TL;DR: Shadow AI is proliferating inside browsers, devices, and on-premise environments, and according to JumpCloud, 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from less than 5% at the start of 2025. Traditional IAM cannot govern what discovery cannot see, and agentic access now needs lifecycle control as well as policy enforcement.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “The Visibility Crisis: Why AI Agents Need To Get Out Of Your Blind Spots”.
By the numbers:
- 40% of all enterprise applications will embed task-specific AI agents by the end of 2026, according to Gartner research cited by JumpCloud.
- AI agents in enterprise applications will rise from less than 5% at the start of 2025 to 40% by the end of 2026, according to Gartner research cited by JumpCloud.
Key questions
Q: What breaks when shadow AI is not included in identity governance?
A: When shadow AI is excluded, the organisation loses discovery, ownership, and enforcement at the same time.
Q: Why do AI agents create a governance problem for IAM teams?
A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.
Q: What are the warning signs that shadow AI is becoming a security problem?
A: Look for AI tools connected outside approved procurement, unexplained API or token usage, and data leaving normal SaaS boundaries.
Practitioner guidance
- Inventory AI identities across execution surfaces Map agents in browsers, endpoints, and on-premise environments so discovery is not limited to approved applications or cloud tenants.
- Assign ownership before access expands Require a named steward for every discovered AI identity and tie that ownership to access approval, review, and revocation decisions.
- Constrain agent permissions to task scope Limit each agent to the minimum data, APIs, and workflows it needs for the specific use case instead of inheriting broad user access.
Bottom line: Shadow AI becomes a governance failure when agents can act before identity teams can see, own, or retire them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is now an identity discovery problem, not just an application control problem. The article’s central failure mode is that AI agents can appear in browsers, devices, and on-premise environments without passing through identity intake. That means the security programme cannot govern what it cannot enumerate. The practitioner conclusion is simple: if the identity is not discoverable, it is not governable.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should organisations govern AI agent risk once discovery is in place?
A: Treat discovery as the first control, then attach ownership, access scope, behavioural monitoring, and review cadences to each active agent. Governance should be based on who can act, what they can reach, and whether the action still matches the business purpose. That is the point where policy becomes enforceable.
👉 Read our full editorial: Shadow AI visibility gaps are outpacing enterprise IAM controls