TL;DR: Automated discovery typically reveals an AI footprint 30 to 50 percent larger than leadership expects, exposing shadow AI, duplicated tools, hidden workflows, and unmanaged third-party features that undermine governance assumptions, according to Holistic AI. Discovery is the control that makes inventory, classification, monitoring, and compliance operational rather than theoretical.
NHIMG editorial — based on content published by Holistic AI: AI Governance. AI Discovery Comes First: You Can’t Govern What You Can’t See
By the numbers:
- The true AI footprint is typically 30–50% larger than leadership expects when automated discovery is applied.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- Systems with least-privileged AI access had a 17% incident rate versus 76% for over-privileged systems, making poorly scoped AI access 4.5x more likely to end in an incident.
Questions worth separating out
Q: How should organisations govern AI systems that cannot verify themselves?
A: They should treat self-checks as advisory only and require an external validation layer for any output that affects security, access, or operational decisions.
Q: Why do hidden AI tools create a governance risk beyond ordinary software sprawl?
A: Hidden AI tools can process sensitive data, call external services, and change outputs or decisions without leaving a clear ownership trail.
Q: What do security teams get wrong about AI governance inventories?
A: They often inventory only the AI they built themselves and miss embedded AI inside vendor platforms and other shadow AI.
Practitioner guidance
- Implement continuous AI discovery Scan cloud accounts, repositories, data platforms, collaboration tools, and internal SaaS settings on an ongoing basis so new AI artefacts are detected as they appear.
- Classify hidden AI by ownership and risk Turn discovered tools, prompts, datasets, and workflows into governed records with named owners, lifecycle status, and data sensitivity labels.
- Map AI dependencies across the estate Link prompts, pipelines, endpoints, and connected datasets so a change in one AI component can be traced to the systems it affects.
What's in the full article
Holistic AI's full blog covers the operational detail this post intentionally leaves for the source:
- A deeper walk-through of the discovery to inventory to ontology pipeline used to build a governed AI graph.
- Examples of the cloud, code, data, document, and agent platforms that continuous discovery can scan.
- Operational detail on how hidden AI artefacts are turned into ownership records and risk classifications.
- The article's own explanation of why full-stack discovery is different from static inventory checks.
👉 Read Holistic AI's analysis of why AI discovery must come before governance →
AI discovery and shadow AI governance: what teams are missing?
Explore further
Discovery is the real control boundary for AI governance. Governance frameworks assume an accurate asset picture, but AI changes too quickly for spreadsheets and annual reviews to keep pace. When discovery is missing, classification, monitoring, and audit all operate on stale assumptions. Practitioners should treat visibility as the first enforceable control, not an administrative cleanup step.
A question worth separating out:
Q: Who is accountable when shadow AI creates spend and compliance risk?
A: Accountability should sit with the business owner of the workflow, the identity that initiated the activity, and the governance function that approved or failed to detect it. If no one can trace an AI interaction back to a named owner, the organisation has already lost control of both spend and policy enforcement.
👉 Read our full editorial: AI discovery is the missing first step in enterprise governance