By NHI Mgmt Group Editorial TeamBased on Lasso Security: “The CISO’s Guide to GenAI Risks: Unpacking the Real Security Pain Points” (May 14, 2026)

TL;DR: GenAI adoption is creating blind spots across shadow tools, employee data leakage, insecure plugins, and compliance gaps, according to Lasso Security’s guide to CISO pain points. The real issue is that traditional IAM and monitoring models were built for deterministic systems, not prompt-driven workflows with weak visibility and expanding third-party access.


At a glance

What this is: This is an analysis of why GenAI is exposing gaps in enterprise identity governance, especially where shadow AI, employee data handling, plugins and APIs outpace existing controls.

Why it matters: It matters because IAM, IGA and security teams need governance that covers prompt-level usage, third-party integrations and data exposure, not just traditional application access.


Context

GenAI changes the identity and governance problem because usage is often distributed, fast-moving and only loosely tied to central approval processes. In practice, employees, developers and business units can introduce new tools and workflows faster than security teams can inventory them, which leaves identity governance blind to where data and access are actually flowing.

For enterprise IAM and security programmes, the issue is not simply that GenAI is new. It is that prompt-driven interactions, retrieval layers, plugins and APIs create control points that legacy monitoring and access review models were never designed to inspect.


Key questions

Q: What breaks when GenAI tools are adopted without central oversight?

A: Shadow AI creates untracked access paths, unmanaged data movement and incomplete ownership. When teams adopt GenAI outside approved channels, access reviews, logging and approval workflows no longer cover the systems that actually touch enterprise data, so governance fails before a security incident even begins.

Q: Why do GenAI plugins and APIs create identity risk?

A: They introduce extra trust boundaries that can be over-permissioned, weakly authenticated, or left without clear revocation ownership. If a model can act through a service account or API token, then identity scope matters as much as model behaviour. The risk is not only data exposure, but backend abuse through a credential path that was never tightly governed.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: What is the difference between sanctioned AI and shadow AI?

A: Sanctioned AI has gone through procurement, legal, and security review, with defined ownership and policy controls. Shadow AI bypasses those gates, often using existing browser sessions or SaaS permissions to process sensitive data outside approved oversight. The difference is not the model. It is the control path.


Technical breakdown

Shadow AI creates ungoverned identity paths

Shadow AI is the GenAI equivalent of Shadow IT, but with a more difficult governance footprint because the risk is not just unsanctioned software. It is unsanctioned access patterns, data use and third-party connections. When business units adopt chatbots, copilots or embedded model features without security review, identity and access decisions happen outside the normal lifecycle, leaving no dependable inventory, owner or review point. That makes control enforcement inconsistent across teams and environments.

Practical implication: security teams need a complete inventory of GenAI tools and the identities, data sources and integrations each one touches.

Plugins and APIs extend GenAI privilege beyond the model

LLMs rarely operate alone in the enterprise. Plugins, APIs and retrieval systems connect the model to data stores, internal applications and external services, which expands the trust boundary far beyond the chat interface. Weak authentication, over-permissioned endpoints or poorly vetted extensions can let a model trigger actions or expose data that should have stayed isolated. In governance terms, the model becomes an access broker, not just a text generator.

Practical implication: treat every GenAI integration as an identity-bearing dependency and review its permissions, auth strength and data reach.

Prompt-level activity breaks legacy visibility assumptions

Traditional SIEM, DLP and endpoint tooling were built to see transactions, files and host activity, not the intent and content of natural-language prompts. That matters because GenAI risk often appears in the prompt itself, in the retrieved context, or in the generated output. Without telemetry at that layer, teams can neither prove what data was exposed nor reconstruct how a risky interaction occurred. The visibility gap is therefore a governance gap, not just a detection gap.

Practical implication: instrument GenAI usage so security teams can trace prompts, retrieved data, outputs and access paths.


Threat narrative

Attacker objective: The objective is to obtain sensitive data, manipulate model behaviour or use GenAI integrations to reach backend systems and business information beyond approved scope.

  1. Entry occurs when employees, developers or business units adopt GenAI tools without central oversight, creating shadow AI and untracked access paths.
  2. Credential or data abuse follows when users paste sensitive information into public-facing models or connect models to permissive APIs and plugins.
  3. Escalation happens when prompt injection, weak authentication or over-permissioned integrations let the system access data or systems beyond intended scope.
  4. Impact appears as data leakage, compliance failure, model integrity loss or broader exposure of proprietary material across the enterprise.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

GenAI governance failures are identity governance failures first. The article describes a pattern where people, tools and business units adopt GenAI faster than central controls can classify, approve or monitor it. That means the real gap is not only model security but the absence of lifecycle governance for who can use what, through which path, with which data. Enterprises should treat GenAI rollout as an identity programme problem, not a tooling side issue.

Shadow AI is the named concept that explains why traditional oversight misses the risk. Shadow AI is not just undiscovered software. It is undiscovered access, undiscovered data flow and undiscovered accountability. Once a chatbot, plugin or embedded model reaches production outside approved channels, access review, logging and ownership all become incomplete by design. Practitioners need to recognise that unmanaged adoption erodes governance before a single malicious act occurs.

Prompt-driven systems collapse the assumption that monitoring can observe a stable transaction boundary. Traditional enterprise controls assume the risky event is visible as a discrete request, file transfer or login. In GenAI, the sensitive action may be the prompt, the retrieved context or the generated output, and those events can span multiple systems. The implication is that governance has to move closer to the interaction layer and away from post-hoc review.

Plugins and APIs turn GenAI into a delegated access problem. The moment a model can reach internal systems or third-party services, the question becomes who authorised that delegation, on what basis, and with what expiry. Weak authentication and over-permissioned integrations are not side risks, they are the control surface. Practitioners should re-evaluate third-party access governance wherever GenAI touches backend data or action workflows.

Compliance for GenAI depends on traceability that most organisations do not yet have. The article makes clear that many enterprises cannot show what data an LLM saw, what it generated, or who accessed it. That is a governance deficit with regulatory consequences, especially where organisations must evidence responsible use and auditable logging. The practical conclusion is simple: without traceability, policy statements about responsible AI remain unprovable.

From our research library:

  • Generative AI use specifically increased from 33% in 2023 to 79% in 2025, according to McKinsey’s Global Surveys on the State of AI.

What this signals

Shadow AI is the governance pattern most enterprises underestimate. The operational risk is not limited to unauthorised software. It is the combination of hidden identity paths, undisclosed data exposure and missing owners, which means the security team cannot certify the environment with confidence. Agentic AI Security Guide is useful where organisations need to translate that risk into a control model.

Prompt-level observability is becoming a baseline requirement for GenAI programmes. If teams cannot trace prompts, retrieved context and generated output, they cannot answer basic governance questions after a security review or incident. That should push programmes toward tighter telemetry, explicit data boundaries and documented accountability across model integrations. NIST AI 600-1 GenAI Profile provides a useful external reference point for governance-oriented control thinking.


For practitioners

  • Build a complete GenAI inventory Map every chatbot, embedded assistant, plugin and API-connected model in use, including business owner, data sources, authentication method and logging coverage.
  • Classify GenAI integrations as identity-bearing dependencies Review each model extension, connector and API as a privileged access path and assess whether its permissions are proportionate to the task it performs.
  • Instrument prompt-level telemetry Capture prompts, retrieved context, outputs and access events so investigators can reconstruct what data was exposed and through which workflow.
  • Apply secure SDLC controls to AI-assisted code Treat model-generated code and prompt injection risks as third-party dependency issues and subject them to the same review gates as external libraries.
  • Set clear data-use boundaries for employees Define which data types are prohibited in public GenAI tools and back that policy with user education and enforcement where possible.

Key takeaways

  • GenAI expands the identity governance problem because use is often distributed across employees, developers and business units before security teams can see it.
  • The highest-risk gaps are shadow AI, plugin and API exposure, and missing prompt-level visibility into what data was used or returned.
  • Governance needs to move from application-centric reviews to interaction-centric controls that cover inventory, telemetry and third-party access paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP API Security Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseGenAI plugins and delegated integrations create privilege misuse risks inside agentic workflows.
Recommendation — Review GenAI connectors for identity and privilege abuse before they can reach internal systems.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance gaps created by enterprise GenAI adoption.
Recommendation — Establish AI governance ownership, approval and accountability for every GenAI use case.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on uncontrolled access to tools, data and integrations across GenAI workflows.
Recommendation — Apply PR.AA-05 to validate GenAI permissions, entitlements and authorisations.
OWASP API Security Top 10API2 — Broken AuthenticationThe article explicitly cites weak authentication and over-permissioned APIs and endpoints.
Recommendation — Harden GenAI API authentication and restrict connector access to the minimum required scope.
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIThird-party plugins and APIs create external dependency risk similar to vulnerable third-party NHIs.
Recommendation — Inventory third-party GenAI integrations and verify their identity, permissions and ownership.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Prompt-Level Visibility: Prompt-level visibility is the ability to see what users or agents submit to an AI tool at the moment of interaction. It matters because disclosure often happens before downstream controls, so the security team needs identity, content, and context at the point of prompt submission.
  • RAG: Retrieval-augmented generation is a pattern where a model queries external content before answering. In security terms, it creates a second control plane that can widen exposure if retrieval scope, source trust, and output filtering are not tightly governed.
  • GenAI Governance: The set of policies, controls, and accountability rules that determine how generative AI is approved, used, monitored, and retired. Effective governance connects purpose, data classification, access boundaries, logging, and ownership so AI programs do not scale faster than control maturity.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org