TL;DR: IBM and the Ponemon Institute’s 2025 Cost of a Data Breach report, cited by Vorlon, shows that 97% of organisations with an AI-related security incident lacked proper AI access controls, while 63% still had no formal AI governance framework, underscoring how quickly AI adoption is outrunning identity oversight. The governance gap is now an access-control problem, not a future policy exercise.
NHIMG editorial — based on content published by Vorlon: IBM's 2025 Cost of a Data Breach findings on the AI governance gap
By the numbers:
- 97% of organisations with an AI-related security incident lacked proper AI access controls.
- 63% of breached organisations either do not have AI governance policies or are still developing them.
- 20% of organisations suffered a breach due to shadow AI, unsanctioned AI tools used without approval or oversight.
Questions worth separating out
Q: What breaks when AI tools are allowed broad write access to internal systems?
A: Broad write access turns an AI tool from a helper into an unreviewed operator.
Q: Should organisations prioritise AI data governance before scaling AI adoption?
A: Yes. Organisations that scale AI before establishing discovery, classification, monitoring, and policy enforcement are effectively expanding the attack surface faster than they can govern it. AI adoption should be matched with controls that follow the data lifecycle, otherwise compliance, exposure, and misuse risks compound as usage grows.
Q: How should security teams discover shadow AI agents in the enterprise?
A: Use endpoint artefacts first.
Practitioner guidance
- Map AI-connected identities into the existing identity inventory Include copilots, AI agents, API tokens, service accounts, and plug-ins in the same inventory used for human and machine identities.
- Enforce least privilege on every AI integration Scope OAuth grants, API keys, and delegated permissions to the minimum data and action set required.
- Continuously discover shadow AI and revoke risky connections Monitor SaaS-to-AI connections for unsanctioned tools, unexpected data flows, and privilege inheritance from legitimate applications.
What's in the full article
Vorlon's full post covers the operational detail this post intentionally leaves for the source:
- Detailed breakdown of how the platform maps SaaS-to-AI access paths and token relationships across connected tools
- Examples of automated revocation workflows for risky permissions and unsanctioned AI integrations
- Integration details for SIEM, SOAR, and ITSM workflows that operational teams can use during containment
- Data-flow mapping examples that show how customer PII and intellectual property move through AI-connected environments
👉 Read Vorlon’s analysis of IBM’s 2025 AI breach findings and governance gap →
AI governance gap: what IBM’s breach data means for IAM teams?
Explore further
AI governance gaps are now identity governance gaps. IBM’s data shows that the majority of AI-related incidents are not exotic model failures but missing access controls and immature governance. That means the control problem sits in IAM, IGA, and NHI management rather than in AI strategy alone. Practitioners should stop treating AI governance as a parallel programme and start treating it as part of the identity estate.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly one identity failure can repeat across systems.
A question worth separating out:
Q: What is the difference between managing human IAM and AI tool access?
A: Human IAM assumes a person authenticates, requests access, and then uses it within known working patterns. AI tool access is different because the tool can move data and act across systems at machine speed, often through delegated credentials. The governance model must therefore focus more on scope, lifecycle, and behavioural monitoring than on login experience.
👉 Read our full editorial: IBM breach findings expose the AI governance gap in enterprise IAM