Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI governance in 90 days: what should teams do first?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: Governance fails when telemetry, access, and reuse are improvised after deployment, because shadow AI wins whenever the unmanaged path is faster than the governed one, according to C1.ai. C1.ai argues for a five-move, 90-day methodology that starts with a single AI intake funnel, central audit logging, identity-aware wraps for the highest-blast-radius apps, reusable agent assets, and weekly measurement of the fastest path between safe and unsafe access.

NHIMG editorial — based on content published by C1.ai: What Would You Do Monday? Here's the Actual Answer. Five moves. Ninety days. No new hires, no vendor decisions, no multi-year roadmap before you start

Questions worth separating out

Q: How should organizations approach the governance of AI agents?

A: Organizations should adopt a governance framework that incorporates continuous visibility, adaptive IAM practices, and stringent policy-based controls.

Q: Why do audit logs not solve AI governance by themselves?

A: Audit logs show activity after it happens, but they do not prevent excessive access or unclear delegation.

Q: What are the signs that shadow AI is still winning?

A: The clearest sign is when the unmanaged route is faster than the governed one and teams keep using it.

Practitioner guidance

  • Create one AI intake front door Require every AI project, build or buy, to enter through a single submission path with ownership, intended use, and review metadata.
  • Stand up central audit logging first Capture agent activity into one queryable log before writing enforcement rules so you can answer what agents did this quarter in under 60 seconds.
  • Wrap the highest-blast-radius applications Place identity-aware proxies in front of the three applications where direct misuse would create the most damage, then date and deprecate old service-account paths as traffic shifts to the governed layer.

What's in the full article

C1.ai's full post covers the operational detail this analysis intentionally leaves for the source:

  • The exact five-move 90-day sequence and the weekly targets attached to each move.
  • The role assignments for CIO staff, CAIO, COO, platform engineering, and business-unit owners.
  • The dashboard metrics used to measure fastest-path delta across safe and unsafe routes.
  • The year-one progression model from initial funnel to reusable assets and quarterly review rhythms.

👉 Read C1.ai's 90-day AI governance playbook for identity and access teams →

AI governance in 90 days: what should teams do first?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Single-path intake is a governance control, not just an operating convenience. When AI projects can enter the enterprise through multiple informal channels, ownership fragments before the first access decision is made. That creates a shadow governance layer that IAM cannot certify, because the system of record was never established. The implication is that identity programmes must treat intake as a control point, not a coordination task.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: How do security teams know if AI governance is working?

A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent. If the team cannot explain who owns an AI workflow, what it can reach, and when its access was last reviewed, governance is incomplete. Control maturity shows up in traceability, not adoption volume.

👉 Read our full editorial: Monday moves for AI governance: five steps in 90 days



   
ReplyQuote
Share: