By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Shadow AI Isn't a Governance Problem Alone” (June 9, 2026)

TL;DR: Discovery tools can find installed AI software, but they miss what identities are doing, which is how a Fortune 50 media breach led to 1.1TB stolen, including 44 million chat messages, over five months undetected, according to Abnormal AI. Behaviour-based governance now matters more than inventory because sanctioned or unsanctioned identities can both become high-risk access paths.


At a glance

What this is: This analysis says shadow AI governance fails when teams focus on installed tools instead of the behaviour of the identities using them.

Why it matters: IAM and security teams need behavioural visibility because sanctioned accounts, unsanctioned tools, and AI agents can all create the same high-risk access pattern while appearing different in inventory.

By the numbers:

  • In 2025, public code repositories absorbed 1.27 million hardcoded AI-service credentials, one every 25 seconds all year.
  • A Fortune 50 media breach led to 1.1TB stolen, including 44 million chat messages, over five months undetected.

Context

Shadow AI governance is the problem of controlling AI use that is either unmanaged or only partially visible to security teams. The core failure in this article is not that organisations cannot find software, but that they cannot reliably see what identities are doing once access exists.

Discovery-based approaches are snapshots. They tell you which tools are installed, but they do not tell you whether an account is touching unfamiliar systems, moving data at abnormal times, or behaving like a takeover.

That matters because the same risk can come from a sanctioned account, an unsanctioned tool, or an AI agent acting in a way legacy controls do not expect. In practice, the governance gap is behavioural, not just inventory-based.


Key questions

Q: Why do AI governance tools need shadow AI discovery?

A: Because policy cannot control what it cannot see. Shadow AI discovery identifies unmanaged applications, embedded AI features, and unsanctioned integrations before they become invisible data paths. Without that discovery layer, governance remains partial and retrospective, which leaves the most exposed systems outside control.

Q: Why do personal AI accounts create more risk than sanctioned ones?

A: Personal AI accounts weaken governance because they sit outside organisational control for MFA, retention, monitoring, and revocation. Even if the user is known, the account is not managed like a corporate identity, so the organisation loses assurance over how sensitive data will be stored or reused. That makes the account itself part of the risk decision.

Q: How can security teams tell whether AI access is behaving like an account takeover?

A: Look for identity behaviour that diverges from the historical baseline, especially unfamiliar system access, unusual timing, and unexpected data movement. When an AI agent or service account starts using valid credentials in ways that were never normal for that identity, the detection problem is behavioural drift rather than authentication failure.

Q: Should organisations prioritise credential lifecycle controls or behavioural monitoring for AI use?

A: They need both, but the sequence depends on exposure. If hardcoded or shared credentials are already present, secret scanning and rotation come first because they remove replayable access. Behavioural monitoring then becomes the ongoing control that shows whether approved access is being used safely.


Technical breakdown

Why discovery misses shadow AI identity risk

Discovery finds installed applications, browser extensions, or sanctioned AI tools, but it does not describe runtime identity behaviour. In identity governance terms, the control answers what exists, not what is happening. That distinction matters because an AI tool can be present, approved, or even fully inventoried while the account behind it is accessing sensitive systems in ways that never appear in a static scan. Behavioural risk depends on timing, target systems, data movement, and whether access aligns with historical patterns. Once those signals matter, the problem stops being software inventory and becomes identity monitoring across human, NHI, and AI-mediated access paths.

Practical implication: move shadow AI review from app inventory to identity activity baselines and anomaly detection.

Why hardcoded AI credentials amplify the exposure window

A hardcoded credential is a secret embedded in code, scripts, or configuration where it can be copied, reused, or leaked outside intended governance. In AI environments, that means service credentials can spread through repositories and pipelines faster than teams can catalogue them. The issue is not only leakage but persistence: once a credential is pasted into a public or shared location, the attack surface expands independently of whether the originating system was ever formally approved. That is why credential visibility and lifecycle control matter as much as tool approval. A discovered app is only one part of the exposure story; a leaked credential creates ongoing reach into the environment.

Practical implication: tie AI credential inventory to secret scanning, rotation, and revocation workflows.

How AI agent behaviour resembles account takeover

An AI agent that begins touching unfamiliar systems can look, from a detection standpoint, like a compromised account. That is because the control problem is behavioural deviation, not just authentication state. If existing rules expect a human operator or a fixed application workflow, they may miss a new access path when the actor is software making runtime decisions. The article’s key point is that legacy detection logic was built for a world where the actor was human. Once AI agents become common, the governance model has to distinguish approved automation from unexpected access expansion, even when the actor still holds valid credentials.

Practical implication: build detections around unfamiliar system access and access-path drift, not only failed logins or malware indicators.


Threat narrative

Attacker objective: The attacker aimed to steal large volumes of internal business information and communications while remaining undetected long enough to maximize exfiltration.

  1. Entry occurred when an employee downloaded a free AI art tool from a public code repository and executed an installer containing an infostealer.
  2. Credentialed access then gave the attacker a foothold inside the environment, allowing long-running surveillance of activity without immediate detection.
  3. Impact followed over five months, when the attacker exfiltrated 1.1 terabytes of data including 44 million internal chat messages, 18,800 spreadsheets, and 13,000 PDFs.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Shadow AI governance fails when it is reduced to asset discovery: inventory tells you what is installed, but not whether identities are behaving in risky ways. That is a structural blind spot, not a tuning problem. Governance needs to shift from static presence checks to behavioural control of access paths, especially where AI tooling sits between the user and the data.

Identity behaviour is the control plane that discovery never sees: a sanctioned account moving customer data at an unusual hour can be more dangerous than an unsanctioned tool that never opens a sensitive system. This is the named concept we see here: behavioural shadow AI governance, meaning governance that evaluates runtime access patterns rather than software lists. Practitioners should treat behavioural drift as the primary signal of risk.

AI agents collapse the old distinction between approved automation and suspicious access: when an agent reaches unfamiliar systems, legacy detection can misread it as compromise because the identity model was built for human timing and human intent. That means access governance, anomaly detection, and acceptable-use policy now have to align around runtime behaviour. The practical conclusion is that behavioural baselines must be identity-aware across human, NHI, and AI-mediated activity.

Hardcoded AI credentials turn shadow AI into durable exposure: the 1.27 million exposed AI-service credentials cited here show that secret leakage is no longer a side issue, it is part of the governance surface. Once credentials spread into public repositories, the organisation loses control over where AI access can be replayed. The implication is that credential lifecycle and behavioural monitoring must operate together, not as separate programmes.

The market signal is simple: discovery-only governance is becoming obsolete: as AI agents proliferate, the useful unit of control is not the application list but the behaviour of the identities behind it. That pushes identity teams toward runtime authorisation, anomaly detection, and lifecycle controls that can distinguish sanctioned use from shadow use. Practitioners should expect governance models that cannot observe behaviour to underperform regardless of how complete the inventory looks.

From our research library:

What this signals

Behavioural shadow AI governance: identity teams need a control model that evaluates runtime activity, not just installed tools. Discovery still matters, but it no longer answers the question that decides risk: which identities are moving data, when, and through which systems.

The governance pattern here is familiar from NHI work. Access reviews and allowlists are weak when the real problem is that a valid identity, human or machine, can behave anomalously without changing its name, tenant, or approval status.

AI governance also has to account for the spread of exposed credentials. In 2025, public code repositories absorbed 1.27 million hardcoded AI-service credentials, one every 25 seconds all year, according to the State of Secrets Sprawl 2026. That kind of leakage turns policy gaps into standing access risk.


For practitioners

  • Shift from discovery to behavioural governance Baseline normal access timing, target systems, and data movement for accounts that use AI tools, then flag deviations from those patterns.
  • Scan and rotate exposed AI credentials Search repositories, code snippets, and configuration stores for hardcoded AI-service secrets, then revoke and rotate anything exposed.
  • Separate sanctioned use from shadow use Classify AI access by identity behaviour, not just tool approval, so an approved app with unsafe activity is not treated as low risk.
  • Detect unfamiliar system access by AI agents Alert when an AI agent or service account begins reaching systems it has not historically accessed, especially if data volume or timing also changes.

Key takeaways

  • Shadow AI becomes dangerous when identity behaviour is invisible, not when a tool simply appears in inventory.
  • The article ties the risk to concrete scale, including a Fortune 50 breach with 1.1TB stolen and 44 million internal chat messages.
  • Behavioural baselines, secret rotation, and access-path drift detection are the controls that change the outcome.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article ties shadow AI risk to exposed hardcoded AI-service credentials.
NHI-04 — Insecure AuthenticationRuntime identity abuse and takeover-like behaviour depend on weak or replayable authentication.
NHI-05 — Overprivileged NHIApproved or shadow identities become dangerous when they can reach more systems than they need.
Recommendation — Scan repositories and configuration stores for exposed AI secrets and revoke them immediately. Enforce stronger authentication and eliminate reusable AI credentials that can be replayed. Reduce AI account permissions to the minimum systems and data paths required for the task.
MITRE ATT&CKTA0006; TA0010 — Credential Access; ExfiltrationThe incident chain involves credential-based entry followed by large-scale data theft.
Recommendation — Map exposed secrets and long-dwell exfiltration activity to TA0006 and TA0010 in detection engineering.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is governing identity access beyond static approval states.
Recommendation — Review AI and service-account entitlements against PR.AA-05 and remove access that no longer matches need.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
  • Hardcoded Credential: A secret such as a password, API key, or token embedded directly in source code rather than retrieved from a secure vault at runtime. Hardcoded credentials are one of the most common and dangerous NHI vulnerabilities.
  • Access-Path Drift: Access-path drift is the gap between what a security team believes can be reached or abused and what is actually reachable after applications, APIs, roles, and identity flows change. It is a common failure mode in fast-moving environments where controls and verification lag behind release cycles.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org