TL;DR: AI use is spreading across GenAI SaaS, endpoint AI applications, and AI agents while oversight remains fragmented, according to Cyberhaven’s 2026 AI Adoption & Risk Report for professional services. Its companion blog notes Claude Desktop usage grew 1,233% in six months alongside an 80% rise in GenAI SaaS data movement, and the governance gap is now a data exposure problem, not a future planning issue.
NHIMG editorial — based on content published by Cyberhaven: Cyberhaven 2026 AI Adoption & Risk Report for professional services
By the numbers:
- Data movement through GenAI SaaS rose 80% year over year.
Questions worth separating out
Q: What breaks when employees use unapproved AI tools with company data?
A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused.
Q: Why do local AI agents complicate identity and access management?
A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence.
Q: What do security teams get wrong about AI governance reviews?
A: They often treat every use case as if it needs the same level of scrutiny.
Practitioner guidance
- Inventory AI tools, accounts, and agent paths Create a live register of sanctioned and unsanctioned AI tools, the identities tied to them, and the data they can reach.
- Apply identity lifecycle controls to AI agents Assign each AI agent an owner, a defined purpose, a scoped permission set, and an expiry or review point.
- Link AI access rules to data classification Set policy so sensitive data cannot be copied into AI tools unless the tool, account, and workflow are approved for that data class.
What's in the full report
Cyberhaven's full report covers the operational detail this post intentionally leaves for the source:
- The full report's tool-by-tool adoption patterns across GenAI SaaS, endpoint AI applications, and AI agents
- The data exposure detail behind the report's governance findings, including where the biggest movement is occurring
- The mid-year update context for teams tracking adoption shifts and policy drift over time
- The companion blog on agent containment and the OpenAI-Hugging Face breach
👉 Read Cyberhaven's 2026 AI Adoption & Risk Report for professional services →
AI adoption and data exposure in professional services: are controls keeping up?
Explore further
AI governance debt is now an access-control problem. The report shows AI adoption widening faster than governance can keep pace, which means the issue is not simply policy lag. It is a mismatch between how quickly employees can adopt tools and how slowly organisations can assert control over accounts, permissions, and data movement. For security leaders, the practical conclusion is that AI governance must be treated as part of access governance, not a separate policy exercise.
A question worth separating out:
Q: How can organisations reduce data exposure in AI tools?
A: Start with data classification, then map where sensitive information can flow into prompts, connectors, and logs. Limit AI systems to the minimum data they need, require owner approval for higher-risk datasets, and monitor for unsanctioned sharing. Data controls work best when paired with identity controls and usage visibility.
👉 Read our full editorial: AI adoption is outpacing governance in professional services