The real break is not the AI feature itself. It is the standing identity behind it. Once an agent has its own token or service account, stealing that identity can give an attacker the same access the agent already had, which turns shadow AI into an identity problem instead of an app-approval problem.
The report says enterprise AI use is moving faster than governance, and one cited study found a 466.7% increase in active AI agents in the last year. It also says these agents are often given privileged access to core systems, which makes OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure the targets that matter.
That shifts the risk from controlling chat tools to controlling the accounts that connect AI to mail, docs, code, and business systems. In environments where agents can read and act, those identities become persistent, high-value credentials that existing governance does not model well.