By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: AnomaliPublished September 9, 2026

TL;DR: Shadow AI is no longer a fringe productivity habit. Anomali cites research showing that 98% of organisations have unverified applications in use and that unsanctioned AI tool usage has tripled in 12 months, turning employee AI adoption into a material data exposure problem. The governance gap is now larger than the policy gap, and conventional DLP is not built for it.


At a glance

What this is: This is Anomali’s analysis of how unapproved AI tool adoption has become a broad data governance and exposure problem across the enterprise.

Why it matters: It matters because security, IAM, and data governance teams now have to control AI usage, data handling, and account oversight across sanctioned and unsanctioned tools.

By the numbers:

👉 Read Anomali’s analysis of shadow AI and systemic data governance risk


Context

Shadow AI is the unsanctioned use of AI tools, models, or assistants outside approved enterprise governance. In this article, the primary issue is not AI adoption itself but the loss of visibility, control, and data handling discipline that follows when employees move sensitive work into unmanaged tools.

That creates a direct governance problem for IAM, data security, and identity teams because the same users, files, prompts, and credentials that are controlled in approved systems can be exposed through consumer AI services and browser-based workflows. For identity practitioners, the lesson is that AI use now behaves like an unmanaged access path, not just a productivity choice. This pattern is becoming typical, not exceptional.

Anomali also ties the problem to security operations and third-party governance because these tools often sit outside established review, logging, and vendor oversight processes. The result is a control gap that spans human identity, data handling, and shadow application management.


Key questions

Q: How should organisations govern AI usage when employees use unapproved tools?

A: Organisations should start with visibility, not enforcement. If teams cannot see which apps, agents, or workflows are being used, they cannot assess data exposure or apply meaningful controls. Once usage is mapped, policy can shift from blanket bans to context-based decisions that reflect sensitivity, role, and business purpose.

Q: Why does shadow AI create risk even when there is no obvious external traffic?

A: Because many AI tools now run locally, inside IDE extensions, containers, or MCP-connected workflows that do not depend on a visible outbound session. Those tools can still access data, invoke APIs, or expose credentials from the endpoint. If governance depends only on network destinations, local models and embedded agents remain effectively invisible.

Q: What breaks when employees hide their AI tool usage?

A: Detection and governance both weaken. If usage is concealed, security teams cannot rely on disclosure, self-attestation, or after-the-fact review to find data exposure. That means policy language alone has little operational value unless the organisation can observe AI use through identity, browser, or network telemetry.

Q: Should organisations prioritise AI inventory before blocking access to tools?

A: Yes. Inventory comes first because teams need to know which tools, accounts, and data flows are actually in use before they can decide what to block, approve, or monitor. A blind block often drives usage underground, while discovery creates the evidence needed for targeted policy and proportionate controls.


Technical breakdown

Why shadow AI breaks traditional data loss prevention

Traditional DLP was built around predictable channels such as email, endpoint copy and paste, and sanctioned cloud applications. Shadow AI shifts data movement into browser prompts, embedded assistants, and third-party LLM integrations, which often bypass the controls, classifications, and policies used in conventional monitoring. The problem is not only exfiltration. It is also context loss, because security tools frequently cannot tell whether a prompt is benign, work-related, or a disclosure of sensitive data. That makes point-in-time blocking too blunt and too late for many enterprise workflows.

Practical implication: Extend DLP to browser, prompt, and unstructured-data workflows before policy enforcement becomes reactive only.

Why unsanctioned AI use behaves like an access governance problem

When employees use AI tools without approval, they are effectively creating new data processing paths and new identity trust relationships outside the normal asset inventory. That means the risk is not limited to content leakage. It also includes unmanaged credentials, third-party account sprawl, and unknown processing locations. From an identity governance perspective, this is similar to introducing a new application without onboarding, owner assignment, access review, or offboarding discipline. Once that happens, auditability collapses because the enterprise no longer knows which identities can reach which AI systems.

Practical implication: Treat every AI tool as a governed application with ownership, inventory, and access review requirements.

Why concealment makes shadow AI harder to detect and contain

The article highlights a behavioral layer that often gets missed. Employees frequently hide their AI usage, which means the security team cannot rely on disclosure, casual review, or after-the-fact questioning. That pushes the problem into detection and control design. If the environment cannot observe AI use at the browser, account, or data level, policy becomes aspirational. The broader lesson is that governance fails when it depends on user honesty rather than technical visibility and enforcement.

Practical implication: Instrument AI usage at the browser and identity layers so concealed use still produces observable signals.


Threat narrative

Attacker objective: The objective is to harvest sensitive corporate data or credentials from unmanaged AI usage and turn ordinary employee workflows into exploitable exposure paths.

  1. Entry occurs when employees paste corporate data into unapproved AI tools or connect unmanaged accounts to external LLM services.
  2. Escalation follows as those tools retain prompts, files, or credentials outside enterprise control, creating a wider exposure surface than the original user action.
  3. Impact is loss of sensitive data, credential exposure, and governance blind spots that increase breach cost and complicate third-party risk management.

NHI Mgmt Group analysis

Shadow AI is best understood as an access governance failure, not just a data loss problem. When employees use unapproved AI tools, the enterprise loses control over where identities, prompts, and files are processed. That makes the issue broader than classic DLP because the hidden path is created by human identity choices and unmanaged application trust. For IAM and governance teams, the practical conclusion is that AI usage must be managed like any other access surface.

AI tool sprawl creates a new category of governance debt. The article's 10 applications per month average and 98% unverified app figure point to a control environment where inventories are stale before review begins. That is a structural problem for IAM, IGA, and SaaS governance because ownership, approval, and offboarding cannot work on assets the enterprise cannot enumerate. The named concept here is shadow AI governance debt, meaning the growing backlog of untracked AI tools and data pathways that outpaces control design. Practitioners should treat enumeration as a governance function, not a one-time discovery exercise.

Concealed AI use makes policy enforcement weaker than many organisations assume. If employees hide their use, then training alone cannot close the gap and self-attestation becomes unreliable. That means detection, browser telemetry, and conditional controls matter more than broad prohibition language. This also intersects with human identity governance because the same employee accounts that are trusted in sanctioned systems become uncontrolled data conduits in shadow systems. The conclusion for practitioners is to align identity policy with observable behaviour, not declared intent.

Regulated organisations will increasingly be judged on third-party AI handling, not just internal policy. The article correctly points to contractual and accountability expectations around external AI services, especially where confidential or regulated data is involved. That shifts the governance question from whether AI is allowed to how it is disclosed, approved, logged, and contracted. For teams operating under NIST CSF and NIST AI RMF, the practical implication is to connect AI inventory, supplier oversight, and data handling rules into one operating model.

What this signals

Shadow AI governance will converge with identity governance. As AI tools become routine work surfaces, teams will need the same discipline they already apply to accounts, privileges, and offboarding. That means linking AI inventory to identity ownership, acceptable-use monitoring, and response workflows instead of treating AI as a separate policy universe. The relevant operating model is already familiar to identity teams, even if the object has changed. See also Top 10 NHI Issues for how unmanaged access paths accumulate risk.

Shadow AI governance debt will become measurable only when enterprises stop counting tools and start counting data paths. The operational question is not how many AI apps exist, but how many identities, files, and prompts are leaving controlled environments through them. That measurement shift is what will separate mature programmes from policy-only programmes, and it is where the connection to NHI and lifecycle governance becomes practical rather than theoretical.

The next phase is not prohibition, but controlled enablement. Security teams that can inventory approved tools, define data handling boundaries, and route usage through monitored identity paths will have a defensible model. Teams that cannot do that will keep discovering shadow AI only after a leak, a complaint, or a third-party review. For identity practitioners, the challenge is to make AI use visible enough to govern without making it so restrictive that business users bypass it.


For practitioners

  • Build a live AI application inventory Catalogue sanctioned and unsanctioned AI tools, the identities using them, and the data they process so governance starts from observed reality, not policy assumptions.
  • Extend DLP to browser-based AI interactions Cover prompts, uploads, and embedded assistants with monitoring that can classify unstructured data in real time rather than relying only on email and endpoint controls.
  • Bind AI use to identity and ownership controls Require owner assignment, access review, and offboarding for every approved AI service, including external LLM integrations and connected accounts.
  • Add AI-specific clauses to third-party governance Update vendor risk reviews and contracts to address acceptable use, data retention, breach notification, and handling of sensitive inputs in AI services.

Key takeaways

  • Shadow AI is now a governance and identity problem because unapproved tools create unmanaged data and access paths outside enterprise oversight.
  • The article’s numbers show the problem is widespread, with 98% of organisations already running unverified applications and many employees using public AI tools for real work.
  • Effective control depends on inventory, browser-level visibility, and identity-linked ownership rather than policy statements or blanket bans.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article centers on AI inventory, ownership, and governance accountability.
Recommendation — Establish a governed AI inventory and assign ownership for every approved and observed AI service.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsShadow AI creates unmanaged access paths that bypass normal authorisation control.
Recommendation — Apply access authorisation controls to AI tools and connected accounts before data flows are allowed.
CIS Controls v8CIS-5 — Account ManagementThe article highlights unmanaged accounts and hidden usage across AI services.
Recommendation — Inventory, review, and remove AI-related accounts that are not tied to an approved business owner.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSensitive data exposure rises when employees can move into AI tools with excessive access.
Recommendation — Limit AI tool access and data connectors to the minimum privileges needed for each role.
ISO/IEC 27001:2022A.5.23 — Information security for use of cloud servicesUnapproved AI tools behave like unmanaged cloud services handling enterprise data.
Recommendation — Govern AI services under cloud-service approval, review, and monitoring processes before use is allowed.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI Inventory: An AI inventory is a governed record of all AI-related assets, enriched with owner, purpose, access, and risk context. It turns discovery into something security, compliance, and IAM teams can use to make approval, review, and revocation decisions.
  • Unmanaged data path: An unmanaged data path is any route by which sensitive information leaves controlled systems without being covered by standard security monitoring or policy. In shadow AI contexts, that often includes browser prompts, personal accounts, uploads, and third-party integrations.
  • Governance Debt: The accumulation of unresolved identity control weaknesses created when teams prioritise speed over lifecycle design. In NHI environments, it shows up as accounts with unclear ownership, undocumented purpose, stale credentials, and no reliable retirement path, all of which make later security work harder.

What's in the full article

Anomali’s full article covers the operational detail this post intentionally leaves for the source:

  • Survey citations and the underlying evidence trail behind the shadow AI adoption figures
  • The specific exposure behaviors observed in prompts, uploads, and personal account use
  • The vendor’s discussion of DLP limitations and AI-aware control models
  • The linked references behind the regulatory and workforce claims

👉 Anomali’s full post covers the data exposure behaviors, governance gaps, and regulatory implications in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle control, and secrets management for practitioners who need to govern dynamic access paths. It helps security and identity teams build the operating discipline needed for modern identity-driven programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org