AI was supposed to make work disappear. Yeah, well, we were also promised flying cars. Epcot lied to us.
Instead, many IT teams are operating in a far different reality. Documents are written faster. Code is generated in seconds. AI agents can summarize reports, automate workflows, and even interact with cloud services. Happy days. But the overall workload hasn’t necessarily fallen. In many organizations, it’s just moved sideways, into the hands of people who are already way too busy.
The real challenge isn’t how quickly AI tools produce work. It’s everything that happens afterward. Reviewing outputs. Correcting mistakes. Managing integrations. Governing access. Auditing activity. Cleaning up abandoned AI projects. Maintaining dozens of disconnected services. The list, as they say, goes on…
Alas, that’s the AI productivity paradox: we measure how quickly AI creates work; everyone can generate decent copy now, but rarely how much work an organization must do before that AI can be trusted.
Faster output doesn’t always mean less work
Most AI productivity metrics focus on the beginning of a workflow rather than the end.
Recent research into AI-assisted software development found that while developers spent less time writing code, they also spent significantly more time supervising, validating, and refining AI-generated output. Researchers described this shift as moving toward “supervisory engineering,” where engineers increasingly guide and verify AI rather than simply write code themselves.
Creating something faster doesn’t automatically mean delivering it faster. Instead, many workflows now look like this:
Generate → Review → Verify → Correct → Approve → Monitor
The first step is far quicker. The rest more often isn’t.
The hidden cost is verification
AI rarely removes responsibility.
McKinsey found that in many agentic AI software engineering workflows, around 60% of operational costs came from checking, repairing, and re-verifying outputs rather than generating them in the first place.
That shouldn’t surprise anyone responsible for production systems. Generated infrastructure still needs reviewing. Generated security policies still need validating. Generated code still needs testing. Generated IAM (Identity and Access Management) configurations still need to be confirmed before they’re deployed to AWS, Azure, or Google Cloud.
AI accelerates creation. It doesn’t eliminate accountability. Strong AI security depends just as much on governing access as on protecting data.
AI tools are multiplying the technology attack surface
We’ve already lived through SaaS sprawl. Now we’re experiencing AI sprawl.
Organizations aren’t adopting a single AI platform. They’re introducing browser assistants, coding copilots, chatbots, document generators, AI search tools, cloud-native agents, and specialized AI services, often independently across different departments.
According to Flexera’s 2026 State of ITAM report, only 31% of organizations have accurate visibility into their AI software, while 59% report increased AI spending waste as AI estates grow more complex.
Every new AI application introduces another lifecycle to manage. As more organizations experiment with agentic AI, approaches such as MCP access requests show how AI can request temporary access without bypassing governance or approval workflows:
- Licenses
- APIs
- Service accounts
- Access permissions
- Integrations
- Monitoring
- Logging
- Support
Someone has to own all of it.
AI agents create identity problems as much as technology problems
Traditional AI mostly answered questions. Modern AI increasingly performs actions. An AI agent might query Snowflake, provision infrastructure, update GitHub repositories, create Jira tickets, or retrieve confidential documents.
Every useful AI agent eventually encounters an access question. That’s the challenge explored in agent access control, ensuring AI agents can request and use only the permissions they genuinely need.
- Who authorized it?
- What can it access?
- How long should it keep that access?
- Can it delegate permissions?
- Can every action be audited afterward?
McKinsey’s 2026 research into AI trust found that organizations are now far more concerned with AI systems doing something inappropriate than simply saying something inaccurate, making governance and security central to successful AI adoption. That’s why identity governance has become one of the most important foundations of AI.
Without governed access, today’s helpful assistant can easily and silently become tomorrow’s unmanaged privileged identity. That’s exactly why continuous identity security matters: access shouldn’t be treated as a one-time event, but as something that’s continually verified throughout its lifecycle.
Many organizations are measuring the wrong thing
A chatbot producing an answer in ten seconds isn’t the metric that matters. The better question is:
How much organizational effort did it take to produce a trusted outcome?
That includes:
- Creation
- Verification
- Remediation
- Governance
- Security
- Maintenance
Deloitte found that while AI adoption continues to accelerate, 84% of organizations have yet to redesign work around AI, meaning many are simply adding AI onto existing processes rather than simplifying them. This is how technology intended to reduce workload can accidentally increase operational complexity.
Making AI tools a productivity multiplier
None of this argues against AI. Quite the opposite. We all want our flying cars and future of leisure. AI delivers enormous value when the surrounding operational model stays simple.
That means reducing shadow AI, avoiding unnecessary access sprawl, limiting identity debt, and ensuring that every AI identity follows the same governed lifecycle as every human identity.
Rather than creating separate approval processes for each new assistant or agent, organizations should centralize AI access controls, automate temporary permissions, adopt zero standing privileges, and revoke access automatically when work is complete.
When access becomes consistent, AI scales far more safely. The goal isn’t simply to deploy more AI tools; it’s to manage them through consistent governance, least privilege, and automated identity controls so they become a genuine productivity multiplier instead of another operational burden.
The real measure of successful AI isn’t how quickly it writes code, drafts documents, or answers questions. It’s whether the organization becomes simpler to operate as AI adoption grows. If AI creates more value, without additional complexity, it’s doing exactly what we hoped it would. Next stop: the flying cars.
AI tools work best when they don’t create another layer of access complexity. Start a free Trustle trial to centralize AI access requests, automate approvals, enforce least privilege, and eliminate standing access before AI sprawl becomes identity sprawl.




