TL;DR: AI sprawl is shifting enterprise risk from application sprawl to identity sprawl, with embedded AI, browser assistants, copilots, agents, and OAuth-connected services multiplying trusted access paths, according to Grip Security. Existing governance models break when access relationships change continuously and non-human identities outnumber manual review cycles.
NHIMG editorial — based on content published by Grip Security: AI Sprawl: The Next Enterprise Security Challenge
By the numbers:
- 54% of enterprise applications now contain AI functionality, according to Grip Security's Mid-Year AI Exposure Update.
- AI-related attacks increased approximately 490% year over year, according to the Grip Security 2026 SaaS + AI Security Report.
Questions worth separating out
Q: How should security teams govern AI features embedded in SaaS applications?
A: Treat embedded AI as a machine identity problem with data access implications.
Q: Why does AI sprawl create more risk than traditional SaaS sprawl?
A: Because AI expands the number of identities that can act, the amount of delegated access they inherit, and the speed at which those relationships change.
Q: What do security teams get wrong about AI agent identity governance?
A: They often assume human IAM patterns can be reused with minor adjustments.
Practitioner guidance
- Inventory AI by identity, not by application Map embedded AI features, browser assistants, copilots, agents, service accounts, and OAuth-connected services in one control plane so governance can follow access relationships instead of product names.
- Continuously govern delegated OAuth scopes Review connected permissions on a fixed cadence, remove inactive integrations, and flag any AI service with broad read or write scope across email, files, or collaboration systems.
- Apply NHI lifecycle control to AI agents Assign ownership, define explicit purpose, review runtime authority, and revoke access when the agent no longer has a justified use case or changes function.
What's in the full article
Grip Security's full webinar covers the operational detail this post intentionally leaves for the source:
- A walkthrough of the AI sprawl operating model across SaaS, browser tools, copilots, and autonomous agents.
- Specific examples of how OAuth-connected services expand delegated trust across enterprise applications.
- The research-backed breakdown of AI exposure patterns and the data behind the Rule of 17.
- Implementation guidance on continuous discovery and automated remediation for AI-related access.
👉 Watch Grip Security's webinar on AI sprawl and identity-first governance →
AI sprawl and identity-first governance: are your controls keeping up?
Explore further
AI sprawl is really a trust-sprawl problem. The article is correct to shift the discussion away from application count and toward the web of identities, permissions, and delegated relationships that AI creates. Once AI features arrive through existing SaaS products, the real control boundary becomes who and what can act under inherited authority. Practitioners should treat trust relationships as the primary governance object, not the application catalog.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly repeat exposure follows governance gaps.
A question worth separating out:
Q: How should teams reduce risk from OAuth-connected AI services?
A: They should monitor delegated scopes continuously, remove dormant integrations, and restrict any service that can reach email, files, CRM records, or collaboration tools without a current business need. Persistent OAuth trust is one of the easiest ways for AI-driven access to outlive the purpose it was granted for.
👉 Read our full editorial: AI sprawl is turning identity governance into the real control plane