Join our Newsletter — 33% off our NHI Course

Shadow AI governance is the identity gap teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Unapproved AI use is already widespread, with up to 81% of the global workforce and 88% of security leaders using shadow AI tools, according to JumpCloud. The real problem is not AI adoption itself, but treating AI as software instead of as a governed identity with explicit access, lifecycle, and monitoring controls, while machine identities now outnumber human accounts by at least 100 to 1 in North American enterprises.

Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “The Identity of AI: Why Your Next Employee Isn’t Human”.

By the numbers:

  • Up to 81% of the global workforce uses unapproved AI tools for daily tasks, according to JumpCloud.
  • 88% of security leaders also admit to using these unapproved tools, according to JumpCloud.
  • North American enterprises were seeing machine identities outnumber human accounts by at least 100 to 1, according to JumpCloud.

Key questions

Q: What breaks when AI agents are managed like ordinary machine identities?

A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review.

Q: Why do unapproved AI tools create more risk than traditional software use?

A: Unapproved AI tools can process user input in ways traditional applications do not, including storing prompts, retaining outputs, or reusing data to improve services.

Q: What do security teams get wrong about shadow AI governance?

A: They often treat shadow AI as a banned-app problem when it is usually an identity and accountability problem.

Practitioner guidance

  • Discover shadow AI access paths Scan browser extensions, network traffic, and authentication tokens linked to AI services so you can inventory where AI is being used without approval.
  • Assign ownership to each AI agent Require a business owner, defined permissions, and a decommissioning path for every approved AI tool or agent so the identity has a clear lifecycle.
  • Enforce explicit verification before AI access Treat each AI agent as a non-human identity that must authenticate before reaching data or systems, with access scoped to a specific task.

Bottom line: Shadow AI becomes an identity issue the moment an AI tool can access data or execute work on behalf of a person.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Shadow AI is no longer an application control issue, it is an identity governance issue. Once employees use AI tools to handle data, draft code, or automate work, the control question becomes who or what is acting on behalf of the business. That moves the problem from endpoint blocking into access scope, credential handling, and lifecycle oversight. Practitioners should treat every unmanaged AI path as an identity event, not a software exception.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.

A question worth separating out:

Q: What should organisations do first when employees are using unapproved AI tools?

A: The first step is to discover which tools are in use and which identities they rely on. Then classify the risk by data sensitivity, access scope, and whether the tool can be governed centrally. If a tool cannot be owned, reviewed, or decommissioned, it should be treated as shadow AI exposure until proven otherwise.

👉 Read our full editorial: Shadow AI is turning AI agents into unmanaged identities



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Shadow AI is an identity governance problem before it is a software governance problem. The article is right to move AI tools out of the app-blocking frame and into the access-management frame. Once an AI tool is used to act on data or workflows, the relevant control question becomes who or what is authorised, by whom, and for how long. Practitioners should treat AI usage as an identity boundary, not just an application choice.

A question worth separating out:

Q: How should teams govern AI agents that act inside customer accounts?

A: Treat them as delegated non-human identities, not as ordinary customer sessions. Governance should require explicit consent, narrow authorization scope, token binding, and a complete audit record tying each action back to the human principal that approved it.

👉 Read our full editorial: Shadow AI is turning AI agents into unmanaged identities


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.