TL;DR: Shadow AI is spreading through personal accounts, unapproved browser extensions, API integrations, and autonomous agents that can access enterprise data and systems outside approved governance, according to Akto. The core issue is inventory and control gap, not just data leakage, because AI actions can hide inside normal user activity and bypass traditional discovery.
At a glance
What this is: This is an analysis of Shadow AI in enterprises and the key finding is that unauthorized AI usage is outpacing governance, visibility, and control.
Why it matters: It matters because Shadow AI creates unmanaged access paths to sensitive data, systems, and decisions, forcing IAM, PAM, and NHI programmes to govern AI usage as part of identity and access control.
By the numbers:
- More than 80% of workers use unapproved AI tools.
- Only 37% of organisations have a documented AI governance policy.
- 69% of organisations either do not monitor AI, not monitor AI usage or address it only reactively.
👉 Read Akto's analysis of Shadow AI risks, detection, and governance
Context
Shadow AI is what happens when employees adopt AI tools, assistants, or agents faster than security teams can inventory, approve, and govern them. The result is not just data leakage. It is an access and accountability gap that affects identity, secrets, auditability, and control over AI-driven actions across the enterprise.
For IAM and NHI programmes, the important shift is that AI usage now creates a governance surface comparable to SaaS sprawl and machine identity sprawl. When AI tools run through personal accounts, OAuth grants, hardcoded API keys, or agentic workflows, they can create hidden privileges that bypass normal approval, review, and revocation processes.
Key questions
Q: What breaks when employees use unapproved AI tools with company data?
A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused. Unapproved tools can copy credentials into unmanaged workflows, which weakens revocation and makes audit trails incomplete. The result is shadow access outside the main identity programme.
Q: Why do shadow AI tools create identity governance risk?
A: Shadow AI is risky because users often reach those tools through identities, browser sessions, or tokens that were never assessed for data handling or access scope. The issue is not just policy compliance. It is whether the identity path into the tool is authorised, reviewable, and reversible.
Q: How do security teams know if shadow AI is actually under control?
A: Security teams know shadow AI is under control when they can inventory every agent, model workflow, and tool connection, then map each one to an owner and access scope. If they cannot explain who owns it, what it can access, and when it was last reviewed, it is not controlled.
Q: Who is accountable when a sanctioned AI tool causes a data breach?
A: Accountability should sit with the owner of the identity and permissions behind the tool, not only the team that approved the application. If a sanctioned AI workflow can reach sensitive data, the organisation must govern its access path, logging, and containment as rigorously as any other high-risk identity.
Technical breakdown
How Shadow AI enters the enterprise
Shadow AI usually enters through approved-looking workflows that are not actually governed. Personal accounts on public AI services bypass enterprise SSO and logging. Browser extensions can read page content across systems. API integrations often start with personal keys and later become embedded in scripts or production tooling. Autonomous agents then compound the problem because they can act on behalf of a user through OAuth tokens, API keys, or stored credentials, creating machine activity that appears legitimate in audit logs.
Practical implication: security teams need discovery and policy controls that cover accounts, extensions, APIs, and agents, not just sanctioned SaaS.
Why traditional monitoring misses AI risk
Traditional monitoring struggles because much Shadow AI activity blends into normal browser traffic, application logs, or user sessions. A prompt sent to a consumer chatbot may look like ordinary HTTPS traffic. An AI feature embedded in SaaS may be enabled by default and inherit existing trust. Agentic workflows are harder still because their actions can be attributed to a human credential even when the behaviour is automated. The control problem is therefore identity plus behaviour, not simply network inspection.
Practical implication: build controls that correlate AI usage, identity context, and action provenance across logs, gateways, and SaaS telemetry.
Shadow AI creates governance debt, not just data exposure
The deeper risk is that AI becomes a hidden decision layer inside business workflows. That means organisations can lose control over what data is shared, which models are used, and what outputs influence downstream decisions. In identity terms, every unapproved AI tool or agent is a potential non-human identity with unclear ownership, uncertain privilege, and weak lifecycle management. That is why policy alone fails when inventory, approval, and monitoring are incomplete.
Practical implication: treat unauthorized AI tools as governance debt and register them in the same control model used for sensitive NHIs.
Threat narrative
Attacker objective: The attacker objective is to exploit hidden AI trust paths to access sensitive data, manipulate workflows, or abuse inherited credentials without triggering normal enterprise controls.
- Entry occurs when employees use personal AI accounts, unapproved browser extensions, or API keys outside enterprise approval and monitoring.
- Escalation happens when those tools gain access to email, documents, databases, or shared systems through OAuth grants, hardcoded secrets, or ambient browser permissions.
- Impact follows when AI-generated outputs, data exposure, or automated actions influence business decisions, leak sensitive information, or create compliance failures.
NHI Mgmt Group analysis
Shadow AI is becoming an identity governance problem, not just a data governance problem. The article correctly shows that the real control gap is not only where data goes, but who or what is allowed to act in the enterprise under AI-mediated workflows. Once an AI tool can authenticate, invoke APIs, or operate through a user’s credentials, it behaves like a non-human identity that needs ownership, scope, and lifecycle controls. Practitioners should stop treating this as a peripheral acceptable-use issue and start governing it as identity risk.
Inventory is the named control failure behind most Shadow AI programmes. The post’s strongest point is that organisations cannot govern what they cannot see. That is the governance debt: unapproved tools, hidden extensions, and agentic workflows can accumulate privileges before security teams discover them. This is where the boundary between IAM, NHI, and SaaS governance collapses in practice, and where approved tool lists, discovery, and review workflows become mandatory.
Shadow AI creates a verification trust gap. Human approval no longer tells the full story when an AI tool can execute actions continuously after the user stops paying attention. This is the same structural issue that appears in machine identity governance, where authentication is not enough without ongoing control of permission, activity, and revocation. Practitioners should assume that any AI workflow with access to data or tools needs explicit trust boundaries, not just a login.
AI governance programs will increasingly inherit NHI control patterns. The mechanisms that matter here are ownership, entitlement scope, secret handling, monitoring, and offboarding. Those are familiar identity controls, but they now need to apply to AI assistants, embedded copilots, and autonomous agents as first-class entities. The organisations that adapt fastest will treat AI usage like an identity estate that must be classified and continuously reviewed.
The market is moving toward runtime control, not static approval. Static policy documents do not stop employees from using AI tools that solve immediate problems. The practical direction is runtime enforcement, visibility into OAuth grants and API usage, and tighter correlation between approved data paths and allowed AI activity. For practitioners, the lesson is that governance has to follow the session, not the annual policy review cycle.
What this signals
Shadow AI governance will converge with NHI governance. As AI tools take on more delegated access, the operational question becomes whether the organisation can continuously enumerate, own, and retire those access paths. That means AI usage records, OAuth approvals, and secret inventories need to be treated as one control surface, not three disconnected ones. The programme signal is clear: inventory-first governance is now a prerequisite for safe AI adoption.
The next control gap is runtime accountability. A policy that bans unapproved AI tools does not stop a user from signing into a consumer service or installing a browser extension. Security teams need telemetry that can show where AI activity starts, which credentials it uses, and what systems it touches. If they cannot trace that chain, they cannot contain the blast radius when behaviour changes.
For practitioners
- Define an approved AI tool registry Classify AI tools as approved, tolerated, or prohibited, then require business justification, data handling rules, and review ownership for each entry. This registry should cover consumer chatbots, embedded copilots, browser extensions, local models, and agentic workflows.
- Inventory AI connections and hidden permissions Discover OAuth grants, browser extensions, API keys, and integration accounts that can reach sensitive systems. Map each connection to a business owner, data tier, and revocation path so you can remove access quickly when a tool is no longer approved.
- Treat autonomous AI workflows as NHIs Assign ownership, scope, monitoring, and offboarding to any AI system that can call APIs or act in business workflows. Use the same lifecycle discipline you apply to service accounts and tokens, including rotation, review, and rapid disablement.
- Add detection for anomalous AI behaviour Correlate prompt activity, tool invocation, and downstream actions so you can spot unusual output lengths, topics, refusal patterns, or unexpected data access. Behavioural changes often reveal unauthorized AI use before a user reports it.
- Update policy to cover data and model boundaries Make it explicit which data types may never be entered into external AI services, whether personal accounts are allowed, and what logging must exist for any AI-assisted workflow. Reinforce this with training and periodic review, not one-time communication.
Key takeaways
- Shadow AI is an identity and governance issue because unapproved tools can act with enterprise credentials, permissions, and data access.
- The biggest operational failure is lack of inventory, because security teams cannot govern tools, agents, or integrations they cannot see.
- Enterprises should manage AI tools like non-human identities, with ownership, scope, monitoring, and offboarding built into the control model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | NHI-03 | The article focuses on unapproved AI tools and delegated access paths that map to agentic AI misuse. |
| NIST AI RMF | GOVERN | Shadow AI exposes AI governance and accountability gaps across the enterprise. |
| NIST CSF 2.0 | PR.AC-4 | Shadow AI often depends on over-broad or unmanaged access permissions. |
| NIST Zero Trust (SP 800-207) | The article calls for continuous verification and policy enforcement around AI access. | |
| MITRE ATT&CK | TA0006 , Credential Access; TA0010 , Exfiltration | The risk includes credential misuse and data exposure through unapproved AI workflows. |
Register AI tools, agents, and integrations under a governed inventory before they can touch enterprise data.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Agentic workflow: An agentic workflow is a sequence of tasks executed by an AI agent with some level of tool access and decision authority. In security terms, the workflow matters because it can span multiple systems, identities, and permissions, which makes attribution and revocation harder than with ordinary automation.
- OAuth Grant: An OAuth grant is the delegated permission an application receives to act on a user's behalf without storing the user's password. In NHI governance, it should be treated as a standing identity relationship with scope, ownership, and revocation requirements, not as a one-time setup detail.
- AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
What's in the full article
Akto's full article covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of detection methods for browser-based Shadow AI and hidden extensions.
- Practical guidance on AI usage policies, governance workflows, and exception handling.
- Examples of how AI-approved SaaS features can create new data-processing risk.
- The article's discussion of zero trust for AI systems and runtime policy enforcement.
Deepen your knowledge
NHI Mgmt Group’s NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need a practical control model for modern identity estates.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org