TL;DR: C1 says shadow AI discovery can identify unauthorized AI agents, MCP servers, and exposed credentials across cloud and endpoint surfaces, then route them into existing identity governance workflows. IBM’s 2025 breach data cited in the post shows one in five organisations reported a shadow AI breach and 97% lacked proper AI access controls; the governance gap is lifecycle, not detection.
NHIMG editorial — what this means for AI and NHI governance
By the numbers:
- 97% lacked proper AI access controls., breach due to shadow AI, and among those breached through an AI model or application, 97% lacked proper AI access controls.
- Only 18% of MCP server deployments implement any form of access scoping for tool permissions.
- 53% of MCP servers expose credentials through hard-coded values in configuration files.
Questions worth separating out
Q: How should security teams govern shadow AI without relying on discovery alone?
A: Security teams should use discovery as the starting point, then combine it with runtime identity telemetry.
Q: Why do AI agents complicate traditional IAM controls?
A: AI agents complicate traditional IAM controls because they do not behave like human users with short, predictable sessions.
Q: What do organisations get wrong about shadow AI governance?
A: They often try to block unsanctioned tools at the network layer without changing employee behaviour or providing an approved alternative.
Practitioner guidance
- Create a unified inventory for AI-adjacent identities Correlate cloud-discovered agents, MCP servers, service accounts, and endpoint tokens into one ownership model so every finding can be tied to a business owner and control state.
- Route discovered agents into identity lifecycle workflows Require request, approval, certification, and de-provisioning for discovered AI identities and secrets so alerts become governed access items instead of leftover findings.
- Flag hard-coded secrets and over-permissioned accounts at discovery time Prioritise plaintext tokens in local config files and service accounts with broad tool reach, then assign remediation based on reachable systems rather than volume alone.
What's in the full announcement
ConductorOne's full product announcement covers the operational detail this post intentionally leaves for the source:
- How the cloud connectors map unowned agents, MCP servers, APIs, and data stores into the platform.
- How endpoint scanning identifies local MCP configs, unsanctioned copilots, and plaintext tokens in .env files.
- How discovered AI identities move through assignment, approval, certification, and de-provisioning workflows.
- How the platform logs review and access actions for audit evidence and operational tracking.
👉 Read ConductorOne's announcement on shadow AI discovery for AI agents and MCP servers →
Shadow AI discovery and MCP visibility: are your controls keeping up?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Shadow AI discovery only works when discovery and governance are joined. The core problem is not blind spots alone, but the fact that AI agents, MCP servers, and exposed secrets become security objects only after someone can own and certify them. Detection without lifecycle control leaves the access path untouched. Practitioners should treat discovery as the front end of governance, not the end of the control story.
A few things that frame the scale:
- 53% of organisations reported lacking complete visibility into non-human identities across cloud and SaaS environments, according to Ultimate Guide to NHIs.
- 43% of organisations still manage service account credentials manually, which leaves rotation and offboarding exposed to human delay, according to Top 10 NHI Issues.
A question worth separating out:
Q: What frameworks matter for runtime AI governance and identity-linked access?
A: The most relevant references are the NIST AI Risk Management Framework, NIST AI 600-1, NIST Cybersecurity Framework 2.0, and where credentials or delegated access are involved, NHI lifecycle guidance. Together they support governance, monitoring, and accountability across AI systems that depend on identities and data access.
👉 Read our full editorial: Shadow AI discovery reframes NHI governance for agentic enterprises