Join our Newsletter — 33% off our NHI Course

AI usage control: what it means for IAM teams and governance

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI Usage Control is emerging as a distinct governance layer because traditional network, endpoint, and legacy DLP controls cannot inspect real-time AI interactions with enough context, according to Lasso Security. The practical issue is not whether organisations allow AI, but whether they can govern prompt-time use, data sharing, and output reuse without collapsing existing IAM assumptions.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Comprehensive Guide to AI Usage Control for Enterprise Security Teams”.

Key questions

Q: What breaks when AI usage is governed only with static allowlists and access rules?

A: Static allowlists and access rules control whether a user can reach an AI tool, but they do not govern what happens inside the live interaction.

Q: Why do legacy DLP controls fail to stop insider risk and GenAI data exposure in practice?

A: Legacy DLP often fails because it relies on static rules and pattern matching that miss the full path of sensitive data.

Q: What are the signs that AI tool usage is outside governance?

A: Look for repeated calls to AI endpoints from unmanaged devices, local processes tied to MCP servers, newly active OAuth tokens, and browser or desktop extensions that have not been reviewed.

Practitioner guidance

  • Implement runtime policy enforcement Inspect prompts, context and outputs at the moment of interaction so policy decisions happen before sensitive information is shared or reused.
  • Inventory shadow AI usage continuously Track browser assistants, copilots, extensions and embedded AI features as active security events, not one-time approvals.
  • Tie AI policy to role and data sensitivity Differentiate low-risk summarisation from high-risk handling of financial, personal or source-code data, and enforce those distinctions consistently.

Bottom line: AI usage control addresses the gap between permitted access and governed use, which is where most enterprise GenAI risk now appears.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 57 minutes ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21363
 

AI usage control is the missing runtime layer between access governance and data protection. The article describes a category that sits inside live workflows, where traditional IAM and DLP controls have weak visibility. That framing is correct because the risk is behavioural, not just perimeter-based. Practitioners should treat AI usage control as a governance layer that closes the gap between permission and actual use.

A few things that frame the scale:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.

A question worth separating out:

Q: Who should be accountable for AI usage policy violations?

A: Accountability should sit with the identity and control owners who can enforce the policy, but business leaders must own the risk decisions for sensitive workflows. If the organisation cannot explain who approved the use case, who monitored it, and who can stop it, the control is not operational.

👉 Read our full editorial: AI usage control exposes the gap between policy and live AI use



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21363
 

AI usage control is a usage-governance layer, not a narrower access-control variant. The article shows that the control point moves to the live interaction because the risky act is not simply opening an AI application, but deciding what data and context enter the prompt and what happens to the output. That is a different governance problem from authorisation at login. Practitioners should stop treating AI governance as a binary allow or block decision and instead define controls around actual use.

A question worth separating out:

Q: How can organisations balance AI productivity gains with accountability?

A: Use AI for drafting, clustering, and highlighting patterns, but keep approvals, commitments, and value definitions with named humans. Pair that with role-based access, review gates, and audit logs so every material decision can be challenged later. Productivity gains only hold when accountability stays explicit.

👉 Read our full editorial: AI usage control exposes the gap between policy and live AI use


This post was modified 57 minutes ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.