October 2, 2026

What to Monitor for AI Governance

Enterprise security
Artificial Intelligence/ AI

Shadow AI, tenants, extensions, prompts, agent actions, exceptions, and spend.

Island blog hero image for What to Monitor for AI Governance

Key takeaways

  • Shadow AI is now the default state: 98% of organizations have employees using unsanctioned AI tools, and 47% access AI through personal or unmanaged accounts.
  • Prompt content and file movement matter more than tool lists. A KPMG survey found 48% of employees admit to uploading sensitive data into AI tools.
  • Agent actions need chain-level visibility. A single agent can touch a file, call an API, and move data to an external domain, and most tools only see one or two steps in that sequence.
  • Exception requests are a governance signal. We found that 93% of prompts sent to a human reviewer get approved, a rate that makes the review step function mostly as a formality.
  • Spend tracking belongs in the same monitoring plan as usage. A McKinsey survey found 93% of respondents have exceeded their AI budgets.

Introduction

Most security and IT teams already know employees use AI at work. What they lack is a clear view of where that use happens, what data moves through it, and what autonomous agents do once they're connected to real systems. Governance policies exist on paper in many organizations, but enforcement depends on signals that most tools were never built to capture. This article walks through shadow AI, personal versus corporate tenants, extensions, prompt and data movement, agent actions, exceptions, and spend, seven categories that matter for AI governance.

Shadow AI is now the baseline governance problem

Most governance conversations still treat shadow AI as an edge case. Compliance Week's 2026 AI Compliance Survey found that 83% of organizations are already using AI tools, yet only 25% have implemented strong governance frameworks. 98% of organizations have employees using unsanctioned AI tools.

Shadow AI persists because AI enters organizations through nine entry points at once, from browser extensions to embedded copilots inside SaaS apps. Security teams facing that many doors tend to fall back on blocking policies, which push usage further into channels they can't see. Monitoring has to start with an honest count of where AI shows up before any control decision makes sense.

Personal versus corporate tenants

Once shadow AI is acknowledged, the next signal is which account employees are using. The same research on unsanctioned AI use found that 47% of employees access AI through personal or unmanaged accounts rather than corporate-licensed tenants. That distinction matters because corporate tenants typically carry different data handling terms than personal accounts, though the specifics vary by provider and agreement.

Monitoring this signal means distinguishing a ChatGPT session logged in with a work email under an enterprise agreement from the same tool logged in with a personal Gmail account. That distinction is a baseline requirement, not an advanced feature. Without tenant-level visibility, every other governance control is guessing.

Browser extensions are their own risk category

AI now arrives packaged as browser extensions, and the volume is larger than most inventories capture. We track more than 18,200 AI extensions with real-time risk scoring. Extensions often request broad permissions that can expose page content, which makes them a direct path for sensitive information to leave managed systems.

Treating extensions as a distinct monitoring category, separate from sanctioned apps, gives security teams a way to flag risky permission requests before they become policy violations. Our enterprise browser sits at this control point, where extension activity and permission requests can be seen and controlled.

Prompt content and data movement

What employees type into AI tools carries more risk than which tool they chose. The KPMG survey mentioned earlier found that 48% of employees admit to uploading sensitive data into AI tools, a habit that outpaces most data loss prevention rules written for file transfers rather than conversational input. Productivity gains explain part of the pressure behind this behavior. An NBER paper showed a 14% increase in productivity for call center workers assisted by generative AI, which means employees have real incentive to keep using these tools even when data handling guidance is unclear.

Monitoring prompt content means watching the text that goes in and the text that comes back. Domain lists don't show that. Data movement across connected SaaS systems is part of this picture too. Our network extends visibility to files, permissions, and configuration changes that move through SaaS APIs, so a browser session isn't the only point of inspection.

Agent actions change the monitoring unit

Agentic AI shifts what needs to be watched from a single prompt to a chain of actions. We put 53% of AI interactions at autonomous actions rather than a person typing a question, which means more than half of current AI activity in some environments isn't a conversation to review after the fact. A single agent can touch a file, call an API, and move data in one sequence, and most tools only see one or two steps in that chain.

Gartner expects AI agents to outnumber human users 10 to 1 in large enterprises within a few years. Our scan of nearly 34,000 public MCP servers found that one in three carries a high or critical severity finding, and 92% of the owners have no verifiable organizational affiliation. Gartner also predicts that over 40% of agentic AI projects will be canceled by the end of 2027. Monitoring agent actions means logging the full sequence an agent completes, from the request that started it through every step after.

Exceptions reveal where policy doesn't match reality

Exception requests are usually treated as an operational nuisance, but we found that 93% of prompts sent to a human reviewer get approved, a rate high enough that the human-in-the-loop step functions mostly as a formality.

Read against that framing, a high approval rate is worth treating as a prompt to reassess policy, not proof that reviewers are approving everything. It may mean the policy blocks more broadly than it needs to, or it may mean the review process needs better context to move faster. NIST's Generative AI Profile recommends transparent acceptable use policies. Watching exception volume and approval rates over time tells a security team whether its written policy still matches how people work.

Spend is a governance signal, too

AI spend tends to live in a separate reporting line from AI usage, which means security teams often learn about a new AI deployment after the invoice arrives. A McKinsey survey found that 93% of respondents have reported exceeding their AI budgets, a pattern that usually means new tools or higher usage tiers got approved without a parallel security review.

Tracking spend alongside usage closes that reporting delay. When a jump in API calls or seat licenses shows up in the same dashboard as browser and agent activity, it becomes a trigger for review rather than a surprise. This is one more reason usage, agent actions, and cost need to sit in the same monitoring view rather than three separate reports.

Bringing the signals together

Shadow AI without tenant visibility just tells you AI is happening somewhere. Agent action logs without spend context miss the budget signal that often precedes a new deployment. NIST's AI Risk Management Framework organizes this kind of work into four functions, Govern, Map, Measure, and Manage, which is a useful way to think about why these monitoring signals need to feed a single decision process rather than sit in separate tools.

AI governance ties these signals, including MCP gateway visibility and agent runtime controls, into that single process rather than treating each one as a standalone tool. Teams that want the fuller model can start from the nine entry points. Getting visibility into shadow AI, tenant type, extensions, prompt content, agent chains, exceptions, and spend is what lets a governance policy be enforced at the point of use.

FAQs

Where should a team with no AI monitoring in place start?

Start with an honest count of where AI already shows up, since AI enters organizations through nine entry points at once, from browser extensions to embedded copilots inside SaaS apps. Trying to build controls before that inventory exists usually means the controls target the wrong channel.

Does blocking AI tools solve the shadow AI problem?

No. Security teams that fall back on blocking policies tend to push usage further into channels they can't see, which is part of why 98% of organizations report employees using unsanctioned AI tools despite existing policies. Visibility into usage has to come before enforcement decisions.

How is monitoring agent actions different from monitoring prompts?

A prompt is a single request a person types. An agent action is a chain, where one agent can touch a file, call an API, and move data to an external domain in one sequence, and most tools only see one or two steps in that chain. Monitoring agents means logging the full sequence, from the request that started it through every step after.

What does a high exception approval rate tell us?

We found that 93% of prompts sent to a human reviewer get approved, a rate high enough that the human-in-the-loop step functions mostly as a formality. Read that way, it's worth treating as a signal to reassess whether policy blocks more broadly than needed, or whether reviewers need better context to decide faster.

Should personal AI accounts be treated differently from corporate accounts in monitoring?

Yes. 47% of employees access AI through personal or unmanaged accounts rather than corporate-licensed tenants, and corporate tenants typically carry different data handling terms than personal accounts. Distinguishing account type is a baseline visibility requirement, not an advanced feature.

Is AI spend a security concern or a finance concern?

Both. A McKinsey survey found that 93% of respondents have exceeded their AI budgets, and spend spikes often mean new tools or usage tiers got approved without a parallel security review. Tracking spend alongside usage turns that delay into a review trigger instead of a surprise.

Do browser extensions need their own monitoring category?

Yes. Extensions often request broad permissions that can expose page content, and we track more than 18,200 AI extensions with real-time risk scoring. Treating them separately from sanctioned apps lets teams flag risky permission requests before they become policy violations.

Island Team

Island is defining the future of work for people and AI agents. Its enterprise agentic control plane helps organizations enable, govern, and audit agentic workforces alongside people. Island boosts productivity across devices, browsers, applications, networks, and data while protecting sensitive information, simplifying access, and helping enterprises scale AI safely.