By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ArmorCodePublished August 6, 2026

TL;DR: Unapproved AI use tripled from 15% to 45% of the workforce in a year, while 67% of employees accessing AI services on corporate devices used personal accounts outside enterprise logging and access controls, according to ArmorCode's analysis of Verizon's 2026 DBIR. The real problem is not use itself but the collapse of prevention-only models, which pushes risk into invisible channels unless governance, sanctioned alternatives, and continuous exposure management replace block lists.


At a glance

What this is: This is ArmorCode's analysis of shadow AI governance, with the key finding that prevention-only controls are failing as unapproved AI use and personal-account access spread across the enterprise.

Why it matters: It matters because IAM, PAM, and security governance teams now have to manage AI usage as a policy, visibility, and accountability problem, not just an endpoint blocking problem.

By the numbers:

👉 Read ArmorCode's analysis of shadow AI governance and enterprise controls


Context

Shadow AI is the use of unsanctioned AI tools, assistants, or browser extensions to do work that falls outside enterprise approval, logging, and data controls. In this article, ArmorCode argues that the core problem is not employee misconduct but a governance gap: people are adopting AI faster than security teams can evaluate, approve, and monitor it.

For IAM and security leaders, the key issue is that shadow AI often bypasses identity, logging, and data handling controls by shifting work onto personal accounts and unmanaged devices. That creates an identity boundary problem as much as a technology problem, because once activity moves outside enterprise identities, policy enforcement and auditability degrade quickly.

The article's starting position is typical of many enterprises now facing AI sprawl: policy exists, but the safe path is not yet competitive with the shadow path. That is exactly where governance programmes break down.


Key questions

Q: What breaks when shadow AI is not discovered early?

A: Teams lose sight of which agents exist, what they can reach, and which credentials they use. That creates blind spots in audit trails, incident response, and offboarding, especially when agents are created locally or disappear after a single task. Discovery failure becomes governance failure once the identity cannot be traced back to an owner.

Q: Why do macOS malware campaigns often become an identity and access problem?

A: Because many campaigns abuse session authority, user approval, or privileged execution to reach their objective. Once a malicious app inherits a trusted workflow, it can steal screenshots, open shells, or capture data without further authentication. That makes the real failure the grant of authority, not only the malware payload itself.

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

Q: Who is accountable when an employee uses an AI tool to trigger harmful access?

A: Accountability stays with the organisation's identity governance and control owners, because the risky behaviour arises from delegated access paths that the business permitted. The right question is whether the delegation chain, review process, and containment controls were defined for AI-assisted execution. The NHI Lifecycle Management Guide is a useful reference for that governance.


Technical breakdown

Why prevention-only controls fail against shadow AI

Prevention-only controls assume users will accept a block when a tool is useful. In practice, employees route around restrictions by switching to personal devices, unmanaged browsers, or non-corporate accounts. That moves activity beyond enterprise logging, DLP, and access governance, so the risk is not removed, only displaced. The technical failure is boundary control without a sanctioned alternative, which is why simple block lists rarely produce durable outcomes. Practical implication: treat AI use as a governed access problem, not a pure denial problem.

Practical implication: pair restrictions with sanctioned access paths that preserve logging, data rules, and identity accountability.

What an AI acceptable use policy must define

An AI acceptable use policy is operational only when it names data classes, approved tools, and the approval path for new services. Vague language like 'use AI responsibly' does not help an employee decide whether a specific prompt is allowed. Effective governance maps data sensitivity to tool category, so the policy becomes a runtime decision aid rather than a document in a repository. The same logic applies to identity controls: if the policy cannot be enforced against a known account, it is not really a control. Practical implication: make policy machine-checkable where possible and explicit where not.

Practical implication: classify data, name approved tools, and define fast approval workflows before users create their own exceptions.

Why continuous exposure management is now part of AI governance

Shadow AI changes too quickly for annual review cycles. New browser extensions, embedded AI features, and niche SaaS tools can introduce exposure between audit points, so governance needs continuous discovery and reassessment. Continuous exposure management borrows the idea of always-on visibility from modern exposure management programmes, but applies it to AI usage patterns, data flows, and tool sprawl. The important point is that the control objective is not perfect elimination. It is timely detection of new AI pathways before they become embedded business habits. Practical implication: run AI governance as an ongoing discovery and triage process, not a periodic review.

Practical implication: continuously discover new AI tools and reclassify their risk before they become normalised in workflows.


Threat narrative

Attacker objective: The attacker objective is to exploit unmanaged AI usage paths to gain access to sensitive business context, source material, or operational data outside enterprise controls.

  1. Entry occurs when an employee uses an unapproved AI service through a personal account or unmanaged device, bypassing enterprise identity and monitoring controls.
  2. Escalation happens when sensitive prompts, code, or internal documents are reused across tools that the organisation cannot log or govern.
  3. Impact follows when invisible AI usage creates data exposure, compliance gaps, or breach cost amplification that security teams discover only after the fact.

NHI Mgmt Group analysis

Shadow AI is becoming an identity-governance problem before it is a tooling problem. When employees move work into personal accounts and unmanaged devices, the enterprise loses the ability to tie AI activity back to sanctioned identities. That weakens auditability, policy enforcement, and incident reconstruction in the same move. For IAM and governance teams, the real issue is not whether AI is allowed, but whether its use remains attributable and enforceable.

Prevention-only models create a governance trust gap. The article shows why blocking tools without an alternative simply shifts behaviour off-network and out of view. That is a control failure, not a user-compliance failure. In governance terms, the safe path must be easier than the shadow path or policy will be bypassed by design.

AI exposure management is now a standing operating model, not a point-in-time review. Shadow AI changes too quickly for quarterly or annual approvals to keep pace with adoption. The named concept here is governance drift: the widening gap between approved AI use and actual AI use as business pressure outpaces policy. Practitioners should treat that drift as a measurable risk signal, not an abstract culture issue.

Bounded automation is the right response to scale, but only inside clear governance boundaries. The article's model of agents routing findings and opening tickets is useful because it limits manual triage burden without delegating authority over policy itself. That distinction matters for agentic AI security too, where automation must remain accountable to human-defined controls. Practitioners should use automation to accelerate governance, not replace it.

The enterprise AI control plane is converging with broader security governance. Shadow AI findings appear in code, cloud, SaaS, and endpoint tooling, so fragmented ownership will continue to produce inconsistent enforcement. The broader market signal is that AI governance now needs the same consistency expected of IAM, PAM, and exposure management. Practitioners should expect governance models to consolidate around shared visibility and policy orchestration.

What this signals

Shadow AI governance will increasingly intersect with identity governance because unmanaged AI usage tends to escape enterprise accounts, audit trails, and access review processes. That makes the boundary between sanctioned and unsanctioned identities a practical control surface, not just an inventory question.

Governance drift: the distance between what policy allows and what people actually do will become a core programme metric. Teams that can measure sanctioned account usage, discovery lag, and approval turnaround will have a better handle on risk than teams that only count blocked attempts.

The control model is shifting toward continuous discovery, policy orchestration, and bounded automation. For practitioners, the next step is to align AI governance with identity, data, and exposure management so that visibility does not depend on a single tool or a quarterly review cycle.


For practitioners

  • Define an AI acceptable use policy with enforceable data classes Classify data into clear tiers such as public, internal, and restricted, then specify which AI tool categories may process each tier. Ambiguous policy language leaves employees guessing and encourages bypass behaviour. Use the policy to make the permitted path obvious at the point of use.
  • Provide sanctioned AI alternatives that match real work patterns Offer enterprise-approved tools such as private LLM access, coding assistants, or vetted writing tools that are faster and easier than the shadow option. If the approved route is slower, users will keep routing around it. Secure enablement only works when productivity and governance are both present.
  • Monitor personal-account and unmanaged-device AI access Look for AI usage that shifts to personal devices, browser-based tools, and non-corporate accounts, because those are the paths that exit enterprise logging and identity controls. Correlate SaaS, endpoint, and identity telemetry to find where usage is happening outside sanctioned boundaries.
  • Run continuous discovery on new AI tools and embedded features Establish a continuous exposure process that identifies newly adopted AI services, browser extensions, and AI features added to existing SaaS platforms. Review their data handling, identity linkage, and logging posture before they become embedded in normal workflows.
  • Automate routing and triage, not policy exceptions Use bounded automation to open tickets, route findings to the correct owner, and attach context for review. Keep the approval decision with humans, especially where a tool handles sensitive data or interacts with regulated workflows.

Key takeaways

  • Shadow AI is not mainly a user misconduct problem. It is a governance and visibility failure that weakens identity attribution and control enforcement.
  • ArmorCode's cited data shows the scale of the issue is already enterprise-wide, with unapproved AI use and personal-account access now common patterns.
  • Effective response depends on sanctioned alternatives, explicit policy, and continuous exposure management, not on block lists alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Shadow AI weakens identity attribution and access oversight.
NIST SP 800-53 Rev 5AC-6The article focuses on limiting what users can access and where they can route data.
NIST AI RMFGOVERNAI governance is the central theme, including accountability and oversight.
OWASP Agentic AI Top 10Agentic automation appears in the remediation workflow, though the article is governance-focused.

Map sanctioned AI usage to access governance and verify every approved tool has an accountable identity path.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Governance Coverage Drift: Governance coverage drift is the gap between the access estate an organisation believes it controls and the access estate actually present across applications and identities. It emerges when discovery is incomplete, integrations lag, or review data does not reconcile cleanly to real entitlements.
  • Sanctioned Alternative: A sanctioned alternative is an approved tool or workflow that gives users a secure way to do the same job they would otherwise do through shadow technology. In practice, this means matching enough of the productivity value that users do not feel forced to route around security controls.
  • Continuous Threat Exposure Management: Continuous Threat Exposure Management is the ongoing process of finding which assets, identities, and paths are actually reachable from the current environment. It moves risk assessment away from static inventories and toward live exposure, so security teams can prioritise what an attacker or misuse path can reach now.

What's in the full article

ArmorCode's full blog covers the operational detail this post intentionally leaves for the source:

  • The article's policy language for classifying public, internal, and restricted data across AI tools
  • The governance model for sanctioned alternatives, including private LLMs, coding assistants, and vetted writing tools
  • The continuous exposure management approach for discovering new AI tools and browser plugins
  • The automation pattern for routing findings into remediation workflows without handing over governance decisions

👉 The full ArmorCode article covers policy design, sanctioned alternatives, and continuous exposure management detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and agentic AI identity. It helps practitioners connect identity controls to the operational realities of modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org