By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: DrataPublished July 22, 2026

TL;DR: Only 13% of IT and security professionals say they have full visibility into AI tools used in their organisation, leaving 87% without confidence in the inventory that GRC, privacy, and security controls depend on, according to Drata’s 2026 State of GRC survey. The practical issue is no longer AI adoption alone, but whether governance can discover and account for what employees are already using.


At a glance

What this is: Drata’s survey shows that most IT and security teams lack full visibility into AI tools, creating a shadow AI inventory gap that weakens governance.

Why it matters: That matters because inventory is the control layer that makes policy, risk review, data handling, and accountability workable across GRC, security, and identity programmes.

By the numbers:

👉 Read Drata's analysis of the 2026 GRC survey on AI visibility


Context

Shadow AI is a governance problem before it is a tooling problem. When employees adopt AI assistants, notetakers, and other AI-enabled services faster than procurement and review processes can register them, inventory stops being a recordkeeping exercise and becomes a control failure. In this article, Drata argues that AI governance starts with seeing what exists, because a programme cannot assess, approve, or restrict what it cannot find.

The visibility gap also creates an identity-adjacent governance issue: every unmanaged AI tool introduces new data paths, decision influence, and accountability questions that security, GRC, and IAM teams still have to answer. For programmes already struggling with service accounts, SaaS sprawl, and workflow automation, shadow AI adds another unmanaged surface that needs continuous discovery rather than periodic review.


Key questions

Q: What breaks when organisations cannot inventory their AI credentials?

A: Rotation, recertification, and offboarding all break down when the inventory is incomplete. Teams cannot prove which keys are active, cannot identify which owners should review them, and cannot confidently retire credentials that may already be obsolete. The result is governance theatre: policies exist, but the evidence needed to enforce them does not.

Q: Why does shadow AI create a governance gap for IAM and security teams?

A: Shadow AI creates a governance gap because organizations cannot manage systems they do not reliably see. If AI apps, agents, and plugin connections live outside the approved inventory, then policy, risk assessment, and monitoring all start from incomplete assumptions. IAM and security teams need discovery that captures real usage, not only sanctioned assets.

Q: How do you know if AI discovery is actually working?

A: AI discovery is working when the organisation can produce one authoritative inventory, classify tools consistently, and explain which data and permissions each tool can reach. If the team still has to switch between dashboards or cannot map runtime usage back to policy, discovery is incomplete even if coverage looks broad.

Q: Who is accountable when AI output causes a compliance or legal issue?

A: Accountability sits with the organisation that deploys and governs the AI use case, not only with the vendor that hosts the model. If an employee or agent uses AI in a business context, the enterprise must be able to show policy, monitoring, and evidence of control. That is now a governance obligation, not optional hygiene.


Technical breakdown

Why AI inventory is now a governance control, not a checklist

Inventory is the first control because every downstream decision depends on scope. If a team cannot enumerate the AI tools in use, it cannot assess data access, regulatory exposure, or business ownership. In practice, point-in-time spreadsheets fail because AI usage changes continuously through browser tools, embedded assistants, and workflow add-ons. Continuous discovery is the architectural answer: monitor for new tools, map ownership, and keep the inventory current enough to support approval and review cycles.

Practical implication: replace periodic AI audits with continuous discovery tied to governance workflows.

How shadow AI expands the attack and compliance surface

Shadow AI is risky because the tool itself may be benign while the usage context is not. Employees can paste sensitive data into external services, route regulated information outside approved boundaries, or rely on outputs in decisions that were never validated for reliability. That makes the real failure mode visibility loss, not just user behaviour. Governance teams need to treat unsanctioned AI as an exposure path across privacy, security, and compliance controls, especially where data classification and approval rules are missing or unenforced.

Practical implication: align AI discovery with data-classification and approved-use controls.

What a live AI inventory must answer for GRC and IAM

A useful inventory is not just a list of names. It must answer what the AI does, what data it touches, what outcome it owns, and who is responsible for it. Those four questions turn discovery into accountability because they connect usage to ownership, risk, and remediation. For identity teams, the same logic applies to AI systems that act inside business workflows: if a system can make decisions or move data, it needs an owner, boundaries, and reviewable access paths.

Practical implication: require ownership and data-access metadata for every AI tool before it enters production use.


Threat narrative

Attacker objective: The objective is to exploit unmanaged AI usage paths to expose data, influence decisions, or create compliance and governance failures before controls can intervene.

  1. Entry occurs when employees adopt AI tools, assistants, and workflow add-ons outside formal review and procurement controls.
  2. Escalation follows when those tools receive company data, expand into business workflows, and operate without an approved inventory or ownership record.
  3. Impact appears as data leakage, privacy violations, compliance exposure, and unreliable AI-supported decisions that the organisation cannot fully trace or govern.

NHI Mgmt Group analysis

Shadow AI is now a governance discovery problem, not a policy-writing problem. Organisations can write acceptable-use rules quickly, but those rules do not constrain tools that have never been identified. The survey result showing only 13% full visibility demonstrates that discovery is the real control plane. For GRC and identity teams, the practical conclusion is that governance begins with asset discovery, ownership, and continuous monitoring, not with policy exceptions.

AI inventory is becoming a prerequisite for defensible accountability. When a tool can touch data, influence decisions, or embed itself in a workflow, someone must own its use and its risk. That makes AI inventory the bridge between GRC oversight and operational identity governance. Without that bridge, approval workflows, data controls, and review processes all depend on assumptions that the programme cannot verify.

Governance blind spots compound faster than security teams can manually close them. Shadow AI expands the same class of risk seen in SaaS sprawl and unmanaged automation, but with higher data sensitivity and less visibility into outcomes. The named concept here is the AI visibility gap: the distance between what employees are already using and what the programme can actually govern. Teams should treat that gap as a standing control deficiency, not a temporary audit issue.

Identity programmes will need to extend ownership logic to AI-enabled workflows. Once AI systems participate in approvals, summarisation, or decision support, they become part of the control environment even when they are not formal users in the IAM sense. That creates a new governance task for identity and access teams: define who owns the AI pathway, what data it can reach, and what review signals prove it remains inside scope. Practitioners should fold AI tools into the same accountability model used for other high-risk digital assets.

Continuous discovery is the only sustainable response to AI adoption velocity. Point-in-time controls will always lag employee experimentation, browser-based usage, and embedded AI features in mainstream platforms. The survey shows why that lag matters: the majority of teams cannot confidently say they know what is running. Practitioners should therefore anchor their programmes on always-on discovery, exception handling, and ownership assignment rather than waiting for a quarterly reconciliation cycle.

What this signals

AI visibility gap: the same blind spot that undermines SaaS and NHI governance is now appearing in AI adoption, and programmes that cannot inventory usage will struggle to prove control effectiveness. This is where identity governance, data classification, and continuous discovery start to converge in practice, especially for tools that touch regulated information or workflow approvals.

For practitioners, the next step is to treat AI tools like any other high-risk digital asset: identify them, assign ownership, and monitor their use against approved data boundaries. Teams that already manage service accounts, API keys, and SaaS access can reuse those governance patterns rather than creating a separate exception process for AI.

The broader signal is that governance maturity will increasingly be measured by discovery speed, not policy volume. As AI features diffuse into everyday software, the programmes that win operationally will be the ones that can answer what is running, who owns it, and what data it can reach before the audit or incident forces the question.


For practitioners

  • Implement continuous AI discovery Monitor endpoints, browsers, SaaS logs, and collaboration tools for AI usage so the inventory updates as new tools appear. Treat discovery as a live control that feeds governance review, not a one-time audit exercise.
  • Bind every AI tool to an owner Require a named business owner and technical owner for each AI capability before it is approved for use. Ownership records should include the data it touches, the business outcome it supports, and the review cadence that keeps it in scope.
  • Tie AI review to data-classification rules Flag tools that receive regulated, confidential, or customer data and route them through the same approval logic used for sensitive SaaS and workflow systems. If the data class is unknown, the tool should remain outside approved use until reviewed.
  • Extend IAM oversight to AI-enabled workflows Map AI assistants and automation features into access review processes where they affect approvals, summarisation, or data movement. The goal is to identify where AI changes the control path, not just where it appears as a software feature.

Key takeaways

  • Shadow AI is a governance visibility problem first, because programmes cannot control tools they cannot inventory.
  • The survey’s 13% visibility figure shows that most teams are still operating with a blind spot in the core control layer that GRC depends on.
  • Continuous discovery, ownership assignment, and data-boundary checks are the controls that turn AI adoption from an unmanaged risk into a governable asset.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-1Asset inventory is the central issue in this article.
NIST AI RMFGOVERNAI accountability and governance are the core theme of the post.
ISO/IEC 27001:2022A.5.9Inventory of information and other associated assets aligns to this article's discovery problem.
GDPRArt.32The article discusses personal and sensitive data exposure through AI tools.

Use discovery and access controls to reduce the risk of personal data leaving approved processing boundaries.


Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI Inventory: An AI inventory is a governed record of all AI-related assets, enriched with owner, purpose, access, and risk context. It turns discovery into something security, compliance, and IAM teams can use to make approval, review, and revocation decisions.
  • Continuous discovery: Continuous discovery is the ongoing process of detecting identities as they appear, change, or disappear across environments. For AI agents and other NHIs, it prevents inventory drift and keeps ownership, privilege, and lifecycle controls aligned with the live environment.
  • Governance Blind Spot: A governance blind spot is a control gap created when programmes cannot see or account for a system, tool, or workflow that still affects business risk. In AI programmes, it means policies exist on paper, but usage continues outside the scope of review and enforcement.

What's in the full report

Drata's full post covers the operational detail this analysis intentionally leaves for the source:

  • The survey methodology and respondent breakdown behind the 13% visibility finding
  • Drata's recommended continuous-monitoring approach for surfacing new AI tools as they appear
  • The four inventory questions the vendor says every AI programme should answer before approval
  • The workload and capacity comparison between teams with complete and incomplete AI inventories

👉 Drata's full post covers the survey findings, the visibility gap, and the inventory questions teams should use.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives practitioners a structured way to connect identity control thinking to the broader security and governance programmes they run.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org