Enterprise AI

AI is creating an enterprise identity crisis

By Uri Haramati, CEO, Torii

Most of the software running inside your business was never approved. According to Torii’s 2026 SaaS Benchmark Annual Report, 61.3% of applications now qualify as shadow IT: connected, active, and operating entirely outside formal oversight. And the fastest-moving part of that shadow estate isn’t typical SaaS. More than half of the top shadow IT apps in 2025 were pure-play AI. Tools that acquire identities and access paths into core systems the moment an employee clicks “Allow.” None of this is the result of a rogue decision. It’s the byproduct of normal adoption happening faster than anyone can track. By 2027, 74% of organizations surveyed expect to be using AI agents at least moderately, according to Deloitte’s 2026 State of AI in the Enterprise report. Yet 80% admit their agentic AI governance capabilities remain immature. Adoption is running ahead of the controls meant to manage it. 

Companies have spent years building governance programs around human users, but those models were not designed for non-human actors that can access data and operate on behalf of employees. 

For IAM and IT directors managing SaaS sprawl, the gap is no longer theoretical. It’s showing up in audit risk, access review backlogs, and tools no one officially owns. Policies can shape how employees use AI, but they do little to address the growing web of permissions and identities beneath that usage. 

If security teams can’t identify every AI tool, agent, and access path operating across the business, they’re making decisions based on an incomplete picture that’s becoming increasingly harder to reconstruct. 

The identities governance is missing 

Non-human identities, or NHIs, aren’t new. Service accounts, API keys, and machine credentials have operated inside enterprise systems for years; often with the same weaknesses we now worry about: unclear ownership, light oversight, access controls without an end date. But what AI changes is their autonomy. A service account executes a narrow, predictable task. An AI agentcan interpret context, make decisions, and act across multiple systems on a user’s behalf. So when ownership and oversight are missing, the failure mode is no longer disuse; it’s an autonomous actor who can reach further and unfold faster than periodic governance can ever catch.  

Risk is created the moment access is granted, and compounded the moment the identity begins to act. A marketing team connects an AI tool to customer data. A sales representative authorizes a copilot to analyze pipeline activity. A SaaS owner approves a new integration without realizing it inherits broad delegated access. Every authorization introduces a new set of permissions that must be tracked, reviewed, and eventually revoked. 

That visibility rarely keeps pace. Security teams may know which employees can access Salesforce or Google Workspace, but they often have far less visibility into which AI tools have been granted access to those same environments.  

At modern SaaS scale, the problem only deepens. As employees experiment with new AI tools, organizations are being asked to govern identities and permissions they may not even know exist. 

Traditional governance models weren’t built for the scale and speed of AI. Quarterly access reviews made sense when software changed slowly, and systems were centrally managed, but an autonomous tool can act thousands of times between two scheduled reviews.  Today, risk can emerge as soon as a new tool is connected or a project ends without access being revoked. 

The longer organizations treat AI adoption and identity governance as separate conversations, the wider the visibility gap grows. Closing it requires rethinking governance for a world where non-human identities, or NHIs, are becoming a permanent and growing part of the workforce.  

Three ways to build identity governance into AI adoption  

AI adoption is outpacing organizations’ governance models. To keep up, identity governance must be part of the adoption process from the outset, not introduced after the fact. Three priorities can help organizations build that foundation. 

1. Start with complete discovery 

Organizations can’t govern what they can’t see. Before assessing risk or reviewing access, they need a complete view of the AI tools, OAuth connections, and NHIs operating across the business. 

Discovery should answer a simple set of questions: Which AI tools are in use? Which systems are connected? Which NHIs are interacting with enterprise systems and data? Without that baseline understanding, organizations have no reliable way to determine where governance efforts should be focused. 

This level of visibility matters because AI adoption extends beyond formal procurement and approval processes. Employees regularly test new tools and connect them to business systems, creating access paths that may never pass through traditional governance checkpoints. Effective discovery helps identify those connections before they become long-term governance blind spots. 

2. Establish context and ownership 

The next step is understanding why each AI tool exists and who is responsible for governing its access. 

Every AI agent and workflow should have an accountable stakeholder responsible for periodically validating its purpose, access, and continued business value. Clear ownership helps ensure permissions evolve alongside business needs rather than lingering after a project or workflow ends. 

As AI usage expands across the business, this accountability helps ensure access remains aligned with a legitimate business need. 

3. Move toward continuous governance 

Periodic review cycles were not built for AI adoption. When permissions can be granted in seconds and integrations can appear overnight, the access landscape may change long before it’s time for the next quarterly review.  

Instead of relying solely on fixed checkpoints, organizations should build governance into the day-to-day management of access. Reviews should be triggered by meaningful changes: a tool requests new permissions, usage patterns shift, activity looks unusual, or business needs change. 

Technology can support continuous governance, but only when organizations have visibility into what tools exist and the teams responsible for them.  

Governance built for a new class of identities 

AI agents have moved quickly from pilots to real-world implementation. Now, the question is whether organizations can track the identities, permissions, and access paths AI creates along the way. 

AI governance must extend beyond acceptable-use policies and into the access layer itself. Organizations need to understand what tools have access to critical systems, why that access exists, and when it should be removed. 

A practical Monday morning step is to inventory every OAuth connection, assign a named owner to each NHI, and flag any access that hasn’t been reviewed since the connection was approved. 

Visibility creates understanding. Understanding provides context. Context creates accountability. Together, they provide the foundation organizations need to keep pace with AI’s growing identity footprint.  

Author

Related Articles

Back to top button