Join our Newsletter — 33% off our NHI Course

Shadow AI governance gap: are your controls watching behavior?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Discovery tools can find installed AI software, but they miss what identities are doing, which is how a Fortune 50 media breach led to 1.1TB stolen, including 44 million chat messages, over five months undetected, according to Abnormal AI. Behaviour-based governance now matters more than inventory because sanctioned or unsanctioned identities can both become high-risk access paths.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Shadow AI Isn't a Governance Problem Alone”.

By the numbers:

  • In 2025, public code repositories absorbed 1.27 million hardcoded AI-service credentials, one every 25 seconds all year.
  • A Fortune 50 media breach led to 1.1TB stolen, including 44 million chat messages, over five months undetected.

Key questions

Q: Why do AI governance tools need shadow AI discovery?

A: Because policy cannot control what it cannot see.

Q: Why do personal AI accounts create more risk than sanctioned ones?

A: Personal AI accounts weaken governance because they sit outside organisational control for MFA, retention, monitoring, and revocation.

Q: How can security teams tell whether AI access is behaving like an account takeover?

A: Look for identity behaviour that diverges from the historical baseline, especially unfamiliar system access, unusual timing, and unexpected data movement.

Practitioner guidance

  • Shift from discovery to behavioural governance Baseline normal access timing, target systems, and data movement for accounts that use AI tools, then flag deviations from those patterns.
  • Scan and rotate exposed AI credentials Search repositories, code snippets, and configuration stores for hardcoded AI-service secrets, then revoke and rotate anything exposed.
  • Separate sanctioned use from shadow use Classify AI access by identity behaviour, not just tool approval, so an approved app with unsafe activity is not treated as low risk.

Bottom line: Shadow AI becomes dangerous when identity behaviour is invisible, not when a tool simply appears in inventory.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Shadow AI governance fails when it is reduced to asset discovery: inventory tells you what is installed, but not whether identities are behaving in risky ways. That is a structural blind spot, not a tuning problem. Governance needs to shift from static presence checks to behavioural control of access paths, especially where AI tooling sits between the user and the data.

A few things that frame the scale:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: Should organisations prioritise credential lifecycle controls or behavioural monitoring for AI use?

A: They need both, but the sequence depends on exposure. If hardcoded or shared credentials are already present, secret scanning and rotation come first because they remove replayable access. Behavioural monitoring then becomes the ongoing control that shows whether approved access is being used safely.

👉 Read our full editorial: Shadow AI governance fails when identity behavior is invisible


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.