TL;DR: Most organisations are using AI or preparing to adopt it, while 94% of IT leaders worry about unchecked integrations and compliance gaps, according to JumpCloud. The real issue is not AI enthusiasm but whether governance, identity controls, and monitoring can keep shadow AI and over-permissioned machine access from expanding the attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Avoiding AI Risks: Policies Your IT Team Needs Now”.
By the numbers:
- 94% of IT leaders worry about unchecked integrations and compliance gaps that could leave their organizations exposed.
- Only 23% of IT teams actively manage machine identities today.
Key questions
A: Security teams should treat authentication and token handling as first-class controls, not afterthoughts.
Q: Why do AI systems create identity risk as well as model risk?
A: Because AI systems rarely act alone.
Q: What are the signs that AI governance is failing in the enterprise?
A: Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.
Practitioner guidance
- Formalise AI integration approval Require named approval owners, security checks, data-flow review, and compliance validation before any AI integration is allowed into production.
- Inventory AI-linked machine identities Track service accounts, API keys, tokens, and credentials used by AI tools so each identity has a documented owner and purpose.
- Tighten permissions for AI workloads Grant bots and service accounts only the minimum access needed for the approved use case, then review scope when the use case changes.
Bottom line: AI adoption is expanding identity risk because AI systems rely on the same credentials, permissions, and data access paths that IAM teams already govern.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI governance is now identity governance with a broader tool surface: Once AI systems are allowed to touch infrastructure, the policy question shifts from model permission to account permission. That means approval, logging, and review mechanisms must cover the identities the AI uses, not just the application the business sees. Organisations that keep AI governance separate from IAM will miss the actual control point.
A few things that frame the scale:
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to the State of Secrets in AppSec.
A question worth separating out:
Q: How should organisations govern access to data used by AI systems?
A: Treat AI data access as an identity governance problem, not just a data storage problem. Define who or what can use each dataset, what purpose is allowed, and what runtime restrictions apply. Then review humans, service accounts, and AI agents separately so entitlement scope matches actual behaviour rather than a generic AI policy.
👉 Read our full editorial: AI governance policies now define identity risk in enterprise IT