The first sign is that you cannot reliably inventory production agents and describe what they touched in operational terms. If the organisation knows AI exists but cannot trace ownership, scope, and recent activity in a single view, it is still managing discovery rather than governance.
What the first sign really tells you
The first sign is not simply that AI exists somewhere in the business. It is that production agents are still not visible as managed operational entities, so the organisation cannot answer basic questions about ownership, scope, and recent activity without manual reconstruction. At that point, AI is being discovered, not governed, and the control problem is still inventory plus attribution.
This is why shadow ai and tracked AI often look mature at a distance but fail up close. A spreadsheet of tools, a list of approved pilots, or a monitoring dashboard can create false confidence if it does not show which agent acted, under whose authority, in which environment, and against which business process.
The operational clue is that governance cannot yet connect the agent to the work it touched. If the team can name a model or app but cannot trace what it accessed, what outputs it generated, or what downstream system it influenced, the programme has not crossed from discovery into accountable control.
How shadow and tracked AI differ in practice
Shadow AI is typically the earlier state: unsanctioned or partially visible use that may sit outside formal procurement, security review, or ownership. Tracked AI is a step forward, but it can still be shallow if the organisation only records that something exists, rather than whether it is controlled, attributed, and measurable in operation.
The difference matters because tracked AI can still behave like shadow AI from a governance standpoint. If onboarding only captures a name, vendor, and business sponsor, but not runtime permissions, data reach, and recent actions, the control surface is incomplete. That is why inventory quality is more important than inventory volume.
A practical test is whether the same record answers both governance and operations questions. Good governance inventory should let you see the agent's owner, approved purpose, connected tools, and current status. It should also let you identify whether the agent has drifted, whether it is still used, and whether its activity matches the approved use case.
What counts as a real governance signal
The meaningful signal is not the presence of an AI register by itself. It is whether the organisation can reconcile approved intent with observed activity in one place, without depending on tribal knowledge or ad hoc hunting across logs, tickets, and SaaS consoles.
That means the inventory must be operationally actionable. It should support ownership assignment, scope review, lifecycle decisions, and incident response. If a team cannot quickly tell whether a production agent is still active, what systems it reached, or whether it has a current owner, the programme is still in an immature tracking phase.
This is also the point at which governance becomes cross-functional. Security may validate access and telemetry, but product, platform, and business owners have to supply the context that explains why the agent exists and what good use looks like. Without that shared view, AI oversight remains fragmented.
Risk and Threat Considerations
Shadow or weakly tracked AI creates hidden access paths, hidden data flows, and hidden decision influence. The main risk is not just noncompliance, it is that an unmanaged agent can keep acting after its purpose has expired, its permissions have widened, or its owner has lost visibility.
Failure mechanism: The organisation records the existence of AI but cannot continuously map agent identity, authority, connected tools, and activity back to a current owner and approved use case. That gap allows unreviewed data access, stale permissions, and unaccountable automation to persist.
Impact: Teams lose containment over where AI can act, what it can read, and how quickly they can respond when behavior changes. In practice, that raises the likelihood of data exposure, policy drift, and delayed incident response because nobody can confidently say what the agent touched.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST AI RMF, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | Govern | AI governance requires inventory, accountability, and continuous oversight of AI systems. |
| Recommendation — Establish governance records that tie each AI system to ownership, scope, and monitored activity. | ||
| ISO/IEC 42001:2023 | 4.4 — AI management system | An AI management system formalises ownership, accountability, and control over AI use. |
| Recommendation — Create an AI management system that keeps production agents inventoried and accountable. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | The question centres on inventory visibility as the first governance signal. |
| Recommendation — Maintain an authoritative inventory of AI systems and update it as usage changes. | ||
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | Shadow and tracked AI are primarily inventory and visibility failures. |
| Recommendation — Inventory all AI assets, owners, and environments before claiming governance. | ||
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | A governed AI estate needs a current inventory of components and their status. |
| Recommendation — Keep a current inventory of AI components, owners, and operational status. | ||
Practitioner Guidance
What to verify: A credible governance state requires more than a register of tools. Verify that every production agent has a named owner, a defined business purpose, an environment classification, and an auditable record of recent activity that can be reviewed without manual reconstruction.
Decision rule: If you can only describe an agent in procurement terms, treat it as tracked but not governed. If you can describe its owner, scope, connected systems, and recent actions in operational terms, you have moved into actual governance and can start measuring drift and exception handling.
What practitioners underestimate: The hardest part is usually not finding the AI, it is proving that what was approved is still what is happening. The first governance milestone is therefore not policy language, but a living inventory that ties authority to observable use.
Practitioner takeaway: The moment you cannot explain a production agent's ownership, scope, and recent activity in one view, you are still doing discovery work, not governance.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org