TL;DR: AI adoption is expanding the identity problem from unmanaged non-human accounts to shadow AI and agentic access, while 77% of employees sharing secrets on ChatGPT shows the human, machine, and AI governance gaps are converging, according to Oasis Security. The security issue is no longer discovery alone, but whether identity control can keep pace with runtime behaviour across all three actor types.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “From Shadow AI to Trusted AI: Securing the Future”.
By the numbers:
- 77% of employees sharing secrets on ChatGPT jeopardizes enterprise security.
Key questions
Q: How should security teams govern shadow AI without slowing adoption?
A: Start with continuous discovery, then classify tools by data access, system connectivity, and provider trust.
Q: Why do AI prompts create identity and data-security risk?
A: AI prompts create risk because they can carry sensitive content outside the original system’s protection boundary.
Q: When should organisations prioritise runtime AI controls over static approvals?
A: Organisations should prioritise runtime AI controls whenever a system can generate outputs, call tools, or move data without a human approving each step.
Practitioner guidance
- Map shadow AI as an identity estate Inventory AI tools, assistants and automations alongside the human and machine identities they use so ownership, access and revocation are traceable.
- Enforce purpose-bound runtime access Restrict AI workflows to the minimum tools and data sources required for the task, and apply just-in-time elevation only where the action truly needs it.
- Treat secret sharing as credential leakage Block or monitor the movement of secrets, tokens and API keys into AI prompts and connected workflows, then revoke exposed credentials immediately.
Bottom line: Shadow AI turns AI adoption into an identity governance issue because tools, tokens and delegated access can appear outside the normal control plane.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is an identity governance problem before it is an AI governance problem. The article’s central value is that it shifts the discussion from model risk to access control, ownership and lifecycle management. When AI tools appear outside inventory, IAM loses the ability to certify, review or revoke with confidence. Practitioners should treat undiscovered AI access as unmanaged identity exposure, not merely as a technology sprawl issue.
A few things that frame the scale:
- Organisations that describe themselves as confident in their AI deployment actually experience a 72% security incident rate, compared to 33% for those who remain cautious, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between human identity governance and NHI governance for AI tools?
A: Human identity governance assumes a person, a manager, and a clear employment lifecycle. NHI governance has to manage credentials, tokens, bots, and agents that can appear instantly, change scope quickly, and outlive the original use case if no one explicitly retires them.
👉 Read our full editorial: Cyber beyond humans: shadow AI and trusted AI governance