By NHI Mgmt Group Editorial TeamBased on JumpCloud: “11 Stats About Shadow AI in 2026” (January 21, 2026)

TL;DR: Shadow AI is now a daily reality, with 8 in 10 office workers using some form of public AI, 60% of organisations already seeing a data exposure event, and AI-related incidents taking 26.2% longer to identify, according to JumpCloud. The governance problem is not adoption itself but the lack of visibility, policy, and sanctioned alternatives across identity-controlled access paths.


At a glance

What this is: This analysis argues that unsanctioned AI use has become a day-to-day enterprise identity issue, with visibility, policy, and approved access paths lagging workforce adoption.

Why it matters: It matters because IAM, IGA, and security teams now have to govern AI access that often sits outside procurement, making shadow usage a control and compliance problem, not just an IT preference.


Context

Shadow AI is the unsanctioned use of AI tools by employees, and it creates an identity governance problem because access happens outside approved procurement, policy, and visibility controls. Once users reach third-party AI tools through personal accounts, browser sessions, or embedded SaaS features, traditional access reviews lose their target.

JumpCloud's framing is that organisations should not try to block every AI interaction. The harder problem is separating approved from unapproved use, mapping data flows into and out of AI services, and then centralising governance through identity and policy rather than reacting after exposure has already occurred.


Key questions

Q: How should security teams govern shadow AI without blocking productivity?

A: Use visibility-based controls instead of blanket bans. Identify which tools are in use, who is using them, and what data they can access, then apply targeted policies by role and data sensitivity. That approach preserves legitimate AI adoption while reducing exposure from unsanctioned tools and unreviewed data paths.

Q: Why does shadow AI increase data exposure risk more than ordinary shadow IT in regulated environments?

A: Shadow AI is riskier because data is often entered through a prompt and ingested instantly, which can create immediate and sometimes irreversible exposure. Unlike a typical unsanctioned app, a consumer AI tool may retain inputs, lack a BAA, and bypass traditional network-based monitoring when users paste data locally or use desktop clients.

Q: What are the signs that shadow AI is becoming a governance problem rather than a productivity aid?

A: The clearest signs are widespread use outside IT visibility, repeated sharing of corporate data with GenAI tools, and no consistent approval path for new applications. If employees are using AI because no sanctioned option exists, or if security teams cannot see which tools are active, the issue has moved from isolated behaviour to unmanaged risk.

Q: What do organisations get wrong about employee use of public AI tools?

A: The most common mistake is assuming the risk begins and ends with the app itself. In reality, the exposure occurs when employees paste data into prompts, so the real control point is the combination of user behaviour, approved tool access, and data classification.


Technical breakdown

Why shadow AI breaks sanctioned access control

Shadow AI becomes an identity problem when employees use AI services outside the organisation's approved access paths. The issue is not the model itself, but the absence of governed onboarding, policy enforcement, and visibility into which identities are touching which tools. When access sits outside the identity provider, IT cannot reliably see entitlement scope, revoke access cleanly, or distinguish employee experimentation from approved usage. That turns AI adoption into an unmanaged access layer rather than a governed service.

Practical implication: bring AI tools under identity-controlled access before they spread across personal accounts and unmanaged browser sessions.

How data flows through third-party AI models create governance gaps

The governance gap widens when sensitive information moves from internal systems into public generative AI tools or embedded SaaS features. At that point, the control problem is not only who can use the tool, but what data can be entered, retained, or reused outside the organisation. Data flow policies, acceptable use rules, and clear approval paths become part of identity governance because they define what authorised users may do with sanctioned identities and sessions.

Practical implication: map AI data flows and restrict which identities can send sensitive material to external models.

Why sanctioned AI alternatives matter for identity governance

Many shadow AI behaviours appear because employees are trying to solve real productivity problems faster than governance teams can respond. That means the control model has to include a sanctioned alternative, not just enforcement. A curated set of approved AI services, tied to identity provider access and backed by acceptable use policies, gives security teams a governable path for adoption. Without that path, user demand simply migrates to hidden tools and evades review.

Practical implication: pair policy enforcement with approved AI services so users have a governed route that competes with shadow usage.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Shadow AI is an identity governance problem before it is a tool-selection problem. The article shows that employees are already using public AI at scale, which means the control boundary has moved from procurement to access governance. If security teams cannot see which identities are reaching which AI services, they cannot manage risk through normal IAM and IGA processes. The practical conclusion is that AI adoption must be governed as an access lifecycle, not as a one-time software approval.

The real failure mode is invisible data movement through sanctioned and unsanctioned AI paths. Once user data, code, or prompts leave managed systems and enter third-party models, the organisation loses direct control over retention, reuse, and exposure. That is why acceptable use policy, data handling rules, and identity-controlled access have to operate together. The practitioner takeaway is that data governance and identity governance are now inseparable in AI usage.

Shadow AI is a signal of unmet business demand, not only a security exception. The article correctly notes that users adopt AI because it is useful and easy to reach, which means pure prohibition will not scale. Identity teams should treat this as an adoption governance problem: define approved paths, standardise access, and remove the incentive to go around controls. The implication is that shadow usage is a discovery input for programme design, not just an incident trigger.

Access governance for AI now depends on distinguishing sanctioned usage from embedded AI features inside existing SaaS. JumpCloud's own statistic that 70% of employee interactions with AI will occur through embedded features shows why visibility will be harder, not easier. That shifts the programme from app-centric review to identity-centric and workflow-centric control. The practitioner conclusion is that teams need discovery across both standalone AI tools and AI capabilities already present in sanctioned platforms.

From our research library:

What this signals

Shadow AI discovery has to become part of routine identity governance. As AI features spread into SaaS and employee workflows, the boundary between sanctioned and unsanctioned use will keep blurring. Teams that rely only on annual policy reviews will miss the faster control cycle now required for access, data handling, and approved-use enforcement.

Approved AI access is becoming a governance control, not a convenience layer. The practical shift is toward routing users through curated services, defined use cases, and identity-controlled access so that the organisation can observe and limit how AI is used. That is the only way to keep adoption visible enough for review without driving it deeper underground.


For practitioners

  • Implement AI application discovery Inventory standalone AI tools and embedded AI features across sanctioned SaaS so IT can distinguish approved use from shadow use.
  • Centralise AI access through identity provider controls Require approved AI services to use identity-controlled access paths rather than unmanaged personal accounts or ad hoc sign-ins.
  • Update acceptable use policy for AI Add clear rules for public AI, prompt handling, data entry, and approved use cases so employees know what is allowed.
  • Map data flows into third-party models Document which systems can send data to external AI tools, which data classes are prohibited, and where logging or review is required.
  • Provide sanctioned AI alternatives Offer a curated toolkit of approved AI applications with documented use cases so teams are less likely to seek shadow tools.

Key takeaways

  • Shadow AI is now a mainstream identity governance issue because employees are using AI tools faster than security teams can track.
  • The control gap is visibility and policy, not employee intent, and unmanaged data movement is the main reason exposure risk rises.
  • The strongest response is to pair discovery with sanctioned AI access paths, clear rules, and data flow governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationShadow AI adoption often exploits user trust in AI outputs and hidden capabilities.
Recommendation — Define approved AI use cases and restrict trust boundaries for employee-facing AI workflows.
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIUnsanctioned AI services create third-party identity exposure through unmanaged access paths.
Recommendation — Inventory third-party AI identities and remove access paths that bypass governed onboarding.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on governing which identities may access AI services and data flows.
PR.DS-10 — Data in Transit is ProtectedThe article stresses controlling data movement into external AI models and services.
Recommendation — Apply entitlement controls to approved AI services and review who can reach them. Protect data flows to AI services and block sensitive submission where policy forbids it.
CIS Controls v8CIS-5 — Account ManagementShadow AI governance depends on knowing which accounts and identities can use AI tools.
Recommendation — Review accounts with AI access and remove pathways that are not explicitly approved.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article is fundamentally about governing identity-controlled access to AI services in cloud environments.
Recommendation — Use IAM governance to centralise approved AI access and reduce unsanctioned usage.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Sanctioned AI: Sanctioned AI is an AI system that has gone through procurement, legal, and security review and is governed by defined controls. The term matters because approved status should reflect real access scoping, ownership, and data handling rules, not just a business decision to use the tool.
  • Data Flow Governance: Data flow governance is the discipline of controlling where sensitive data can move, who can move it, and how that movement is recorded. It links access policy to runtime evidence so teams can spot policy violations across accounts, regions, and third-party access paths.
  • Acceptable Use Policy: An acceptable use policy defines which data, tools, workflows, and actions are permitted for an identity or system. For AI governance, it becomes the boundary that turns vague intent into enforceable scope, which auditors and security teams can test against actual runtime behaviour.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org