TL;DR: Shadow AI now spans IDEs, browsers, SaaS apps, AI agents, and MCP connections, creating visibility gaps, data leakage, and autonomous actions that traditional IT controls were not built to manage, according to Akto. The control problem is no longer whether AI is present, but whether enterprises can govern what it can see, decide, and do.
At a glance
What this is: Shadow AI is the use of unsanctioned AI tools, agents, and embedded AI features without formal visibility or governance, and the key finding is that it behaves less like shadow IT and more like autonomous risk.
Why it matters: It matters because security teams need controls that cover AI usage, data flows, and actions, not just app approval, if they want to govern NHI-like AI systems and human workflows together.
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
👉 Read Akto's article on what shadow AI is and how to govern it
Context
Shadow AI is now a governance issue because AI systems are moving into the same workflow layers where security teams already struggle to see and control access. The primary keyword here is shadow AI, and the problem is not just unsanctioned software, but unsanctioned decision-making and action inside enterprise tools.
Unlike shadow IT, which mainly hid data storage and software usage, shadow AI can interpret prompts, generate outputs, call APIs, and trigger workflows. That creates a direct intersection with IAM, NHI governance, and agentic AI security because the relevant question becomes who or what is acting, under what authority, and with what data.
The article’s starting position is typical for modern enterprises: adoption is bottom-up, embedded in daily work, and usually discovered after the fact. That is precisely why runtime visibility and policy enforcement now matter more than one-time approval checks.
Key questions
Q: What breaks when organisations ban shadow AI instead of governing it?
A: Bans often push AI use into personal accounts, unmanaged devices, and hidden workflows, which removes visibility from security and makes data exposure harder to detect. The control failure is not usage itself, but concealment. A better model is to approve fast, workable alternatives and enforce policy on identity, data handling, and logging.
Q: Why do conversational AI systems create new identity and access risks?
A: Because they can combine data retrieval, decision-making, and execution in a single interaction. That collapses the gap between information access and business action, which traditional IAM and security tools were not built to manage. The result is higher exposure when the system can modify records or disclose sensitive guest data.
Q: How do you know if shadow AI governance is actually working?
A: You know it is working when you can see where AI is used, what data it touches, what actions it can take, and whether those actions are blocked or approved in real time. If usage is still being discovered through incidents or audits, governance is lagging behind adoption.
Q: Who is accountable when rogue AI accesses regulated data or enterprise systems?
A: Accountability should sit with the teams that approve the use case, grant the permissions, and own the data or application being accessed. Security can set the control model, but legal, compliance, IT, and business owners all need defined decision rights and revocation authority.
Technical breakdown
Why shadow AI is different from shadow IT
Shadow IT usually expands the software estate without changing how systems make decisions. Shadow AI is different because the tool can transform input, infer intent, and take actions through APIs, plugins, or embedded workflows. That means risk is not limited to data residency or app sprawl. It also includes decision integrity, unauthorized automation, and unreviewed side effects. In practice, the attack surface extends into IDEs, browsers, SaaS apps, and AI agent chains where traditional discovery controls were not designed to operate.
Practical implication: security teams need controls that observe AI behavior at runtime, not just inventory approved applications.
Why AI agents create an identity problem
When an AI agent can call tools, access data, or trigger workflows, it behaves like a non-human identity in operational terms. The governance challenge is that the agent may inherit privileges from a human user, a service account, or an embedded integration, then act faster than manual review can intervene. This is why agentic AI security intersects with NHI governance. The key issue is not whether the model is intelligent, but whether its permissions, scope, and action boundaries are explicit and continuously enforced.
Practical implication: define agent identities, limit their scopes, and separate human approval from machine execution where the risk warrants it.
How runtime guardrails differ from static policy
Static policy says what should happen. Runtime guardrails decide what can happen in the live workflow. That distinction matters because shadow AI is dynamic: prompts change, tools change, context changes, and the same agent can behave differently from one session to the next. Runtime controls therefore need to evaluate data sensitivity, action type, and destination systems in real time. This is closer to Zero Trust thinking than traditional software approval, because trust must be re-evaluated at each action boundary.
Practical implication: pair policy definition with live enforcement on prompts, data access, and outbound actions.
Threat narrative
Attacker objective: The objective is to obtain sensitive enterprise data or manipulate internal processes through unsanctioned AI paths that bypass normal governance.
- Entry occurs when employees adopt AI tools inside IDEs, browsers, SaaS apps, or MCP-connected workflows without formal security review.
- Escalation happens when those tools inherit access to source code, customer records, internal documents, or internal APIs and start acting with that context.
- Impact follows when the AI system leaks sensitive data, retains prompts beyond policy, or triggers unintended workflow changes at machine speed.
NHI Mgmt Group analysis
Shadow AI governance debt is now a board-level issue: enterprises are accumulating unmanaged AI usage faster than they can define policy, visibility, and accountability. Because AI is embedded in browsers, IDEs, and SaaS workflows, security teams are losing control at the moment of adoption rather than at the moment of breach. The practical conclusion is that AI governance can no longer be treated as an innovation side project.
AI agents should be governed as non-human identities: once an AI system can call tools or trigger workflows, its permissions become an identity problem, not just an application problem. That makes NHI-style lifecycle thinking relevant, including scoped access, revocation, review, and traceability. Enterprises that fail to name the agent identity will struggle to govern the action path.
Runtime visibility is the named control gap here: the article’s own logic shows that static approval processes miss the real risk because shadow AI lives inside active sessions and changing contexts. That makes this a detection and enforcement problem rather than a one-time policy problem. The practitioner takeaway is that governance must follow execution, not just procurement.
Shadow AI is a Zero Trust problem in disguise: trust assumptions collapse when an AI system can decide and act on behalf of a user without repeated authorization. The relevant discipline is not banning tools, but continuously verifying data, action, and destination boundaries. That shift will define which organisations can scale AI without expanding blast radius.
Enterprises need a named control model for AI usage: the article effectively points to an AI usage control layer that sits between approved access and live execution. That layer has to bridge IAM, NHI governance, and AI monitoring because each on its own is incomplete. The practitioner conclusion is simple: if you cannot see, classify, and constrain AI action paths, you do not govern shadow AI.
What this signals
Shadow AI will increasingly force security programmes to converge IAM, NHI governance, and AI policy into a single runtime control plane. The enterprises that wait for a clean category boundary between human access and machine action will keep finding gaps after adoption has already spread.
Agent identity sprawl: as AI systems become embedded in ordinary work, organisations will need a way to distinguish approved assistants from unsanctioned agentic workflows. The practical signal is whether your programme can classify and constrain AI actions before they reach business systems, not after a prompt has already executed.
The governance bar is also moving toward continuous verification, which aligns more closely with Zero Trust and lifecycle management than with traditional software approval. If your current process cannot show where AI usage exists, who owns it, and how it is revoked, your control model is already behind.
For practitioners
- Discover shadow AI across workflows Inventory AI usage in IDEs, browsers, extensions, SaaS apps, and MCP-connected tools before policy work starts. Focus on where data enters and where actions leave the workflow, because those are the points where visibility breaks down fastest.
- Classify AI tools by action risk Separate read-only assistants from tools that can call APIs, modify records, or trigger business processes. Assign explicit approval paths to any workflow where an AI system can change state in another system.
- Bind permissions to agent scope Treat agent access like NHI access and define narrow scopes, explicit lifetimes, and revocation points for every AI system that touches enterprise data. Use the NHI Lifecycle Management Guide to align provisioning and offboarding with AI tool usage.
- Enforce runtime guardrails on prompts and outputs Monitor sensitive inputs, output destinations, and triggered actions in real time so policy can block risky behaviour before it completes. That is the control that matters when AI changes context faster than humans can review it.
- Create approved AI paths for common use cases Provide sanctioned tools and documented guardrails for coding, analysis, and customer workflows so employees are not pushed toward shadow usage. If the secure path is harder than the unsafe one, adoption will continue underground.
Key takeaways
- Shadow AI is a governance and identity problem because AI systems can now access data and trigger actions inside normal enterprise workflows.
- The main failure is invisibility: without runtime discovery and control, security teams cannot know what AI systems can see, decide, or change.
- Practitioners should treat AI agents like non-human identities, with scoped permissions, revocation, and live enforcement rather than static approval alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack surface, NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | Shadow AI and AI agents raise agentic access and action governance risks. | |
| NIST AI RMF | GOVERN | AI governance, accountability, and oversight are the article's central concerns. |
| NIST CSF 2.0 | PR.AC-4 | The article centers on controlling access and permissions for AI-enabled workflows. |
| NIST Zero Trust (SP 800-207) | Runtime verification and reduced trust assumptions align with Zero Trust thinking. | |
| GDPR | Art.32 | Shadow AI can expose personal data and create security obligations under GDPR. |
Treat AI tools touching personal data as security-controlled processing and document safeguards under Article 32.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Runtime Guardrail: A control applied while an AI agent is operating, not just during configuration or review. Guardrails can block dangerous tool calls, require approval for sensitive actions, or stop data leakage before it reaches systems or users.
- MCP: Model Context Protocol, an open way for AI agents to connect to tools and data sources. It improves interoperability, but it also introduces a shared integration layer that must be governed carefully because the protocol can widen access across many systems at once.
What's in the full article
Akto's full article covers the operational detail this post intentionally leaves for the source:
- Examples of shadow AI in IDEs, browsers, SaaS apps, and MCP-connected workflows
- Step-by-step guidance for discovering AI usage across employee tools and business processes
- Runtime guardrail concepts for prompts, data access, and AI-driven actions
- Policy-building detail for approved AI use, human review, and safe enablement
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management for practitioners building stronger identity control. It is designed for security teams that need to connect identity governance to broader enterprise risk management.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org