TL;DR: Unapproved AI tools are already widespread, with 61% of organisations encountering unsanctioned or unmonitored use, according to JumpCloud research, while breaches involving unmanaged applications add an average of $670,000 and 97% lack basic access controls. The real gap is governance, not experimentation, and it spans IT, security, and legal ownership.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Defining Your AI Governance Dream Team: Aligning Legal, Security, and IT in the Age of AI”.
By the numbers:
- 61% of organisations report encountering unsanctioned or unmonitored use of AI tools by employees.
- 97% of these breaches involve a complete lack of basic access controls.
Key questions
Q: What breaks when AI agents have no clear owner?
A: Lifecycle control breaks first, followed by revocation, review, and accountability.
Q: Why do unsanctioned AI tools create the same governance problems as shadow IT?
A: Unsanctioned AI use creates shadow IT risk because users often route around restrictions when a tool is blocked.
Q: How do security teams know whether an AI agent control stack is actually working?
A: Look for three things: every agent has a traceable identity, permissions are narrow enough to explain in operational terms, and actions can be audited end to end.
Practitioner guidance
- Define named ownership for every AI agent Record a business owner, technical owner, and approval authority for each deployed agent before it can access enterprise data or systems.
- Extend application inventory to shadow AI Add unsanctioned AI tools to discovery, inventory, and access review workflows so hidden usage does not remain outside governance.
- Enforce least privilege on agent access Scope each agent to the minimum data, APIs, and actions required for its task, then remove standing access that is not actively needed.
Bottom line: AI governance fails when organisations adopt tools faster than they assign ownership, scope access, and define accountability.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is not a usage problem, it is an identity problem. When employees adopt unmonitored tools, the organisation loses the ability to tie access, ownership, and auditability to a governed identity path. That is why the issue sits across IAM, security, and legal at the same time. Practitioners should treat unsanctioned AI use as a control-plane failure, not a training gap.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
A question worth separating out:
Q: Who is accountable when an AI agent or unapproved tool causes a breach?
A: Accountability should sit with the business owner of the workflow, the technical custodian of the identity path, and the legal or compliance function that approved usage boundaries. If those roles are not defined up front, incident response becomes a debate about ownership instead of a containment exercise.
👉 Read our full editorial: AI agent governance is failing where teams lack ownership
AI agent governance fails first as an ownership problem, not a tooling problem: When no team is clearly accountable for an AI agent, the organisation cannot consistently assign scope, approve data use, or retire access. That breaks the basic governance chain that IAM and legal rely on to make policy enforceable. The implication is that AI governance has to be built as an accountable lifecycle, not as a loose security checklist.
A few things that frame the scale:
- 52% of respondents see AI security decision-making power shifting toward platform and infrastructure teams rather than the executive suite, according to the 2026 Infrastructure Identity Survey.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Who should be accountable for enterprise AI governance?
A: Accountability should sit with a named owner for each AI system, supported by a cross-functional governance structure that includes security, legal, IT, and business leadership. The committee can coordinate decisions, but each AI use case still needs a clear operational owner for approvals and oversight.
👉 Read our full editorial: AI agent governance is failing where teams lack ownership