TL;DR: AI-generated deepfakes, hallucinations and shadow AI are pushing organisations toward continuous verification of identities, devices and actions rather than default trust, according to Commvault. The governance lesson is clear: responsible AI adoption succeeds when policy, guardrails and approved tools reduce blind trust without blocking productivity.
NHIMG editorial — based on content published by Commvault: AI trust, zero trust and shadow AI in the age of convincing AI
Questions worth separating out
Q: How should organisations govern AI usage when employees use unapproved tools?
A: Organisations should start with visibility, not enforcement.
Q: Why do deepfakes change identity verification requirements?
A: Deepfakes change requirements because they let attackers create believable but false evidence that can pass weak visual checks.
Q: What breaks when organisations trust AI outputs too quickly?
A: Decision quality breaks first, followed by governance and accountability.
Practitioner guidance
- Map AI tools to governed access paths Inventory approved and shadow AI tools alongside the identities, data sets and internal systems they can reach.
- Add contextual checks to high-risk AI actions Require additional verification when AI-enabled workflows touch finance, identity recovery, privileged approvals or data export.
- Redesign identity recovery for deepfake resistance Move high-risk recovery and approval flows away from voice-only or chat-only confirmation.
What's in the full article
Commvault's full article covers the conversational framing, examples and episode context this post intentionally leaves for the source:
- The full episode discussion with Diana Kelley on how trust changes as AI systems imitate people and make decisions.
- The practical examples used to explain zero trust, shadow AI and continuous verification in a business setting.
- The broader Ready. Or Not. episode context that links agentic AI, cyber resilience and data management.
- The original FAQ-style answers on digital trust, deepfakes, zero trust and shadow AI.
👉 Read Commvault's discussion of AI trust, zero trust and shadow AI →
AI trust, shadow AI and zero trust: what should teams do now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Continuous verification is becoming the operating model for AI trust. The article reinforces a structural shift: organisations can no longer treat identity assurance as a one-time event. When AI can imitate people, generate content and act inside workflows, trust has to be re-established at the point of action. That aligns with zero trust architecture and with the broader move toward contextual identity decisions in both human and machine workflows. Practitioners should treat every sensitive AI-enabled interaction as a re-verification moment.
A question worth separating out:
Q: Who is accountable when shadow AI creates spend and compliance risk?
A: Accountability should sit with the business owner of the workflow, the identity that initiated the activity, and the governance function that approved or failed to detect it. If no one can trace an AI interaction back to a named owner, the organisation has already lost control of both spend and policy enforcement.
👉 Read our full editorial: AI trust now depends on continuous verification, not default trust