Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Shadow AI visibility is the governance gap teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12387
Topic starter  

TL;DR: Only 13% of IT and security professionals say they have full visibility into AI tools used in their organisation, leaving 87% without confidence in the inventory that GRC, privacy, and security controls depend on, according to Drata’s 2026 State of GRC survey. The practical issue is no longer AI adoption alone, but whether governance can discover and account for what employees are already using.

NHIMG editorial — based on content published by Drata: the first post in its 2026 State of GRC series on AI visibility and shadow AI

By the numbers:

Questions worth separating out

Q: What breaks when organisations cannot inventory their AI credentials?

A: Rotation, recertification, and offboarding all break down when the inventory is incomplete.

Q: Why does shadow AI create a governance gap for IAM and security teams?

A: Shadow AI creates a governance gap because organizations cannot manage systems they do not reliably see.

Q: How do you know if AI discovery is actually working?

A: AI discovery is working when the organisation can produce one authoritative inventory, classify tools consistently, and explain which data and permissions each tool can reach.

Practitioner guidance

  • Implement continuous AI discovery Monitor endpoints, browsers, SaaS logs, and collaboration tools for AI usage so the inventory updates as new tools appear.
  • Bind every AI tool to an owner Require a named business owner and technical owner for each AI capability before it is approved for use.
  • Tie AI review to data-classification rules Flag tools that receive regulated, confidential, or customer data and route them through the same approval logic used for sensitive SaaS and workflow systems.

What's in the full report

Drata's full post covers the operational detail this analysis intentionally leaves for the source:

  • The survey methodology and respondent breakdown behind the 13% visibility finding
  • Drata's recommended continuous-monitoring approach for surfacing new AI tools as they appear
  • The four inventory questions the vendor says every AI programme should answer before approval
  • The workload and capacity comparison between teams with complete and incomplete AI inventories

👉 Read Drata's analysis of the 2026 GRC survey on AI visibility →

Shadow AI visibility is the governance gap teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11961
 

Shadow AI is now a governance discovery problem, not a policy-writing problem. Organisations can write acceptable-use rules quickly, but those rules do not constrain tools that have never been identified. The survey result showing only 13% full visibility demonstrates that discovery is the real control plane. For GRC and identity teams, the practical conclusion is that governance begins with asset discovery, ownership, and continuous monitoring, not with policy exceptions.

A question worth separating out:

Q: Who is accountable when AI output causes a compliance or legal issue?

A: Accountability sits with the organisation that deploys and governs the AI use case, not only with the vendor that hosts the model. If an employee or agent uses AI in a business context, the enterprise must be able to show policy, monitoring, and evidence of control. That is now a governance obligation, not optional hygiene.

👉 Read our full editorial: Shadow AI visibility gaps are undermining governance in GRC



   
ReplyQuote
Share: