TL;DR: Most enterprise AI governance fails at enforcement, because AI now appears inside SaaS, OAuth grants, browser tools, and AI agents that periodic reviews cannot reliably see, according to Grip Security. The practical shift is from policy documents to continuous discovery, identity context, and technical controls that can actually reduce permissions and revoke access.
NHIMG editorial — based on content published by Grip Security: How to Build an AI Governance Program That Actually Enforces Policy
By the numbers:
- 54%, e than half of enterprise applications, 54%, now contain detectable AI functionality, and the average Grip customer uses 1,017 AI-enabled applications.
- Grip's 2026 observations found approximately one AI agent for every 17 identities.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
Questions worth separating out
Q: How should security teams govern AI agents that use OAuth access?
A: Security teams should inventory each agent, limit scopes to the minimum required, assign an owner, and monitor its behaviour continuously.
Q: Why do AI governance programs fail when they rely on approved-tool lists alone?
A: Approved-tool lists only describe which applications were reviewed, not what AI can reach after deployment.
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability.
Practitioner guidance
- Discover AI where it actually operates Inventory standalone AI tools, embedded SaaS features, browser-based tools, OAuth-connected apps, and AI agents in one view.
- Map each AI capability to an owner and access path For every AI integration or agent, identify the human owner, the non-human identity used, the OAuth scopes granted, and the SaaS applications reached.
- Translate policy into revocation and reduction controls Define which AI permissions must be reduced, which OAuth grants must be revoked, and which integrations should be removed when they exceed policy.
What's in the full article
Grip Security's full webinar covers the operational detail this post intentionally leaves for the source:
- The webinar shows how to turn policy into specific control actions across AI, identities, permissions, OAuth, and SaaS.
- It walks through the discovery to enforcement workflow in more operational detail than this analysis.
- It expands on continuous monitoring and remediation triggers for new AI apps, integrations, and permission drift.
- It includes the source material's webinar framing and implementation emphasis for teams building an AI governance programme.
👉 Read Grip Security's webinar on building an enforceable AI governance program →
AI governance enforcement: what IAM and security teams are missing?
Explore further
AI governance fails first as an identity problem, not a policy problem. Organisations can publish acceptable-use rules, approval workflows, and committee decisions without changing what an AI system can actually reach. Once AI appears inside SaaS, OAuth, and agentic workflows, the control point shifts to identity, permission, and lifecycle governance. The field should treat AI governance as an access-control discipline with policy as input, not as the control itself.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to The 2026 Infrastructure Identity Survey.
- Another finding from the same survey shows that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
A question worth separating out:
Q: Who should own AI governance when AI touches identity and access?
A: Ownership should sit with the team that can explain the AI system’s access, purpose, and operating boundaries end to end. In practice, that means AI governance must connect security, IAM, data, and engineering accountability so the system is not treated as a floating experiment. If ownership is unclear, lifecycle control will be inconsistent.
👉 Read our full editorial: AI governance needs enforceable controls, not just policy and review