TL;DR: Shadow AI is creating invisible AI tools, agents, MCP servers, and exposed credentials across endpoints and cloud identity estates, while IBM reports that one in five organisations has already had a breach tied to shadow AI and 97% of those breached lacked proper AI access controls. The governance gap is not discovery alone, but ownership, lifecycle control, and auditability for non-human identities.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- 97% lacked proper AI access controls., breach due to shadow AI, and among those breached through an AI model or application, 97% lacked proper AI access controls.
Questions worth separating out
Q: How should security teams govern shadow AI without relying on discovery alone?
A: Security teams should use discovery as the starting point, then combine it with runtime identity telemetry.
Q: Why do shadow AI tools complicate IAM governance?
A: Shadow AI tools complicate IAM because they can hold real privileges without appearing in normal inventory or review processes.
Q: What breaks when an AI agent is not part of identity inventory?
A: When an AI agent is not part of identity inventory, governance breaks at the point of discovery.
Practitioner guidance
- Inventory endpoint-installed AI tools and local MCP servers Scan developer laptops and workstations for locally installed coding assistants, MCP declarations, and credential files written to disk.
- Assign ownership to every discovered AI identity Create a workflow that requires an owner for every agent, token, service principal, managed identity, or integration discovered in cloud and identity platforms.
- Route shadow AI into existing lifecycle controls Bring discovered AI identities through request, approval, certification, and de-provisioning using the same lifecycle process used for other NHIs.
What's in the full announcement
ConductorOne's full blog covers the operational detail this post intentionally leaves for the source:
- The endpoint scanning logic used to identify installed AI tools, local MCP servers, and credential artefacts
- The cloud and identity provider connectors used to enumerate agents, service principals, app registrations, and managed identities
- The ownership, approval, and certification workflow that turns discovery into governed access items
- The credential handling flow that moves exposed secrets into governed storage and strips plaintext from config files
👉 Read ConductorOne's blog on shadow AI discovery and agentic identity governance →
Shadow AI discovery and agentic identity: what teams are missing?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Shadow AI discovery is not an AI visibility feature, it is an identity inventory control. The central problem is not whether a model exists somewhere in the estate, but whether the AI tool, agent, MCP server, or credential can be assigned an accountable owner and brought under lifecycle governance. Without that, security teams discover activity but cannot govern it. The practitioner conclusion is that discovery only matters when it feeds ownership, review, and de-provisioning.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how often identity inventory still lags governance reality.
A question worth separating out:
Q: Who should be accountable for AI identity governance?
A: Accountability should sit with the team that owns the workflow and the team that owns identity controls, because AI access crosses both domains. Security, platform, and application owners each hold part of the lifecycle, but one business owner must remain responsible for the access decision and its removal.
👉 Read our full editorial: Shadow AI discovery exposes the governance gap in agentic identity