Join our Newsletter — 33% off our NHI Course

Shadow AI and OAuth tokens: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Vercel’s breach reportedly began with an employee approving broad OAuth access for an unapproved AI tool, then escalated through a stolen token into Google Workspace and internal systems before stolen data surfaced on BreachForums, according to Josys. The incident shows that visibility into SaaS integrations and permission chains now matters as much as endpoint security.

Editorial analysis by NHI Mgmt Group, based on content published by Josys: “5 Things the Vercel Breach Reveals About Shadow AI and Your Organization”.

By the numbers:

  • 78% of employees use AI tools like ChatGPT and Claude.
  • Only 30% of organizations have full visibility into what those tools are.

Key questions

Q: What breaks when employees can approve unreviewed AI apps with OAuth access?

A: The control that breaks is delegated trust.

Q: Why do shadow AI incidents drive breach costs higher for organisations?

A: Shadow AI increases breach cost because it often handles sensitive personal and intellectual property data outside approved controls.

Q: Where do standard IAM controls fail in a Shadow AI breach?

A: They fail at the boundary where a legitimate login turns into delegated app access.

Practitioner guidance

  • Inventory unapproved AI integrations Identify every AI tool connected through work accounts, browser extensions, and SaaS consent flows, then classify whether each one has an owner, contract, and approved business purpose.
  • Review OAuth grants by scope and tenant Pull the current OAuth app inventory, sort by delegated permissions, and flag any app that can read mail, files, tokens, or environment data without explicit business approval.
  • Revoke tokens after third-party compromise Add consent revocation to incident response so that a compromised vendor endpoint cannot keep using a still-valid OAuth token while containment is in progress.

Bottom line: Shadow AI creates a blind spot when employee-approved integrations receive enterprise access without IT review or contract control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Shadow AI is a governance problem before it is a technology problem. The Vercel case shows that an unapproved AI tool can enter the environment through ordinary employee behaviour and still create enterprise-grade identity risk. Traditional SaaS governance assumes approved software, known contracts, and visible owners, but shadow integrations bypass all three. The practitioner conclusion is simple: if the tool is invisible, its permissions are unmanaged.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
  • Organisations with high levels of shadow AI faced an average of $670,000 in additional breach costs compared with those with little or none, according to IBM's 2025 Cost of a Data Breach Report.

A question worth separating out:

Q: Should organisations manage OAuth consent like privileged access?

A: Yes. High-risk OAuth permissions can expose mail, files, and tenant resources, so they should be handled with the same care as elevated access. That means limiting who can approve, tracking every grant, and reviewing the access lifecycle instead of treating consent as a one-time user choice.

👉 Read our full editorial: Vercel breach shows shadow AI is a governance blind spot


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.