By NHI Mgmt Group Editorial TeamBased on JumpCloud: “From Shadow to Sight: How to Use AI SaaS Management to Discover Rogue AI in 24 Hours” (December 10, 2025)

TL;DR: Shadow AI is creating data leakage and compliance exposure because employees use free-tier AI tools with personal accounts and enter sensitive data, while many organisations also lack visibility into non-human and agentic usage, according to JumpCloud. The real governance failure is not detection alone but the inability to inventory, classify, and control unapproved AI access before data leaves the enterprise boundary.


At a glance

What this is: This is an analysis of shadow AI as an identity governance problem, with the key finding that organisations need visibility into unapproved AI tools, agents, and users before they can govern data exposure and access.

Why it matters: IAM, NHI, and AI governance teams need a shared inventory of shadow AI because untracked usage turns identity, data, and compliance controls into after-the-fact cleanup.

By the numbers:

  • 68% of employees use free-tier AI tools like ChatGPT with personal accounts.
  • 57% admit to inputting sensitive data such as customer personally identifiable information and internal documents into ungoverned models.
  • There are over 6,500 GenAI domains and 3,000 apps observed across enterprises.
  • Some unsanctioned AI applications have been found running for over 400 days.

Context

Shadow AI is the use of unapproved AI tools, models, or assistants outside formal governance, and it creates an identity problem before it becomes a data problem. Once employees can reach public AI services with personal accounts, security teams lose sight of which identities are interacting with which tools and what data is being exposed.

The governance gap is not just detection. Organisations need to inventory unapproved AI tools, the users touching them, and any non-human or agentic identities that may be accessing company data without direct human oversight. Without that baseline, policy becomes reactive and enforcement becomes inconsistent.


Key questions

Q: How should security teams govern shadow AI without blocking productivity?

A: Use visibility-based controls instead of blanket bans. Identify which tools are in use, who is using them, and what data they can access, then apply targeted policies by role and data sensitivity. That approach preserves legitimate AI adoption while reducing exposure from unsanctioned tools and unreviewed data paths.

Q: What breaks when organisations cannot see shadow AI usage?

A: When shadow AI is invisible, security teams lose control over where data is sent, which assistants are connected, and whether those systems can retain or expose sensitive information. That undermines policy enforcement, auditability, and incident response. It also means the organisation may be granting machine-driven access without a defined identity lifecycle.


Technical breakdown

Why shadow AI becomes an identity governance issue

Shadow AI is not only about unsanctioned software. It becomes an identity governance issue when the organisation cannot answer who accessed the tool, whether that access was linked to a managed identity, and whether the resulting data flow was approved. In practice, the same governance failure appears across human users, NHI, and agentic workflows: the access path exists outside the normal inventory, review, and approval cycle. That means policy cannot be enforced consistently because the subject of governance is missing from the record.

Practical implication: build governance around the identity and the access path, not just the application name.

Why visibility matters more than blanket blocking

The article’s core mechanism is that visibility enables classification, and classification enables control. If an organisation only blocks broadly, it still cannot distinguish between high-risk free-tier use, low-risk approved use, and potentially useful tools that should be brought under enterprise controls. A workable governance model needs discovery first, then risk scoring, then policy action. That sequence is what turns shadow AI from an unknown into an inventory that can be managed through identity, device, and web access data.

Practical implication: sequence discovery before enforcement so policy decisions are based on actual usage, not assumptions.

What changes when agents are part of the shadow AI problem

The article broadens the problem beyond people using chatbots. It also includes scripts and agentic identities that may access company data autonomously, which means the identity subject is no longer always a human user. That shift matters because a managed account, token, or service path can now sit behind the AI interaction, and standard user-centric governance may miss it entirely. Shadow AI discovery therefore needs to cover both visible human usage and the non-human execution layer that can move data into external AI systems.

Practical implication: extend discovery and approvals to non-human execution paths that can send data to AI services.


Threat narrative

Attacker objective: The practical outcome is data exposure and governance failure through unapproved AI usage, not a traditional intrusion into a single system.

  1. Entry occurs when employees use free-tier or unapproved AI tools with personal accounts, creating access outside enterprise governance.
  2. Credentialed use expands when ungoverned models receive sensitive data such as customer PII and internal documents, even though the interaction is not formally approved.
  3. Impact follows as corporate data leaves the enterprise boundary and becomes difficult to trace, classify, or defend under compliance obligations.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Shadow AI visibility is now an identity governance control, not a policy slogan. The article is right to move the discussion away from fear-based blocking and toward discovery, because governance cannot operate on systems, apps, or agents it cannot enumerate. That is true for human users and even more true when non-human or agentic identities are involved. The practical conclusion is that AI governance starts with inventory quality, not policy volume.

Shadow AI creates a new form of identity blind spot because the subject of governance may be a personal account, a managed user, or a non-human executor. Once AI usage spans both human and machine-driven access paths, the old assumption that identity inventories map neatly to approved business applications stops holding. That is a governance design problem, not merely a detection gap. Practitioners should treat AI discovery as a cross-domain identity exercise spanning IAM, NHI, and usage monitoring.

Complete visibility is the control that determines whether AI can be classified, approved, or contained. The article’s most useful contribution is the sequencing lesson: discover first, then decide whether a tool should be blocked, warned, or formally onboarded with SSO and other enterprise controls. Without that sequence, organisations either over-block and drive work underground or under-govern and accept unmanaged exposure.

Shadow AI is also a lifecycle problem because unapproved use tends to persist once it enters daily workflow. The longer an unsanctioned tool remains in circulation, the harder it becomes to correct user behaviour, reclassify the service, or apply access governance after the fact. For identity programmes, that means discovery cadence and offboarding logic matter as much as policy wording.

From our research library:

What this signals

Shadow AI discovery needs to sit alongside IAM and NHI governance, not beside them. If organisations treat AI visibility as a separate tool problem, they miss the fact that the same unmanaged access patterns can involve users, service accounts, and autonomous workflows. The governance answer is a single inventory that can classify human and non-human access paths together.

72% of governance effort is wasted when the subject of control is still unknown. The stronger lesson from this article is that policy cannot be effective until the organisation has a complete record of the tools, identities, and data paths in play. Discovery is the prerequisite for meaningful approval, denial, or containment.


For practitioners

  • Build a unified AI inventory Correlate identity, device, and web access data to identify unapproved AI tools, the users accessing them, and any associated non-human execution paths.
  • Classify AI usage by risk and business need Separate high-risk free-tier use from low-risk tools that may be candidates for formal approval, so governance decisions are based on actual exposure rather than blanket suspicion.
  • Apply targeted enforcement Use warnings, soft blocks, or access restrictions for the highest-risk users and domains before sensitive data continues to flow into ungoverned services.
  • Bring approved AI under enterprise controls Where employees rely on useful tools, formalise approval and attach enterprise identity controls such as SSO so usage moves into a governable boundary.

Key takeaways

  • Shadow AI is an identity governance issue because organisations cannot govern AI use they cannot inventory, classify, or attribute to a user or non-human identity.
  • The article links unapproved AI use to real exposure, including free-tier tool adoption, sensitive data entry, and long-lived unsanctioned applications.
  • The decisive control is complete visibility into tools, users, and agentic paths so teams can move from reactive blocking to governed approval and enforcement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIShadow AI overlaps with unmanaged human use of AI access paths and unapproved accounts.
Recommendation — Audit AI access paths for unmanaged human use and move them into approved identity controls.
NIST CSF 2.0ID.AM-01 — Physical devices and systems are inventoriedThe article’s core message is that AI tools must be inventoried before they can be governed.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsUnapproved AI usage is fundamentally an authorization and entitlement problem.
Recommendation — Inventory AI tools, users, and access paths so governance can operate on known assets. Apply entitlement controls to approved AI tools and remove access to unapproved ones.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article focuses on governance, accountability, and policy around AI use.
Recommendation — Establish ownership, policy, and review processes for AI use before it spreads unchecked.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article explicitly extends shadow AI visibility to agentic identities that can access data.
Recommendation — Constrain agent identities so they cannot access data outside approved privileges.

Key terms

  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Identity Inventory: Identity inventory is the process of discovering and recording every identity that can access systems or data. For NHIs, it includes owner, purpose, privilege scope, lifecycle status, and where the credential is used. Without inventory, governance, audit evidence, and incident response all become partial and unreliable.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org