TL;DR: Shadow AI is expanding faster than enterprise governance can see it, with one example finding 243 AI products in use where leaders believed there were six and the article citing Thomson Reuters data that generative AI use nearly doubled in a year, according to Island. The core issue is tenant-blindness at the point of use, and blocking alone often pushes risky activity into personal accounts and unmanaged devices.
At a glance
What this is: This analysis argues that shadow AI is primarily a visibility and governance problem, not a simple blocking problem, because usage is often far broader than enterprises realise.
Why it matters: It matters because IAM, PAM, and broader security teams cannot govern AI usage, data exposure, or agent activity until they can distinguish sanctioned from unsanctioned access at the point of use.
By the numbers:
- An enterprise found 243 AI products in active use after believing it had only six sanctioned tools.
👉 Read Island's analysis of why shadow AI is a visibility problem
Context
Shadow AI is the use of AI tools, extensions, or agents outside approved governance, and the control gap usually appears where organisations assume visibility equals control. In practice, the problem is not just whether a tool is blocked, but whether the security team can see corporate tenants, personal accounts, unmanaged devices, and agent-driven access distinctly enough to apply policy at the point of use.
For identity and security teams, the relevance is direct: once AI tools can operate through browser sessions, desktop applications, and backend connectors, access governance becomes a runtime problem as much as an approval problem. That makes this topic closely connected to NHI governance and agentic AI risk, even though the article is framed as a browser visibility issue.
The article’s starting position is typical of most enterprise environments, not exceptional: leaders believe they know the approved set, then discovery reveals a much larger shadow layer of use.
Key questions
Q: How should organisations govern shadow AI without blocking legitimate use?
A: Start with approved-use policy, tool inventory, and data classification. Then require that any AI system handling internal information has named owners, logged access, and defined credential paths. The goal is not prohibition, but visibility and control. If a tool cannot be inventoried or monitored, it should not process sensitive data.
Q: Why does shadow AI create an identity governance problem?
A: Shadow AI creates an identity governance problem because unapproved tools and agents can access enterprise data without being inventoried, owned, or recertified. That breaks attribution and makes revocation unreliable. Once AI usage sits outside the identity programme, security teams lose visibility into who or what is actually acting inside the environment.
Q: What do security teams get wrong about blocking AI tools outright?
A: They assume network blocking creates control, but users often shift to personal devices, browser workarounds, or OS-level agents that bypass those restrictions. Blocking can reduce visible risk while increasing shadow AI and making the governance problem harder to measure.
Q: How should teams respond when AI agents can reach backend systems?
A: Treat each connector as a governed delegation path with explicit ownership, scoped permissions, and logging. If an agent can move data across systems, it needs controls closer to PAM and NHI governance than to ordinary application usage oversight.
Technical breakdown
Why blocking shadow AI fails at the last mile
Blocking approaches usually assume the organisation controls the place where traffic exits, but AI use now happens across personal accounts, unmanaged endpoints, and consumer services. A URL alone cannot distinguish a sanctioned corporate tenant from an unsanctioned personal login, so the same destination can carry very different governance risk. Once users can route around a hard block, the data often leaves the environment entirely, which turns policy into displacement rather than control. This is why the control problem shifts from destination filtering to session-level context, data handling, and identity awareness.
Practical implication: move from destination blocking to context-aware policy that can distinguish tenant, device, and session state.
Browser and desktop visibility as governance controls
The browser and desktop are now the practical control plane for much of AI usage because that is where humans and agents touch tools. Traditional network choke points were designed for cleaner traffic patterns, not for mixed sanctioned and unsanctioned AI use across devices and identities. When visibility sits at the last mile, teams can identify which tools are actually in use, how data moves, and when policy should steer, redact, or restrict. That is materially different from relying on gateway logs after the fact.
Practical implication: instrument the last mile first, then use the evidence to decide where to allow, monitor, or block.
Agentic AI and MCP multiply the identity boundary
Agentic AI changes the shadow AI problem because agents do not just query tools, they can act through them. Model Context Protocol servers create a runtime bridge into back-end systems, which means a single agent connection may reach multiple data sources or applications in one session. That makes the identity boundary more complex than a normal SaaS login, because the real question becomes which actor, which tenant, and which delegated capability is in control at execution time. Governance therefore has to extend beyond human behaviour into machine-mediated delegation.
Practical implication: treat agent-to-system connections as governed identities with scoped access and traceable delegation.
Threat narrative
Attacker objective: The objective is to exploit unsanctioned AI use and delegated access paths to move sensitive data outside governed controls while remaining effectively invisible.
- Entry occurs when employees or agents access AI tools through sanctioned or personal sessions that the organisation cannot reliably distinguish.
- Escalation happens when blocked or restricted tools are replaced by personal accounts, unmanaged devices, or agent connections to backend systems.
- Impact follows when sensitive data leaves the approved environment or an agent moves information across systems without effective oversight.
NHI Mgmt Group analysis
Shadow AI is an identity governance problem disguised as a visibility problem. The operational issue is not simply that teams cannot list every tool, but that they cannot reliably distinguish sanctioned AI access from unsanctioned use across tenants, devices, and sessions. That makes AI oversight partly an identity problem, because governance fails when the organisation cannot bind use to a trusted account, context, or control boundary. The practitioner conclusion is clear: AI discovery must become part of identity governance, not a separate side programme.
Blocking alone creates governance theatre when business value is driving adoption. Once people see productivity gains, they route around hard denies through personal logins, unmanaged endpoints, and consumer services. That pattern does not reduce risk, it displaces it into places the security team can no longer observe or steer. The field should treat proportional control as the real objective, with visibility first and enforcement tuned to context. The practitioner conclusion is to preserve governed use rather than chase absolute prohibition.
Agentic AI expands shadow AI into delegated machine behaviour. The named concept here is last-mile AI governance gap: the point where policy is weakest because action happens inside the browser, desktop, or runtime connector instead of a central control plane. MCP-style connections make that gap larger because one agent can reach multiple systems in a single flow. This validates the need for governance that follows the action, not just the account. The practitioner conclusion is to treat runtime delegation as a governance boundary.
Security teams should stop measuring AI risk only by approved-tool counts. Tool inventories are useful, but they are not the same as actual usage, tenant ownership, or data exposure paths. The article’s example of six sanctioned tools turning into 243 discovered products shows how quickly the assumed picture diverges from reality. The discipline now needs measurable visibility into where AI is being used, by whom, and under what identity context. The practitioner conclusion is to measure actual use before refining policy.
The market signal is moving toward embedded governance at the point of work. Network-centric controls alone are too coarse for AI environments where the same destination can be safe in one context and risky in another. That pushes the category toward controls that understand browser sessions, desktop activity, and delegated machine action. For identity programmes, this validates a broader shift: AI governance will increasingly intersect with human identity, secrets, and non-human access control. The practitioner conclusion is to align AI controls with identity and runtime governance together.
What this signals
Last-mile AI governance gap: the next control battleground is the point where browser sessions, desktop use, and agent delegation meet. Security programmes that still rely on coarse destination controls will continue to miss sanctioned from unsanctioned use, especially as employees mix personal and corporate AI access in the same workflow.
For IAM and PAM teams, the practical shift is to treat AI usage evidence as governance input, not just telemetry. The relevant question is no longer whether a tool exists, but whether the organisation can prove who used it, under what tenant, with what permissions, and whether the data stayed inside policy boundaries.
If the article’s pattern holds, visibility will become the primary differentiator between organisations that can adopt AI safely and those that merely restrict it. The strongest programmes will connect discovery, policy, and runtime enforcement across human identity and delegated machine access, rather than treating them as separate problems.
For practitioners
- Map actual AI usage before writing new policy Discover which AI tools, tenants, extensions, and agents are truly in use across browser, desktop, and sanctioned enterprise accounts, then compare that inventory with the approved list.
- Move control to the point of use Use context-aware controls that can distinguish corporate from personal sessions, unmanaged devices, and sensitive prompts before data leaves the approved environment.
- Treat agent connectors as governed identities Scope Model Context Protocol and similar connectors as delegated access paths, with explicit ownership, least privilege, and logging for each backend system they can reach.
- Replace broad allow-or-block rules with proportional enforcement Redact sensitive data, steer users toward approved AI options, and reserve hard restrictions for cases where context shows real exposure risk.
- Review governance metrics for hidden usage Track discrepancies between sanctioned AI inventories and observed usage so leadership can see whether shadow AI is shrinking or just moving elsewhere.
Key takeaways
- Shadow AI becomes unmanageable when organisations can no longer tell sanctioned use from unsanctioned use at the point of access.
- Visibility gaps are the real control failure, because blocking often pushes AI activity into personal accounts and unmanaged devices.
- Runtime governance must extend to AI agents and delegated connectors, or machine-mediated access will outpace identity controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A01 | The article covers AI tools and agentic runtime access risk at the point of use. |
| NIST AI RMF | GOVERN | Governance and accountability are central to distinguishing approved from unsanctioned AI use. |
| NIST CSF 2.0 | PR.AA-1 | Identity management and access control are needed to separate corporate and personal AI sessions. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege matters when AI tools or agents can reach data and backend systems. |
| NIST Zero Trust (SP 800-207) | Zero trust principles fit last-mile control and untrusted device usage. |
Assign ownership for AI discovery, policy, and runtime enforcement under the GOVERN function.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Last-Mile Access Governance: The control model that governs what an authenticated subject can do inside the session, not just whether they can connect. It extends identity, posture, and policy into browser, endpoint, and application activity so data use, tool use, and movement are constrained where work actually happens.
- Delegated access path: A delegated access path is the chain of identities, tokens, connectors, and approvals that lets one system act through another. It becomes a governance concern when the path outlives the original approval or can be reused for actions beyond the intended business purpose.
- Tenant Blindness: Tenant blindness is the inability to distinguish whether a session belongs to a corporate or personal account when both reach the same AI service. That gap undermines governance because the destination looks identical even though the data owner, policy scope, and risk exposure are different.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- The browser-level visibility model used to distinguish corporate from personal AI access.
- How the control point shifts when AI use spans browser, desktop, and network layers.
- Why agentic AI and MCP-style connections widen the governance surface beyond ordinary shadow IT.
- The vendor's example of consolidating thousands of atomic rules into a smaller application-boundary model.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management in practical operational terms. It is designed for practitioners who need to connect identity controls to real-world access paths across human and machine systems.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org