According to the Businesses at Work 2026 report, by Okta, built from data across more than 14,000 client organizations collected between November 2024 and October 2025, 91% of organizations already use AI agents to some degree. The same report measures the other half of the story: only 10% say they have a mature strategy to manage those agents, and just 32% apply the same identity rigor to them that they already apply to a regular employee.
That gap isn't about which AI model a company picked. It's about the door through which people — and now agents — walk in to use it. When a tool arrives outside the official purchasing process, it almost always arrives with its own login and password, never touching the same directory that already controls the corporate inbox and the finance system.
For whoever owns budget and risk, that gap has a concrete effect: IT stops being able to say, with confidence, who is actually authorized to use each AI tool in the company — and that's true even before any incident happens.
Every new tool is a new door
The most common adoption path is a familiar one: someone on a team pays with the department card, signs up with a work email, and picks a password on the spot. None of that process ever touches the central directory the company already maintains for everything else.
In Brazil and across Latin America, that path tends to be even shorter: buying an AI tool rarely goes through a formal process, and the security team only learns the tool exists once it's already been in use for months inside some operating area.
1Password's Access-Trust Gap 2025 report measured this build-up from the corporate security side: at least 34% of the apps used at the companies surveyed are not protected by single sign-on, and 70% of the IT and security professionals surveyed say single sign-on, on its own, is no longer enough to secure the identity of the people who work there.
The same survey found that 52% of employees have already downloaded an application without IT approval — a behavior most internal policies treat as an exception, but that the research shows is a simple majority.
AI speeds this pattern up. Verizon's 2026 Data Breach Investigations Report found that unapproved AI tool use among employees jumped from 15% to 45% in a single year, and that this use now ranks among the report's three most common causes of unintentional data leakage. Each of those tools shows up with its own door — and most of them never talk to the directory the company already keeps for everything else.
The practical result is an access list that grows faster than any IT team can track item by item. Every new tool adds to an inventory almost nobody reviews in full, and each one, on its own, seems too small to justify a formal process.
Why a stronger password doesn't fix it

The most common response from companies is technical and narrow: require a stronger password, enforce periodic resets, or publish a list of banned tools. None of those measures change the central fact: the tool still lives outside the company's directory, with an identity nobody there truly administers.
A stronger password doesn't solve what happens when someone leaves the company: with no link to the central directory, closing that specific access depends on someone on the IT team remembering to do it, tool by tool.
A list of banned tools has the same limit as any ban with no official alternative: it reduces what shows up in the company's records, not what the team actually uses to get work done. The jump from 15% to 45% in unapproved AI use that Verizon measured in a single year happened during the exact period when more companies published stricter AI policies.
The problem, then, isn't a discipline problem. It's an architecture problem: as long as entering an AI tool depends on a password created outside the company's directory, no policy on its own will close that door.
The alternative isn't choosing between blindly trusting the team and banning everything. It's moving where the door sits: instead of every tool having its own lock, all of them use the same entrance the company already manages.
What has to be in place
A governed AI environment fixes this at the root, not at the edge — with four verifiable mechanisms.
Entry through corporate identity. People use the same login they already use for the network and the company email. The corporate directory — the same one IT already maintains — is what confirms who they are, with no extra sign-up and no extra password to remember.
Profile and permissions coming from the directory. Role, department, and function arrive already set from wherever the company already keeps that information, instead of every new tool rebuilding that record from scratch, with its own criteria and its own gaps.
Automatic deprovisioning. When someone leaves the company directory, their AI access drops at the same instant — with no manual task that someone could simply forget in the middle of a list of other tools.
A single access log. Who logged in, when, and what they did get recorded alongside the rest of corporate access, in one place — not scattered across separate dashboards nobody ever cross-checks when they need to reconstruct what happened.
This is how Skyller was designed: entry through the corporate identity that already exists, profile pulled from the directory, and automatic deprovisioning the moment someone leaves.
Fewer passwords, real visibility

For whoever runs IT, the most immediate gain is the number of passwords that stop existing. Every tool that starts entering through corporate identity is one less password to reset and one less ticket when someone forgets their own access.
For whoever owns security, the gain is different: the same log that already shows who logged into the finance system starts showing who logged into the AI tool and what they asked it. Investigating an incident stops depending on rebuilding, tool by tool, who had access to what. At Skyller, that record is born connected to the rest of corporate access, not sitting as a separate dashboard.
And for whoever runs the operation, the gain shows up in everyday adoption: a tool people already open with the login they use every day has one less barrier between them and the work. Nobody has to remember one more password to start using it.
None of these gains depend on the team changing its behavior. They show up because the door moved — and that's an architecture decision, not an internal awareness campaign.
Before approving one more tool
Before approving the next AI tool — or finding out the team is already using one without telling anyone — it's worth reviewing four points with IT:
- Does the tool log in through corporate identity, or does it have its own sign-up? If the answer is "it has a separate login," that's already the first point of risk, and it's worth asking why that exception was accepted.
- Does leaving the company directory automatically remove access? If it depends on someone remembering, tool by tool, that access will keep existing long after it should have ended.
- Is there one place to check who logged in and what they did? If the answer is scattered across different dashboards, one per vendor, that record effectively doesn't exist when someone else needs it.
- How many AI tools is the team using today that IT doesn't know about? Without that count, any new security policy only protects part of the company — and the larger part could be outside it.






