Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Coding assistants and endpoint AI growth: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Enterprise endpoint AI use grew 509% year over year, while coding assistants rose 357% and Claude 5,680%, according to Cyberhaven Labs data on hundreds of thousands of employees. The finding shows that adoption velocity, not tool popularity, is now the governance variable that determines exposure.

NHIMG editorial — based on content published by Cyberhaven: The Fastest-Growing AI Categories in the Enterprise Are Also the Riskiest

By the numbers:

Questions worth separating out

Q: How should security teams govern coding assistants on developer endpoints?

A: Treat coding assistants as governed non-human identities with endpoint reach, not as simple productivity tools.

Q: Why do AI agents create a visibility problem for IAM teams?

A: AI agents often appear outside formal onboarding through shadow AI, scripts, or workflow tools, so they never enter the normal identity inventory.

Q: What breaks when AI governance only covers one approved vendor?

A: Coverage becomes partial the moment users adopt another model or a desktop client on a different operating system.

Practitioner guidance

  • Instrument endpoint discovery for all AI native apps Track native and desktop AI usage on managed devices, including the operating system, application name, and data paths it can reach.
  • Restrict coding assistants around repositories with secrets Apply repository, path, and workload restrictions before coding assistants are permitted near files that contain API keys, deployment scripts, or internal architecture.
  • Build model-agnostic AI inventory and logging Maintain discovery across Claude, ChatGPT, Copilot, and any other desktop AI tools so that monitoring does not depend on a single sanctioned interface.

What's in the full article

Cyberhaven's full blog post covers the operational detail this post intentionally leaves for the source:

  • Department-level AI usage breakdowns that show where engineering and sales concentration changes the control strategy.
  • OS-specific usage patterns that explain why Mac and Windows fleets need different monitoring assumptions.
  • Examples of how endpoint-native AI tools reach source code, credentials, and internal architecture in daily workflows.
  • The article's own recommended framing for prioritising high-risk AI categories over merely popular ones.

👉 Read Cyberhaven's analysis of the fastest-growing and riskiest enterprise AI categories →

Coding assistants and endpoint AI growth: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Adoption velocity is now the core AI governance variable. When AI tools grow 500% in a year, policy written around quarterly review cycles is already behind the operational reality. The issue is not whether the tool is approved in principle. It is whether governance can observe and constrain what the tool can touch before sensitive data is traversed. For identity teams, that is the same design problem seen in NHI governance when access outpaces lifecycle control. Practitioners should treat speed of adoption as a control signal, not just a usage metric.

A question worth separating out:

Q: Who is accountable when an AI assistant surfaces private code from a cached repository?

A: Accountability usually spans the repository owner, the platform owner, and the team governing indexing or retrieval. The source system may be private, but the cached copy may still be live in another layer. That is why privacy incidents involving code and secrets should be handled as cross-platform access governance failures, not isolated GitHub hygiene issues.

👉 Read our full editorial: Coding assistants are widening the enterprise AI governance gap



   
ReplyQuote
Share: