Executive Summary
The evidence supports a focused conclusion: shadow AI and SaaS sprawl are governance problems before they become tooling problems. Organizations need to know which external services and AI systems are in use, who is accountable for them, what data and enterprise access they can reach, which supplier and configuration requirements apply, and how an approval decision becomes an enforceable control.
This report synthesizes public guidance and current standards activity from NIST and MITRE. It does not assert a universal rate of shadow AI adoption, SaaS application count, loss event, productivity gain, or return on investment. Vendor telemetry is deliberately excluded from the core evidence base so the report can focus on governance principles that remain valid across different enterprise environments. CyberTech Intelligence converts the evidence into a service-lifecycle operating model and readiness score for leadership use.
Research Methodology and Source Selection
This report is a secondary-research synthesis and CyberTech Intelligence operating-model analysis. Sources were selected for authority, direct relevance to cybersecurity or AI governance, current publication or update status, accessible methodology or standards context, and practical applicability to external services, AI systems, identity, assurance, and supply-chain risk. Government and standards-body sources were preferred. Independent assurance research was used where it adds cross-framework context. Claims were kept within each source's stated scope.
Evidence Universe and Assumptions
The evidence universe includes NIST Cybersecurity Framework resources, NIST cybersecurity supply-chain guidance, NIST AI and AI-agent initiatives, NIST generative-AI guidance, and MITRE AI assurance research available as of September 21, 2026. "Shadow AI" is treated as organizational use of AI services, models, agents, or AI-enabled capabilities that are not fully visible to or governed by the organization's approved process. "SaaS sprawl" is treated as growth or fragmentation in external software services that makes inventory, ownership, access, configuration, cost, data, and lifecycle governance harder. Neither term is used to imply that all unsanctioned use is malicious or that all large SaaS portfolios are poorly governed.
Evidence Grading
Table 1. Evidence Grading and Permitted Use
|
Grade |
Source Standard |
Permitted Use |
|---|---|---|
|
A |
Government or standards-body primary guidance and publications. |
Control principles, definitions, governance outcomes and public program direction. |
|
B |
Recognized independent research with transparent scope. |
Assurance concepts, cross-framework synthesis and decision support. |
|
C |
Vendor technical documentation or dataset. |
Only the vendor's stated capability, design or observed dataset. Not used in the core research findings. |
|
D |
CyberTech Intelligence synthesis derived from cited evidence. |
Operating models, readiness tools and leadership questions, clearly labeled as CTI analysis. |
Research Limitations
Public guidance does not provide a single enterprise-wide benchmark for the acceptable number of SaaS applications, the prevalence of shadow AI, the correct percentage of blocked services, or the revenue value of a governance program. AI and SaaS environments also differ materially by industry, data sensitivity, architecture, geography, workforce model, and supplier mix. The research therefore does not convert public guidance into universal numeric thresholds. Organizations should establish local baselines and test whether controls are effective in their own environment.
Key Terminology Distinctions
Table 2. Key Terms
|
Term |
Meaning in This Report |
|---|---|
|
Shadow AI |
AI service, model, agent or AI-enabled capability used without complete visibility, approval or governance through the organization's defined process. |
|
SaaS sprawl |
Growth or fragmentation in external software services that makes governance of ownership, access, configuration, data, cost and lifecycle more difficult. |
|
Sanctioned service |
A service approved for stated use under documented conditions and ownership. |
|
Unsanctioned service |
A service not approved for the observed use. This is a governance status, not by itself a technical risk rating. |
|
Business owner |
Person accountable for the service purpose, users, business need and lifecycle decision. |
|
Technical owner |
Person accountable for identity, configuration, integration, monitoring and technical closure. |
|
Policy enforcement |
Translation of a use decision into practical access, data, configuration, warning, approval, restriction or blocking controls. |
|
Readiness score |
Internal CTI assessment aid; not a certification, external rating, audit or forecast. |
Research Framework
Findings are organized through the CyberTech Intelligence Shadow AI & SaaS Governance Framework: Discover, Classify, Own, Approve, Constrain, Observe, Retire, and Measure. The framework is a CTI operating synthesis. It maps recurring evidence themes to the decisions a leadership team must make across the service lifecycle.
Executive Findings
-
Cybersecurity frameworks treat inventories of assets, software, supplier relationships, and services as foundational inputs to risk management rather than optional administrative records. [1] [2]
-
AI governance is moving toward stronger inventory, documentation, testing, evaluation, identity, authorization, and transparency expectations. [3] [4] [5] [6] [8]
-
Supplier and service governance must extend beyond a procurement event because permissions, integrations, configuration, ownership, and use change over time.
-
AI and SaaS governance can share one operating control plane because both depend on service discovery, identity, data boundaries, supplier requirements, ownership, monitoring, and lifecycle decisions.
-
Delegated access and software-agent authority make identity and authorization part of the service inventory, not a separate technical appendix. [4] [5]
-
Policy is operational only when an approval or restriction can be traced to an enforceable control and an evidence record.
Inventory Is the Starting Point, Not the End
NIST CSF 2.0 is designed around cybersecurity outcomes that organizations can use to manage and reduce risk. Its resource and overview guidance emphasizes the use of CSF outcomes as a common structure rather than a fixed implementation recipe. [1] For shadow AI and SaaS sprawl, the asset-management lesson is that a service register should support decisions, not simply list names.
An effective inventory should connect service identity with business purpose, owner, user population, data, integrations, approval state, review date, and retirement status. A raw discovery list may be large and noisy. Governance improves when the list is progressively enriched and each service is routed toward a decision: sanction, sanction with conditions, restrict, replace, block, or retire.
Ownership Must Be Explicit
Cybersecurity governance fails when responsibility is implied. NIST C-SCRM guidance provides a structured approach to strategy, policies, plans, risk assessments, and supplier-related risk management. [2] Those mechanisms depend on accountable roles. For an external service, ownership should cover both business outcome and technical control because neither side can fully govern the lifecycle alone.
The service record should name who can approve a new use, who reviews data conditions, who manages privileged and non-human access, who evaluates supplier change, and who authorizes retirement. If the owner leaves or responsibility moves, the governance system should detect and correct the orphaned record.
AI and SaaS Need a Shared Control Plane
NIST's 2026 presentation on AI supply-chain transparency describes a GUARD sequence that begins with governance structure for inventory, responsibilities, policy, compliance, and impact assessment, then moves through understanding, adaptation of existing practices, impact reduction, and demonstration of control effectiveness. [3] This is especially relevant to shadow AI because it places inventory and responsibility inside the same lifecycle as policy and control evidence.
The shared control plane does not require one product. It requires one operating record and decision vocabulary. A team should be able to look at an external SaaS platform, a generative-AI application, or an AI agent connection and ask the same first questions: What is it? Who owns it? Which data and systems can it reach? What authority does it have? Which policy applies? How is the decision enforced and reviewed?
Third-Party Services Extend the Risk Boundary
Supply-chain risk management is relevant because the enterprise depends on capabilities, components, and services it does not fully control. NIST SP 800-161 Rev. 1 provides guidance for identifying, assessing, and mitigating cybersecurity risks throughout the supply chain and integrating C-SCRM with enterprise risk management. [2] A SaaS or AI approval should therefore include both supplier assurance and customer-side control requirements.
That distinction is important. A supplier can have mature internal security and still expose customer-configurable identity, logging, data, or integration choices. Conversely, a customer can configure a service carefully and still depend on supplier practices it cannot directly manage. Governance needs evidence for both sides of the responsibility boundary.
Identity and Permissions Must Be Visible
NIST's AI Agent Standards Initiative identifies security and identity as active areas for standards development, while the NCCoE concept paper on software and AI-agent identity highlights identification, authorization, auditing, non-repudiation, and controls for prompt-injection-related risk. [4] [5] These efforts are current standards activity, not a finalized enterprise standard. They nonetheless reinforce a direction that matters for SaaS and AI governance: software actors and integrations need visible identity and authority.
For a service inventory, this means recording more than human users. High-impact OAuth applications, API clients, service accounts, agent identities, automation credentials, and privileged roles should be within scope where they can access sensitive enterprise resources or take actions on behalf of users.
Policy Enforcement Must Produce Evidence
NIST's ITL AI Program emphasizes testing, evaluation, verification and validation as a core area for trustworthy AI, while the Generative AI Profile provides a cross-sector resource for incorporating trustworthiness considerations into AI design, development, use and evaluation. [6] [8] MITRE's AI Assurance Landscape similarly argues that AI assurance spans multiple categories and lacks one standardized approach. [7]
For shadow AI and SaaS sprawl, assurance should be practical. The organization should be able to show that a use decision resulted in an implemented control, that the control can be observed, and that exceptions and changes are routed back to an owner. The evidence record can include sanctioning state, group membership, data policy, OAuth scope, configuration baseline, user warning, block event, exception approval, review date, and retirement confirmation. The specific evidence will vary by service and risk.
Board-Level Evidence and Decision Metrics
-
Visibility: percentage of observed AI and SaaS services represented in the governed inventory; coverage by discovery source.
-
Ownership: percentage of governed services with current business and technical owners; count and age of orphaned services.
-
Decision speed: median time from first observation or request to sanction, restriction, exception, replacement, or retirement decision.
-
Identity and integration: count of high-impact OAuth/API integrations reviewed; privileged or non-human identities without current owners.
-
Data governance: services approved for sensitive data by data class; policy exceptions and aging.
-
Control health: warning, restriction, block, and configuration exceptions; remediation closure time.
-
Lifecycle: services retired, tokens revoked, accounts closed, renewals stopped, and closure evidence completed.
-
Change: services re-reviewed after a material change in purpose, data, ownership, permissions, supplier, or functionality.
Twelve-Month Implementation Roadmap
0-90 days: establish the service register, reconcile priority discovery sources, define ownership fields, classify highest-use AI services, and create an explicit approval and exception path. 3-6 months: connect identity, data, integration, and configuration evidence to priority services; enable practical sanctioning, warning, restriction, or blocking controls; begin retirement of orphaned or duplicate services. 6-9 months: extend coverage to non-human identities and high-impact integrations; standardize supplier and customer-side control requirements; measure decision cycle time and exception aging. 9-12 months: automate recurring evidence where justified, test retirement and revocation procedures, review portfolio metrics with leadership, and expand only where measurement shows the governance model is working.
Strategic Takeaway
Shadow AI and SaaS sprawl are not solved by a single discovery feed, policy document, or blocking technology. The durable model is a service-lifecycle control system: discover what is used, classify the business and data context, assign owners, make an explicit decision, enforce the decision, observe change, retire trust cleanly, and measure whether the program is keeping pace. That operating model allows adoption to continue without requiring the organization to choose between visibility and usability.
Governance and Decision Rights
Figure 1. Governance and Decision Rights
|
Decision Stage |
Accountable Owner |
Required Evidence |
Exit Criteria |
|---|---|---|---|
|
Discovery intake |
Security / IT service governance |
Observed service, source signal, user or requester, first-seen evidence. |
Service enters governed review queue. |
|
Business classification |
Business owner |
Purpose, users, process dependency, expected duration. |
Business need recorded. |
|
Data and access review |
Security/identity / data owner |
Data classes, roles, integrations, delegated scopes, configuration. |
Use conditions and controls approved. |
|
Supplier/service review |
Third-party risk or procurement owner |
Supplier evidence, required customer controls, contract or terms where applicable. |
Supplier and customer responsibilities accepted. |
|
Policy enforcement |
Technical owner |
Sanction state, access/data controls, warnings, restrictions, exception path. |
Decision is technically enforceable. |
|
Ongoing operation |
Business and technical owners |
Usage, exceptions, changes, access review, control health. |
Thresholds met or corrective action active. |
|
Retirement |
Business owner with technical closure owner |
Account, token, integration, data, renewal and dependency closure. |
Trust and commercial lifecycle closed. |
CyberTech Intelligence Shadow AI & SaaS Governance Framework
Figure 2. Eight-Layer Research Framework
|
Layer |
Name |
Operating Requirement |
|---|---|---|
|
01 |
Discover |
Surface active services and AI capabilities from multiple evidence sources. |
|
02 |
Classify |
Record purpose, users, data sensitivity, integration and action scope. |
|
03 |
Own |
Assign accountable business and technical owners with a review date. |
|
04 |
Approve |
Set sanctioned, restricted, prohibited or exception conditions. |
|
05 |
Constrain |
Apply identity, data, permission, configuration and integration controls. |
|
06 |
Observe |
Monitor use, change, exceptions, configuration and control health. |
|
07 |
Retire |
Remove accounts, delegated trust, data obligations, dependencies and renewals. |
|
08 |
Measure |
Track coverage, decision speed, exceptions, lifecycle health and control effectiveness. |
Shadow AI & SaaS Governance Readiness Score
Rate each domain from 0 to 4: 0 = absent; 1 = informal; 2 = documented; 3 = implemented and tested; 4 = measured and continuously improved. Maximum score: 40. Readiness percentage = total score divided by 40, multiplied by 100. Suggested interpretation: Basic 0-24%; Developing 25-49%; Defined 50-69%; Managed 70-84%; Adaptive 85-100%. This is an internal CTI assessment aid, not a certification, audit, product rating, revenue forecast, or conversion prediction.
Shadow AI & SaaS Governance Readiness Score
|
Domain |
Executive Assessment Question |
Ready-State Evidence |
|---|---|---|
|
Discovery |
Can material AI and SaaS use be surfaced from multiple sources? |
Current inventory with source and last-seen evidence. |
|
Classification |
Is purpose, data, user, integration and action scope recorded? |
Completed service classification. |
|
Ownership |
Are accountable business and technical owners current? |
Named owners and next review date. |
|
Policy |
Are allowed, restricted and prohibited uses explicit? |
Approved use decision and exception route. |
|
Identity |
Are human, admin and non-human identities visible? |
Identity, role and ownership register. |
|
Integration |
Are delegated permissions and API scopes reviewed? |
Integration scope and revocation evidence. |
|
Data |
Can sensitive-data conditions be governed and evidenced? |
Data decision and control record. |
|
Monitoring |
Are material changes routed to review? |
Monitoring, alerts, review queue and closure. |
|
Retirement |
Can accounts, tokens, data obligations and renewals be closed? |
Complete retirement record. |
|
Measurement |
Are coverage, decision speed, exceptions and control health visible? |
Metrics, thresholds, trend and owner. |
Governance Maturity Model
Figure 3. CyberTech Intelligence Governance Maturity Model
|
Maturity |
Operating Pattern |
Leadership Priority |
|
|---|---|---|---|
|
Reactive |
Discovery is ad hoc; ownership and approval status are incomplete. |
Build one inventory and assign owners. |
|
|
Defined |
Service records, policy decisions, owners and review paths exist. |
Standardize data, identity and integration review. |
|
|
Controlled |
Policy decisions are enforced and material changes are monitored. |
Reduce exception aging and improve control evidence. |
|
|
Adaptive |
Controls and review frequency change based on measured risk and lifecycle evidence. |
Scale automation only where evidence supports it. |
|
Benchmark Shadow AI & SaaS Governance Readiness
Score the ten readiness domains against current evidence, not planned controls. Use the lowest-scoring domains to set the next executive review agenda, then repeat the assessment after the first 90-day remediation cycle or any material change in the service portfolio.
About CyberTech Intelligence
CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.
Research and Citation Governance
External sources are used only within their stated scope. Government and standards guidance is treated as control guidance, independent research is attributed to the publishing organization, and vendor documentation is used only for vendor-specific capabilities or observed datasets. CyberTech Intelligence does not infer that a named organization has an incident, control weakness, buying project, budget, or risk posture without direct evidence. CTI frameworks and readiness tools are editorial operating models, not certifications, audits, legal conclusions, product ratings, or forecasts. Editorial QA control completion: 10/10.
References
- National Institute of Standards and Technology, “NIST Cybersecurity Framework 2.0: Resource & Overview Guide,” February 26, 2024. https://www.nist.gov/publications/nist-cybersecurity-framework-20-resource-overview-guide (Accessed September 21, 2026. Relevance: authoritative overview of CSF 2.0 as an outcome-based framework for managing and reducing cybersecurity risk.)
- National Institute of Standards and Technology, “SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations,” final update November 1, 2024. https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final (Accessed September 21, 2026. Relevance: authoritative C-SCRM guidance for policies, plans, assessments, supplier relationships, and enterprise risk integration.)
- National Institute of Standards and Technology, “Operationalizing Transparency: Navigating the AI Supply Chain with OWASP AI Exchange and AIBOM,” May 19, 2026. https://csrc.nist.gov/presentations/2026/operationalizing-transparency-navigating-the-ai-su (Accessed September 21, 2026. Relevance: current NIST-hosted presentation describing governance, inventory, responsibility, policy, AI supply-chain understanding, control reduction, and demonstration.)
- National Institute of Standards and Technology, “Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation,” February 17, 2026. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure (Accessed September 21, 2026. Relevance: current standards initiative identifying AI-agent security and identity as research and standards priorities.)
- National Institute of Standards and Technology, “New Concept Paper on Identity and Authority of Software Agents,” February 5, 2026. https://www.nist.gov/news-events/news/2026/02/new-concept-paper-identity-and-authority-software-agents (Accessed September 21, 2026. Relevance: current NCCoE concept work on identification, authorization, auditing, non-repudiation, and secure agent adoption.)
- National Institute of Standards and Technology, “NIST Information Technology Laboratory AI Program,” updated August 14, 2026. https://www.nist.gov/artificial-intelligence/nist-information-technology-laboratory-itl-ai-program (Accessed September 21, 2026. Relevance: current NIST program direction on AI testing, evaluation, verification, validation, risk management, and standards).
- MITRE, “The AI Assurance Landscape (v1.0),” May 8, 2025. https://www.mitre.org/news-insights/publication/ai-assurance-landscape-v10 (Accessed September 21, 2026. Relevance: independent synthesis of AI assurance needs across more than 50 frameworks, used for assurance-program context.)
- National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” July 26, 2024; NIST page updated April 8, 2026. https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence (Accessed September 21, 2026. Relevance: authoritative cross-sector profile for incorporating trustworthiness considerations into generative-AI design, development, use, and evaluation.)