By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: CyberhavenPublished February 11, 2026

TL;DR: 39.7% of AI interactions involve sensitive data, while personal-account use dominates major GenAI tools and creates visibility gaps across SSO, logging, retention, and model-training controls, according to Cyberhaven’s 2026 AI Adoption & Risk Report. The real governance problem is not AI adoption itself, but unmanaged AI use outside enterprise identity and data controls.


At a glance

What this is: Cyberhaven’s report shows that sensitive enterprise data is moving into AI tools routinely, with much of that activity happening through personal accounts and outside security visibility.

Why it matters: This matters because IAM, data security, and NHI governance teams need to treat AI usage, endpoint agents, and account provenance as part of the control surface, not a separate productivity problem.

By the numbers:

👉 Read Cyberhaven's analysis of how sensitive enterprise data is flowing into AI tools


Context

AI adoption has become a data governance problem as much as a productivity one. The primary issue is not simply that employees are using GenAI, but that they are doing so through accounts and workflows security teams cannot reliably see or control. That creates a direct challenge for AI data loss prevention, identity governance, and endpoint oversight.

The article’s core finding is that sensitive data is already flowing into AI tools at scale, while enterprise controls lag behind day-to-day use. Where this intersects with identity is through account provenance, SSO enforcement, and the growing role of AI agents as software entities that can move data across memory, file systems, and external services.


Key questions

Q: How should security teams govern personal AI assistants that act on behalf of employees?

A: Treat each assistant as a distinct non-human actor with its own identity, policy scope, and audit trail. Human delegation alone is not enough when the assistant can move across email, documents, calendars, and internal systems. Governance should bind the sponsor, the executor, and the target resource so access reviews and investigations can separate request from action.

Q: Why do personal AI accounts create so much risk in enterprise environments?

A: Personal accounts bypass enterprise identity controls, so security teams lose visibility into who authorised access, what scopes were granted, and whether the session can be revoked. They also separate the data trail from the user’s corporate identity, which makes investigation, containment, and audit evidence much harder.

Q: What do security teams get wrong about blocking AI tools outright?

A: They assume network blocking creates control, but users often shift to personal devices, browser workarounds, or OS-level agents that bypass those restrictions. Blocking can reduce visible risk while increasing shadow AI and making the governance problem harder to measure.

Q: How should teams respond when AI agents can access local files and memory?

A: They should govern the agent as a software identity with scoped permissions, ownership, and logging. If the agent can persist context, read files, or sync data, it should be treated as a governed asset with explicit boundaries around storage, access, and outbound movement.


Technical breakdown

Why personal AI accounts create governance blind spots

When employees use GenAI through personal accounts, the organisation loses the linkage between identity, activity, and retention policy. SSO is bypassed, logging becomes incomplete, and enterprise settings for data usage or model training no longer apply consistently. That makes the same prompt or file upload materially different depending on whether it occurs under a managed corporate identity or an unmanaged consumer account. The governance gap is not only authentication. It is the inability to assert custody over data after it leaves enterprise-controlled identity boundaries.

Practical implication: security teams need account provenance checks and conditional controls that distinguish enterprise AI use from unmanaged personal access.

How AI agents widen the data exposure surface

AI agents are not just chat interfaces. They can maintain persistent context, store searchable memory, and interact directly with file systems, clipboards, and local workflows. That changes the exposure model from single-session prompt leakage to longer-lived data retention across endpoint and application layers. In effect, the agent becomes a new software actor that can collect, reuse, and synchronise sensitive information outside normal browser-based monitoring. For IAM and NHI teams, that makes the identity of the agent and its permissions part of the same governance conversation as the user behind it.

Practical implication: treat agent permissions, storage locations, and sync paths as governable assets, not just user productivity features.

Sensitive data in AI tools is a data security and access control problem

The report shows that AI-bound content includes source code, project material, sales data, and regulated information. That broadens the risk from an isolated browser issue to a cross-functional control problem involving classification, endpoint telemetry, and access boundaries. If sensitive material is being pasted or uploaded every few days, then traditional awareness training alone will not change the exposure pattern. Organisations need policy enforcement that can recognise high-risk data types at the point of use and respond before the data enters tools that may store or reuse it.

Practical implication: align DSPM, DLP, and identity controls so sensitive content is detected before it reaches external AI services.


Threat narrative

Attacker objective: The objective is to obtain or persist access to sensitive enterprise information by exploiting unmanaged AI use and the retention behaviour of external AI services.

  1. Entry occurs when employees interact with AI tools through personal accounts or endpoint-based agents outside normal enterprise identity paths.
  2. Credential or context abuse follows when sensitive prompts, uploads, or copied material are retained in personal or third-party systems beyond corporate control.
  3. Impact occurs when confidential code, business data, or regulated information is exposed to retention, reuse, or downstream compromise outside the organisation's visibility.

NHI Mgmt Group analysis

AI data governance now depends on identity provenance, not just content inspection. The report makes clear that many AI interactions happen through personal accounts, which means security teams lose the ability to tie usage to enterprise policy, retention, and audit obligations. That is a control failure, not a visibility inconvenience. The field should now treat AI account provenance as part of governance for both human and software identities.

Persistent AI agents create a new class of data-bearing identity risk. Once an AI system can retain memory, access files, and synchronise content beyond browser controls, it behaves like a governed software actor rather than a simple application feature. That places the problem squarely in the overlap between NHI governance, endpoint control, and AI security policy. The right frame is not whether agents are useful. It is whether their permissions, memory, and data flows are bounded.

AI usage restrictions that ignore user behaviour often increase shadow AI. The report shows that blocking tools does not eliminate demand, it moves activity into unmanaged channels where enterprise controls weaken further. This is the same governance pattern seen in other identity-adjacent risks: when legitimate work is obstructed, users adopt alternatives that evade logging and policy. The practical conclusion is that security teams need monitored, sanctioned paths rather than blanket prohibition.

Data classification must extend into AI execution paths. Sensitive material is no longer confined to repositories and file shares. It now moves through prompts, clipboard actions, uploads, and agent synchronisation. That means classification and enforcement have to operate at the point of interaction, not only at rest or in transit. Practitioners should expect AI use cases to become a durable data governance tier, not a temporary exception.

Endpoint-level AI oversight will become a standard requirement. The article’s endpoint and agent examples show why browser-only controls are insufficient. Security programmes that can only observe network destinations will miss local agent memory, file-system access, and synchronisation behaviour. The discipline should now be asking which endpoint controls can prove where AI data was handled and by which identity, not just which model received the prompt.

What this signals

AI usage is now a governance signal for both data security and identity security. When employees move prompts, uploads, and code into unmanaged tools, security teams lose the chain of custody that modern control models depend on. The practical shift is toward monitoring AI interactions as part of the enterprise access surface, not as a side channel. Related identity controls are described in the NIST SP 800-63 Digital Identity Guidelines and in Ultimate Guide to NHIs , Why NHI Security Matters Now.

Data-flow visibility gap: the central risk is no longer whether AI is used, but whether sensitive material can be traced from user action to model interaction to storage outcome. That requires alignment between endpoint telemetry, DLP, classification, and identity policies. Programmes that cannot see the path will not be able to govern the outcome.

For identity and data teams, the next step is to separate sanctioned AI usage from shadow AI and then attach policy to each path. That means defining which data types may enter external tools, which accounts may use them, and which endpoint agents are allowed to persist or synchronise content. Without that boundary, governance becomes reactive.


For practitioners

  • Map AI usage to identity provenance Classify which AI interactions occur under enterprise SSO, which occur through personal accounts, and which are initiated by endpoint agents. Build policy exceptions only where identity provenance is visible and auditable, because unmanaged account paths are where enterprise retention and training controls fail.
  • Extend DLP to prompts, uploads, and clipboard flows Treat prompt text, copied content, file uploads, and endpoint synchronisation as governed data movement. Apply controls before sensitive material reaches external AI services, especially for source code, regulated records, and deal or research material.
  • Create sanctioned AI access paths with logging Offer approved AI tools with enterprise authentication, logging, and retention settings so employees are not pushed into shadow AI. The objective is not to ban usage, but to keep it inside observable control boundaries.
  • Inventory endpoint-based AI agents separately from browser use Track AI agents that can persist memory, access local files, or sync data outside standard browser monitoring. Assign ownership for those agents, review their permissions, and restrict the data stores they can read or write.

Key takeaways

  • Sensitive enterprise data is already flowing into AI tools often enough to make governance, not adoption, the defining risk.
  • Personal accounts and endpoint agents create visibility gaps that undermine SSO, logging, retention, and data-use controls.
  • The practical response is to govern AI usage as an identity and data problem, with sanctioned access paths and endpoint-aware enforcement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10NHI-01AI agents and unmanaged tool use raise agentic governance and data-handling risks.
NIST CSF 2.0PR.AC-4Personal AI accounts bypass identity controls central to access governance.
NIST SP 800-53 Rev 5AC-6Least privilege is relevant where AI tools and agents access sensitive business data.
NIST AI RMFGOVERNAI usage governance depends on clear accountability for data handling and model exposure.
ISO/IEC 27001:2022A.5.15Access control is directly implicated by personal account use and unmanaged AI access.

Require explicit access rules for AI tools and verify that corporate data never relies on personal logins.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Activity provenance: Activity provenance is the ability to trace an action back to the identity, approval, and scope that authorised it. For AI platforms, provenance matters because logs alone do not prove accountability unless they connect usage to a named owner and an approved business context.
  • Persistent Agent: A persistent agent is a non-human identity that can continue checking, adjusting, or revisiting its work over time. Unlike one-shot automation, persistence expands the control problem because the agent can keep acting after the original task has changed or failed.
  • Data custody: Data custody is the organisation's practical ability to know where sensitive information is, who can access it, and how long it persists. It is a governance concept that becomes critical when data moves into third-party AI tools that may store or reuse inputs.

What's in the full report

Cyberhaven's full analysis covers the operational detail this post intentionally leaves for the source:

  • Per-tool breakdowns of how employees are using ChatGPT, Gemini, Claude, and Perplexity across account types
  • Category-level analysis of which business data types are most frequently entering AI workflows
  • Endpoint and agent behaviour patterns that explain why browser-only controls miss part of the risk
  • The report's framing of how visibility gaps should influence enterprise AI governance decisions

👉 The full Cyberhaven post covers account patterns, data categories, and the endpoint risk picture in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management in a way that helps teams build durable control models. It is designed for practitioners responsible for identity, access, and security governance across modern enterprise environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org