TL;DR: C1.ai reports that knowledge workers are already using AI tools at scale, but only 18% know their company’s AI policy and 78% are bringing their own tools. The deeper failure is not model quality but the lack of identity, policy, and lifecycle controls that make governed AI easier than shadow AI.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Your AI Strategy Has a Blind Spot”.
Key questions
Q: How should teams stop shadow AI from becoming the default access path?
A: Make the governed path faster and simpler than bypasses.
Q: Why do AI agents need identity and access governance if the model is already strong?
A: Because model strength does not control who or what the agent can touch in production.
Q: What breaks when AI access still depends on manual setup and approvals?
A: Users bypass the approved route.
Practitioner guidance
- Map shadow AI entry points Inventory personal assistants, browser-based AI tools, MCP connections, and locally created credentials that bypass formal request workflows.
- Classify AI agents as governed identities Assign ownership, lifecycle states, and scoped permissions to enterprise agents and user-scoped assistants instead of treating them as unmanaged integrations.
- Separate low-risk from privileged AI actions Define which tool calls can be auto-approved and which operations require step-up human approval at execution time.
Bottom line: AI adoption becomes a governance failure when the approved path is slower and more technical than the shadow path.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- The step-by-step access flow for governed AI provisioning, including Slack approval and policy-based auto-approval
- The operational distinctions between personal assistants and enterprise agents, including ownership and lifecycle handling
- The credential vaulting and audit workflow behind tool-level enforcement for AI access
- The practical comparison between manual setup for MCP access and a governed access path
👉 Read C1.ai's analysis of AI governance, identity controls, and shadow AI →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity, not model quality, is the governance bottleneck in enterprise AI. The article’s core insight is that workers already want AI access, but the approved path is too slow and technical to compete with shadow adoption. That means governance fails at issuance, approval, and enforcement, not at model selection. Practitioners should treat AI adoption as an identity workflow problem first.
A few things that frame the scale:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap, according to the State of Secrets in AppSec.
- Business leaders plan to spend $124 million on average on AI in 2026, and 91% say data security and risk will shape their AI strategy.
A question worth separating out:
Q: When should organisations require human approval for an AI agent action?
A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse. Approval is also warranted when the agent’s decision depends on ambiguous input or external data that cannot be trusted at face value. High-consequence actions need a human stop point.
👉 Read our full editorial: AI governance’s blind spot is identity, not model quality