TL;DR: Shadow AI is expanding faster than enterprise governance can see it, with one example finding 243 AI products in use where leaders believed there were six and the article citing Thomson Reuters data that generative AI use nearly doubled in a year, according to Island. The core issue is tenant-blindness at the point of use, and blocking alone often pushes risky activity into personal accounts and unmanaged devices.
NHIMG editorial — based on content published by Island: The AI You Can't See: Why Shadow AI Is a Visibility Problem, Not a Blocking Problem
By the numbers:
- An enterprise found 243 AI products in active use after believing it had only six sanctioned tools.
Questions worth separating out
Q: How should organisations govern shadow AI without blocking legitimate use?
A: Start with approved-use policy, tool inventory, and data classification.
Q: Why does shadow AI create an identity governance problem?
A: Shadow AI creates an identity governance problem because unapproved tools and agents can access enterprise data without being inventoried, owned, or recertified.
Q: What do security teams get wrong about blocking AI tools outright?
A: They assume network blocking creates control, but users often shift to personal devices, browser workarounds, or OS-level agents that bypass those restrictions.
Practitioner guidance
- Map actual AI usage before writing new policy Discover which AI tools, tenants, extensions, and agents are truly in use across browser, desktop, and sanctioned enterprise accounts, then compare that inventory with the approved list.
- Move control to the point of use Use context-aware controls that can distinguish corporate from personal sessions, unmanaged devices, and sensitive prompts before data leaves the approved environment.
- Treat agent connectors as governed identities Scope Model Context Protocol and similar connectors as delegated access paths, with explicit ownership, least privilege, and logging for each backend system they can reach.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- The browser-level visibility model used to distinguish corporate from personal AI access.
- How the control point shifts when AI use spans browser, desktop, and network layers.
- Why agentic AI and MCP-style connections widen the governance surface beyond ordinary shadow IT.
- The vendor's example of consolidating thousands of atomic rules into a smaller application-boundary model.
👉 Read Island's analysis of why shadow AI is a visibility problem →
Shadow AI visibility gaps: are your controls keeping up?
Explore further
Shadow AI is an identity governance problem disguised as a visibility problem. The operational issue is not simply that teams cannot list every tool, but that they cannot reliably distinguish sanctioned AI access from unsanctioned use across tenants, devices, and sessions. That makes AI oversight partly an identity problem, because governance fails when the organisation cannot bind use to a trusted account, context, or control boundary. The practitioner conclusion is clear: AI discovery must become part of identity governance, not a separate side programme.
A question worth separating out:
Q: How should teams respond when AI agents can reach backend systems?
A: Treat each connector as a governed delegation path with explicit ownership, scoped permissions, and logging. If an agent can move data across systems, it needs controls closer to PAM and NHI governance than to ordinary application usage oversight.
👉 Read our full editorial: Shadow AI is a visibility problem, not a blocking problem