakage, because credentials, tokens or operational details can be exposed outside governed channels and then reused in ways the organisation cannot trace. That creates a governance overlap between human behaviour, NHI handling and AI-assisted workflows. The article’s statistic shows this is already a practical risk domain, not a future-state concern. The control challenge is to govern both the user action and the downstream credential exposure it creates.
Practical implication: treat secret-sharing behaviour as a credential governance problem, not just a user-awareness issue.
Threat narrative
Attacker objective: The objective is to exploit unmanaged AI use and exposed credentials to reach enterprise data and access paths that were never meant to sit outside governance.
- Entry occurs when shadow AI or employee use of AI tools introduces unmanaged access into the environment through browser use, integrations or pasted credentials.
- Credential exposure follows when secrets, tokens or operational data are shared into AI prompts or connected workflows without governance.
- Escalation happens when those exposed credentials or delegated accesses are reused across systems that were never designed for AI-mediated use.
- Impact is enterprise data exposure, loss of control over access scope and weakened compliance posture across human and non-human identity estates.
Breaches seen in the wild
- Vercel Context.ai OAuth Supply Chain Breach: Shadow AI app Context.ai OAuth integration exposes Vercel customer data via unmanaged third-party token.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Shadow AI is an identity governance problem before it is an AI governance problem. The article’s central value is that it shifts the discussion from model risk to access control, ownership and lifecycle management. When AI tools appear outside inventory, IAM loses the ability to certify, review or revoke with confidence. Practitioners should treat undiscovered AI access as unmanaged identity exposure, not merely as a technology sprawl issue.
Trusted AI governance depends on runtime control, not static approval. A workflow that is safe at provisioning can become unsafe once the agent selects tools, exchanges context or carries delegated privilege into a new action path. That is why purpose-bound access and just-in-time elevation matter more here than traditional access assignment alone. The discipline has to move from who approved the account to what the system can do in the moment of execution.
Secret-sharing behaviour shows that human and non-human identity controls are converging. The article’s employee statistic is important because it links user behaviour to credential leakage, which then becomes an NHI problem. This is the same governance chain seen in many modern compromises: human action creates machine credential exposure, and machine exposure creates enterprise risk. IAM teams need a unified control model that spans people, secrets and AI-mediated workflows.
Runtime guardrails are the missing control boundary for AI adoption. Inventory and policy are necessary, but they do not stop an agent or user from overreaching once access exists. The article points toward a control model built around least privilege at creation, continuous ownership during use and automated revocation at decommission. Practitioners should frame AI governance as an access lifecycle problem with the same rigor applied to critical NHIs.
Identity blast radius is now a board-level governance concept. The more AI touches shared accounts, tokens and high-trust workflows, the more one weak control can spread across human, machine and agentic paths. That changes how teams should think about segmentation, escalation and accountability across the identity estate. The practical conclusion is that AI adoption must be governed as a blast-radius problem, not just an innovation programme.
From our research library:
- Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Read next: Shadow AI and AI Agent Discovery Guide
What this signals
Shadow AI discovery has become a prerequisite for identity governance. If an organisation cannot find the tools, it cannot govern the access paths those tools create. That makes discovery the first control boundary for AI programmes, and it belongs inside the same operating model used for NHIs and privileged access.
Purpose-bound access is the right design pattern for AI-mediated workflows. The practical shift is away from broad, persistent permissions and toward access that is scoped to a specific task, session and data source. For IAM and PAM teams, that changes the control objective from standing access reduction to runtime containment.
Human behaviour is now a direct input to machine identity risk. In the source article, 77% of employees sharing secrets on ChatGPT is a reminder that one careless prompt can become a credential governance event. Security teams should treat user education, secret detection and NHI revocation as a single workflow, not separate problems.
For practitioners
- Map shadow AI as an identity estate Inventory AI tools, assistants and automations alongside the human and machine identities they use so ownership, access and revocation are traceable.
- Enforce purpose-bound runtime access Restrict AI workflows to the minimum tools and data sources required for the task, and apply just-in-time elevation only where the action truly needs it.
- Treat secret sharing as credential leakage Block or monitor the movement of secrets, tokens and API keys into AI prompts and connected workflows, then revoke exposed credentials immediately.
- Unify human and non-human governance Align joiner-mover-leaver, access review and offboarding processes so AI-related access is governed with the same lifecycle discipline as other identities.
Key takeaways
- Shadow AI turns AI adoption into an identity governance issue because tools, tokens and delegated access can appear outside the normal control plane.
- The operational risk is not limited to discovery. Runtime behaviour, secret sharing and inherited permissions create the actual exposure path.
- IAM and PAM teams need one governance model for humans, NHIs and AI-mediated workflows so ownership, scoping and revocation stay aligned.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on AI access paths inheriting or exceeding intended privilege. |
| Recommendation — Constrain agent identities so they cannot inherit broader privilege than the task requires. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article explicitly links employee secret sharing and AI workflows to leaked credentials. |
| NHI-05 — Overprivileged NHI | The governance problem is excessive access across AI tools, tokens and delegated identities. | |
| Recommendation — Detect and revoke secrets exposed to AI prompts, copilots and connected workflows. Reduce standing access on AI-connected identities to the minimum scope needed for each workflow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about controlling access scope and entitlement boundaries across AI use. |
| Recommendation — Review AI-related entitlements under PR.AA-05 and remove unused or excessive permissions. | ||
| MITRE ATT&CK | TA0006;TA0010 — Credential Access; Exfiltration | The article describes credential exposure and resulting data-access risk through AI workflows. |
| Recommendation — Map exposed-secret scenarios to TA0006 and TA0010 to sharpen monitoring and containment priorities. | ||
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Trusted AI: AI that is governed to be safe, secure, transparent, explainable, privacy-aware, and resilient in the environments where it is used. The term is not just about model quality, but about the organisational controls that make AI decisions defensible and manageable over time.
- Purpose-bound access: Purpose-bound access is permission limited to a defined task, dataset, or workflow, with revocation when that purpose ends. For AI systems, the control matters because broad reusable access creates unnecessary blast radius and blurs accountability across people, tokens, and connected systems.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org