TL;DR: AI-related attacks rose nearly 490% year over year, while enterprises now average 139+ AI-enabled SaaS applications and 23,021 SaaS apps outside centralized visibility, according to Grip Security’s 2026 SaaS + AI Security Report. The governance gap is shifting from model oversight to identity, OAuth, and access-path control, which makes unmanaged non-human identities the operational weak point.
NHIMG editorial — based on content published by Grip Security: AI Governance Statistics for 2026: Trends, Risks & Enterprise Data
By the numbers:
- AI-related attacks increased approximately 490% year over year
- The average enterprise now operates 139+ AI-enabled SaaS applications
Questions worth separating out
Q: How should security teams govern AI agents that use OAuth access?
A: Security teams should inventory each agent, limit scopes to the minimum required, assign an owner, and monitor its behaviour continuously.
Q: Why do AI agents make non-human identity governance harder?
A: AI agents make governance harder because they can request tools, act autonomously, and change behaviour across sessions while still relying on machine credentials.
Q: What breaks when SaaS sprawl is left out of AI governance?
A: AI governance breaks when SaaS sprawl is ignored because the organisation loses visibility into where AI is embedded, which identities connect those tools, and what data those tools can touch.
Practitioner guidance
- Inventory AI-enabled SaaS and connected identities continuously Build a unified inventory of AI-capable SaaS applications, OAuth-consented apps, service accounts, API keys, and automation identities.
- Review OAuth scopes as a lifecycle control Treat delegated permissions as standing access until proven otherwise.
- Add NHI controls to AI governance workflows Require NHI inventory, ownership, rotation, and offboarding checks before AI integrations go live.
What's in the full report
Grip Security's full report covers the operational detail this post intentionally leaves for the source:
- SaaS and AI attack trend breakdowns that show where the 490% year-over-year increase is coming from
- Visibility data on OAuth risk, third-party integrations, and unmanaged AI-enabled applications
- Operational guidance on how identity exposure, delegated access, and SaaS sprawl combine into governance failure
- Practical recommendations for teams trying to prioritise discovery, review, and control implementation
👉 Read Grip Security's AI governance statistics for 2026 and the identity risk patterns behind them →
AI governance is failing at the identity layer, not the model layer?
Explore further
AI governance debt is accumulating faster than most security programmes can absorb. The article shows that adoption is outrunning inventory, review, and enforcement, which means governance is becoming a lagging control rather than an enabling one. Once SaaS and AI capabilities are distributed across hundreds of applications, policy-only governance loses practical force. Practitioners should treat governance debt as a measurable security exposure, not a maturity slogan.
A question worth separating out:
Q: Who should own accountability for AI data access risk?
A: Accountability should sit with the teams that own identity, data governance, and security operations together. If AI can access enterprise data, then ownership must cover entitlement design, monitoring, and incident response across the full workflow. The governance gap is not just technical, because without a named owner, no one can prove who approved or contained the access.
👉 Read our full editorial: AI governance risk is really an identity governance problem