Surveys and spreadsheets miss the reality of local configuration and usage data on managed devices. They do not reveal which MCP servers are connected, how they map to source applications, or how much AI is being consumed across tools. That leaves security, finance, and IT working from stale self-reported data instead of evidence from the endpoint.
Why This Matters for Security Teams
Surveys and spreadsheets fail because they capture what people remember, not what devices are actually running. That matters most when AI tooling and MCP connectivity are changing outside central visibility, because local configuration, cached secrets, and per-device permissions are the real source of exposure. Security teams end up reconciling self-reported usage against endpoint evidence too late, which distorts risk, spend, and incident response priorities.
This is not a theoretical gap. NHIMG research on The 2026 Infrastructure Identity Survey shows that 67% of organisations still rely heavily on static credentials, even as agentic systems become more common. That same pattern shows up in MCP environments, where the State of MCP Server Security 2025 found hard-coded credentials and weak access scoping to be widespread. In practice, many security teams discover the gap only after an internal review, cost spike, or credential exposure has already occurred, rather than through intentional governance.
How It Works in Practice
Accurate AI and MCP governance starts with telemetry from the endpoint, workspace, or managed device, not with a quarterly survey. The core question is not just whether AI is being used, but which applications are invoking it, which MCP servers are connected, what secrets are present locally, and whether usage aligns with approved business purposes. For that reason, practitioners should treat spreadsheets as a reporting artifact, not a control plane.
Current guidance suggests combining inventory, policy, and runtime evidence. That means correlating local configuration files, browser extensions, desktop apps, agent runtimes, and MCP client settings with identity and endpoint management data. It also means using authoritative sources such as NIST SP 800-53 Rev 5 Security and Privacy Controls for control mapping, while using NHIMG research such as Ultimate Guide to NHIs - Key Research and Survey Results to understand how non-human identities and secrets actually accumulate in modern environments.
- Build an evidence-based inventory from managed endpoints, not self-attestation.
- Map each AI tool or MCP server to the source application and the identity that invokes it.
- Record whether credentials are static, ephemeral, or embedded in local configuration.
- Track consumption and access by team, device, and workflow so finance and security see the same data.
- Reconcile approved use with observed use on a recurring basis, not only at review time.
For standards alignment, the access and inventory patterns should also reflect the intent of the OWASP Agentic AI Top 10, because unmanaged tool access and hidden runtime behaviour are exactly where agentic environments drift away from policy. These controls tend to break down when AI use is decentralized across managed devices and local configuration is allowed to override central policy.
Common Variations and Edge Cases
Tighter visibility often increases administrative overhead, requiring organisations to balance faster discovery against privacy, endpoint-management maturity, and user trust. That tradeoff is real, especially when teams want per-device telemetry without creating a surveillance program.
There is no universal standard for this yet, but current best practice is evolving toward minimum necessary collection, strong data classification, and clear separation between operational telemetry and content capture. Organisations with BYOD, contractor-heavy fleets, or offline development environments may need different collection methods, because not every endpoint can be governed through the same tooling. In those cases, policy exceptions should be explicit rather than inferred from incomplete spreadsheets.
This is also where AI and MCP visibility diverge from classic software inventory. An application list can look complete while hidden local connectors, token caches, or unapproved MCP servers remain active. That is why the strongest programs pair endpoint evidence with risk-oriented reviews of AI usage, rather than asking staff to remember what they installed last month. The gap is especially pronounced in fast-moving engineering teams, where tools are added faster than central registers are updated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A1 | Hidden tool use and unmanaged agent behaviour create the core risk here. |
| CSA MAESTRO | GOV-1 | Governance requires evidence-based visibility into agent and MCP usage. |
| NIST AI RMF | GOVERN | AI governance depends on trustworthy inventory and accountability data. |
| NIST CSF 2.0 | ID.AM-01 | Asset management fails when AI tools and MCP endpoints are not inventoried. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Local secrets and hidden connectors are NHI exposures that surveys miss. |
Maintain an evidence-based asset inventory covering AI tools, connectors, and endpoints.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org