AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-06-19

AI Adoption Research from Nudge Security Reveals How Widespread AI Use Is Transforming Security Governance

What happened

Nudge Security published AI adoption research in June 2026 documenting the scale and composition of enterprise AI tool use across its customer base. The research finds that AI agents, integrations, and AI-native development platforms are now embedded in standard enterprise workflows at a scale that outpaces governance controls designed for traditional SaaS procurement. OpenAI and Anthropic remain the dominant providers by integration volume. Emerging agent tools including Manus and Lindy are entering enterprise environments through individual contributor adoption rather than IT procurement channels. The report identifies data egress as the primary governance gap: enterprise data is leaving controlled environments through prompts, file uploads, and OAuth-connected integrations, in ways that existing data loss prevention and vendor risk controls were not designed to detect or restrict.

Why it matters

  • ·AI tool adoption is now primarily bottom-up. Security and compliance teams are building governance programs retroactively against a deployment baseline that already exists, not establishing controls before adoption begins.
  • ·Agent tools like Manus and Lindy that accept OAuth connections to enterprise systems create data exposure pathways that bypass traditional perimeter controls. Once connected, an agent can pull, process, and retain data outside approved data boundaries with no visibility to security teams.
  • ·Prompt and file upload egress channels are invisible to most DLP systems tuned for email and file transfers. Organizations that believe they have comprehensive data loss controls may have uncovered exposure in AI interactions.
  • ·Third-party AI vendor risk assessments focused on contract terms miss the operational risk from connected integrations and persistent data retention in provider systems, meaning PRC controls need to extend to OAuth-granted agent access.

Governance controls affected

What to do now

  • Deploy an AI tool inventory mechanism capable of discovering OAuth-connected AI applications and agents, not just approved vendors in the procurement system.
  • Extend data loss prevention policy scope to cover AI prompt and file upload channels, and test detection coverage against representative prompt-based data extraction scenarios.
  • Classify AI agents and integrations with OAuth access to production systems as third-party risk assets and apply vendor risk assessment procedures (PRC-001) to them.
  • Update acceptable-use policy to require that AI tool connections to enterprise systems go through a lightweight approval workflow, even for individual contributor tools.
  • Audit currently connected AI applications for scope of OAuth access granted and revoke permissions that exceed the documented use case.

What to watch next

Nudge Security's ongoing visibility into enterprise AI tool adoption positions them to release periodic benchmarks as agent adoption accelerates. Watch for follow-on research on agent credential patterns and OAuth scope accumulation, which will likely surface as the next major enterprise governance challenge as agentic AI deployments scale.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Insight2026-07-16

Agentic Developer Tools Are the New Shadow IT, With a Larger Blast Radius

The Grok Build incident is not a data breach story. It is a category error story: organizations are applying shadow IT controls to a class of tools that bypasses those controls by design. Agentic coding assistants have codebase-level access, transmit code as part of their core function, and expose data in proportion to the developer's own privileges. The governance frameworks built for unauthorized SaaS subscriptions are not built for this.

Corporate Policy2026-07-29

ChatGPT Work Brings Agentic Workplace Automation to Enterprise, Exposing Access Control and Audit Gaps

OpenAI has launched ChatGPT Work, an agentic product designed to execute tasks autonomously across enterprise applications and files. The release extends AI activity beyond the chat interface into operational systems, creating direct exposure across access control, least-privilege enforcement, human oversight, and audit logging programs. Compliance teams at organizations considering or already piloting the product need to assess their agentic governance readiness before deployment proceeds.

Corporate Policy2026-07-28

Hush Security's $30M Series A Puts NHI Credential Governance and Agent Registries on the Enterprise Compliance Agenda

Tel Aviv-based Hush Security has closed a $30 million Series A round, bringing total funding to $41 million, to expand its machine access platform for AI agent governance. The platform registers AI agents in a central registry, enforces just-in-time scoped permissions at runtime, and maintains a full audit trail for each agent interaction. The raise signals growing market pressure on enterprise compliance teams to implement formal non-human identity controls as agentic deployments scale.