TL;DR: Only 13% of IT and security professionals say they have full visibility into AI tools used in their organisation, leaving 87% without confidence in the inventory that GRC, privacy, and security controls depend on, according to Drata’s 2026 State of GRC survey. The practical issue is no longer AI adoption alone, but whether governance can discover and account for what employees are already using.
NHIMG editorial — based on content published by Drata: the first post in its 2026 State of GRC series on AI visibility and shadow AI
By the numbers:
- Only 13% of IT and security professionals confidently claim full visibility into the AI tools active in their organization.
- 77% of GRC teams report a meaningful increase in workload.
- 68% of teams with confidence in the completeness of their AI inventory took on a 10%+ workload increase with no new headcount.
Questions worth separating out
Q: What breaks when organisations cannot inventory their AI credentials?
A: Rotation, recertification, and offboarding all break down when the inventory is incomplete.
Q: Why does shadow AI create a governance gap for IAM and security teams?
A: Shadow AI creates a governance gap because organizations cannot manage systems they do not reliably see.
Q: How do you know if AI discovery is actually working?
A: AI discovery is working when the organisation can produce one authoritative inventory, classify tools consistently, and explain which data and permissions each tool can reach.
Practitioner guidance
- Implement continuous AI discovery Monitor endpoints, browsers, SaaS logs, and collaboration tools for AI usage so the inventory updates as new tools appear.
- Bind every AI tool to an owner Require a named business owner and technical owner for each AI capability before it is approved for use.
- Tie AI review to data-classification rules Flag tools that receive regulated, confidential, or customer data and route them through the same approval logic used for sensitive SaaS and workflow systems.
What's in the full report
Drata's full post covers the operational detail this analysis intentionally leaves for the source:
- The survey methodology and respondent breakdown behind the 13% visibility finding
- Drata's recommended continuous-monitoring approach for surfacing new AI tools as they appear
- The four inventory questions the vendor says every AI programme should answer before approval
- The workload and capacity comparison between teams with complete and incomplete AI inventories
👉 Read Drata's analysis of the 2026 GRC survey on AI visibility →
Shadow AI visibility is the governance gap teams are missing?
Explore further
Shadow AI is now a governance discovery problem, not a policy-writing problem. Organisations can write acceptable-use rules quickly, but those rules do not constrain tools that have never been identified. The survey result showing only 13% full visibility demonstrates that discovery is the real control plane. For GRC and identity teams, the practical conclusion is that governance begins with asset discovery, ownership, and continuous monitoring, not with policy exceptions.
A question worth separating out:
Q: Who is accountable when AI output causes a compliance or legal issue?
A: Accountability sits with the organisation that deploys and governs the AI use case, not only with the vendor that hosts the model. If an employee or agent uses AI in a business context, the enterprise must be able to show policy, monitoring, and evidence of control. That is now a governance obligation, not optional hygiene.
👉 Read our full editorial: Shadow AI visibility gaps are undermining governance in GRC