Est.
Shadow AILong read

AI Agent Proliferation Outside IT-Sanctioned Channels

Autonomous agents execute actions faster than security teams can discover them.

Staff Writer · · 12 min read
Cover illustration for “AI Agent Proliferation Outside IT-Sanctioned Channels”
Shadow AI · September 28, 2026 · 12 min read · 2,625 words

Shadow IT had a shape security teams learned to trace. A rogue SaaS app held data passively until a human logged in and did something with it, and that human left a trail: an invoice, a login record, a data flow that appeared eventually in an audit. Slow, annoying, but tractable. Shadow AI agents do not sit still long enough for that kind of forensics to work, because they read files, draft messages, update records, call APIs, and trigger workflows on their own, with no human approving each individual step.

That is the whole ballgame. Damage from a shadow SaaS app is an exposure sitting quietly somewhere, waiting to be found and closed. Damage from a shadow agent is an action already completed, an email already sent, a record already changed, before anyone with a security badge knew the thing existed.

Agents act instead of merely storing, reading files, drafting messages, updating records, calling APIs, and triggering workflows autonomously, without a human approving each step. They multiply in minutes, with no procurement cycle, no ticket, nothing resembling the external trail a purchase order used to leave behind.

IBM has described shadow AI as a mirror of the shadow IT wave from a decade ago, but with far higher stakes, because the data involved doesn't just sit in an unsanctioned app anymore. It trains or transits an external model. That distinction reframes the entire governance question. It is about discovering what agents already exist, watching what they do while they do it, and enforcing rules before an autonomous action causes harm that cannot be undone. Three structural differences make agent sprawl categorically harder to govern. Agents are built inside already-sanctioned platforms (a custom GPT inside ChatGPT, an agent inside Copilot Studio), so they inherit platform trust and never surface in traditional discovery.

The rapid growth of agent sprawl and its surprising numbers for security teams

Start with the velocity, because the velocity is the story. Gartner projects that by 2028 the average Fortune 500 company will run more than 150,000 active AI agents, up from fewer than 15 in 2025 Gartner. No review process on earth was built to scale with a curve like that.

The near-term numbers back it up. Active agents inside the Microsoft 365 ecosystem grew fifteenfold year over year, according to BetterCloud's reporting Gartner Gartner. Gartner separately estimates that by the end of 2026, 40% of enterprise applications will carry task-specific AI agents baked in, up from under 5% in 2025 LayerX. A joint CSA and Token Security survey found 82% of organizations had already discovered unknown AI agents running somewhere in their infrastructure, entirely outside governance oversight LayerX beam.ai.

The Gravitee State of AI Agent Security 2026 report puts a finer point on the gap between building and approving: 80.9% of technical teams have moved past the planning stage into active testing or production, yet only 14.4% of those agents went live with full security and IT sign-off. Turn that around and the picture gets uncomfortable fast. The approved agent is the exception now, not the rule.

Nothing in the SaaS era grew this fast. That speed differential is not a footnote to the difficulty of governing at scale, it is a governance failure in its own right, because a review process calibrated for annual license renewals cannot keep pace with a workforce spinning up new agents between coffee breaks.

Diagram: The Agent Approval Gap: Building vs. Sign-Off. Visualizes: Show the stark contrast between two figures from the Gravitee State of AI Agent Security 2026 report: 80.9% of technical teams have moved past planning into active testing or…

Who builds unsanctioned agents and why they persist

Everyone, basically. Microsoft's Work Trend Index found 78% of AI users at work bring their own tools outside IT approval Microsoft 2025 Work Trend Index. UpGuard's State of Unsanctioned AI Tools Report puts the figure at 81%, and notes fewer than half of those workers actually understand their own company's AI policy UpGuard 2025 State of Unsanctioned AI Tools Report. A separate CSA survey found 52% of employees admit to using AI tools without official approval, often through personal accounts that route straight around enterprise security controls secondtalent.com.

The pattern shifts by industry, and the shift matters because the stakes shift with it. In financial services, 72% of employees use at least one unsanctioned AI tool, in a sector where unauthorized data processing carries some of the steepest regulatory exposure anywhere. In healthcare, patient data turns up in 18% of AI data events, and HIPAA penalties run as high as $2.13 million per violation category per year. In legal work, 45% of professionals use consumer-grade AI tools on the job, which puts privilege and client confidentiality on the line every time Gartner Thomson Reuters 2024.

By function, marketing and sales lead on unapproved tool use, with HR close behind, but engineering wins on total AI adoption of any kind: more than 60% of engineering staff use AI tools, roughly 20 points ahead of marketing once approved and unapproved use gets counted together Cyberhaven 2026.

Banning any of this does not fix it. Roughly half of employees say they would keep using unapproved AI tools even under a full ban, and 60% say the productivity payoff is worth the security risk if it helps them hit a deadline Cyberhaven 2026. Google Cloud's Cybersecurity Forecast 2026 says that banning drives usage off the corporate network, which means the security team loses visibility rather than gaining control Cyberhaven 2026. A training gap explains a lot of the naivety involved. More than half of employed respondents in one survey said they had received no training whatsoever on the security or privacy risks these tools carry. They are productive employees, solving problems the fastest way available to them, which is exactly why a policy memo was never going to be the fix.

The data employees feed these agents and its destination

Diagram: Sensitive Data in AI Tools: A Threefold Rise in Two Years. Visualizes: Visualize the rapid rise in sensitive data being shared with AI tools: 10.7% of AI-shared data qualified as sensitive two years ago versus 34.8% today, based on…

The trend line here is the whole argument. Cyberhaven Labs found that 34.8% of data shared with AI tools now qualifies as sensitive, up from 10.7% just two years earlier, based on a sample spanning millions of workers Cyberhaven Labs 2025 AI Adoption and Risk Report. That is more than a threefold jump in what people are willing to paste into a chat window.

It gets worse once you ask where that data actually lands. Cyberhaven found 83.8% of AI-bound corporate data goes to tools rated critical or high risk by security classification, not merely unsanctioned but actively dangerous Cyberhaven Labs 2025. LayerX's Enterprise AI and SaaS Data Security report found 77% of workers paste sensitive data into tools like ChatGPT, 82% of those pastes happen through personal accounts invisible to enterprise monitoring, and 40% of file uploads contain personally identifiable information or payment card data Gartner LayerX 2025 Enterprise AI and SaaS Data Security report beam.ai. Separate research puts the share of workplace ChatGPT and Gemini accounts that are personal somewhere between 73.8% and 94.4% as of 2025, which means enterprise data loss prevention tooling is being routed around at the account level before it ever gets a chance to work verax.ai.

Source code is the single most commonly leaked data type across these incidents, and Samsung's leak of proprietary code into a public AI tool is not an outlier but a preview. The same pattern plays out constantly, at companies that never make headlines.

The distinction that matters here separates shadow agents from shadow SaaS cleanly. Data sitting in an unauthorized SaaS store can be audited, retrieved, deleted. Data that transits or trains an external model cannot be pulled back once it's gone. That irreversibility is the reason after-the-fact investigation stops being a viable strategy. Prevention has to happen at the point of action, because there is no cleanup crew for a model that already learned something it shouldn't have.

No-code platforms and MCP made agent creation a two-minute operation with no security review

Gartner already counts 41% of employees as "business technologists," people outside IT who build technology for their own teams, and expects citizen developers to outnumber professional developers four to one at large enterprises. No-code and low-code platforms turned that population loose on agent creation. Tools like Lindy, Zapier Central, Bardeen, and Gumloop on the no-code side, and Langflow, Rasa, DronaHQ, and Stack AI on the low-code side, put agent building within reach of anyone who can drag a box onto a canvas, usually with no procurement step and no IT ticket in sight, though platforms like Gumloop do build in access controls and audit logging by design.

The Model Context Protocol, an open standard Anthropic introduced in late 2024 that lets an AI application ask an external server what tools are available and then invoke them on demand, connects most of this. Adoption moved fast: more than 10,000 active public servers within a year, and by mid-2026 over 9,400 indexed across major registries, with private and enterprise-internal servers estimated at three to four times that count blog.qualys.com langprotect.com. MCP adoption grew more than 400% in 2025, and the overwhelming majority of those deployments happened with no formal security review attached.

Installing an MCP server is a package-manager command away. Hundreds of them sit published on npm and PyPI for Postgres, GitHub, Slack, Google Drive, AWS, Kubernetes, ready to connect an agent to production systems in the time it takes to read this paragraph. The NSA flagged the underlying problem in a May 2026 Cybersecurity Information Sheet: MCP's growth outpaced its own security model, much like early web protocols did, and the specification often expects servers to query and sometimes execute actions on behalf of connected clients. That inverts the client-requests-data pattern security teams built their defenses around, and leaves attack paths that go largely untraced.

AI agents proliferating outside IT-sanctioned channels represent a categorically different risk from legacy shadow IT, since they don't just hold data but act on it autonomously at machine speed, making discovery, monitoring, and enforcement the core governance challenge organizations must now solve. The combination of no-code builders and MCP means the technical barrier to deploying an agent with broad system access is now lower than the barrier to requesting a new SaaS license, which inverts the entire shadow IT detection model.

Organizations' inability to see the agents already running inside their environments

Confidence and reality have split apart here. 82% of executives believe their existing policies protect them from unauthorized agent actions, while only 21% actually have visibility into what those agents can reach, which tools they call, or what data passes through them LayerX beam.ai. That's not a small gap, that's most of the leadership layer operating on a belief with no supporting evidence.

Only 24.4% of organizations have full visibility into which of their AI agents are talking to each other, according to a Gravitee survey, which means most enterprise environments carry agent-to-MCP-server connections nobody on the security team can see Gravitee 2026 survey. CSA's April 2026 research found 53% of organizations have already watched an AI agent exceed its intended permissions. Not a projected risk. A documented pattern, already happened, already logged somewhere nobody checked.

DTEX's Insider Threat Report names shadow AI as the top driver of negligent insider incidents, ahead of unmonitored file sharing and personal webmail, the categories that used to top that list. That is not a future compliance risk. That is a present one.

Real incidents have already surfaced. A tenant isolation flaw at Asana affected up to 1,000 enterprises coalitionforsecureai.org. WordPress plugins exposed more than 100,000 sites to privilege escalation coalitionforsecureai.org. Researchers demonstrated prompt injection delivered through ordinary support tickets coalitionforsecureai.org. The structural reason visibility keeps failing is straightforward once named: agents built inside sanctioned platforms never surface in SaaS discovery tools, agents running on personal accounts never surface in DLP, and MCP connections are not tracked by most SIEMs. The detection stack in most organizations was built for a threat that stored data. This one acts on it. 43% of organizations cannot produce an AI inventory (a foundational requirement under NIST AI RMF and ISO 42001, and a practical prerequisite for EU AI Act compliance, Gartner, 2025), meaning compliance failure is not a future exposure but a present one.

The requirements of effective AI agent governance beyond logging

Governance has to follow the authority an agent holds, not the name of the model behind it. An agent becomes materially riskier the moment it can call tools, reach private data, act under a delegated identity, or make a change, so governance needs to track who can invoke it, what it can see, what it can do, what needs a human sign-off, and how every consequential action gets reviewed and, if necessary, reversed.

A useful way to sort agents is by authority level rather than by vendor or model. Some are purely advisory, producing information for a person to review. Some draft records or messages but cannot send or commit them. Some perform bounded actions inside a narrow, pre-approved scope. And some carry high-impact authority, capable of touching money, access, production systems, people, legal obligations, or public communications.

Identity discipline matters as much as the authority tier. Agents should run on short-lived, scoped credentials, with read and write authority kept separate and the actual acting principal visible in every log entry. NIST's 2026 concept paper on agent identity and authorization names identification, authentication, authorization, auditing, and non-repudiation as the core concerns, but that document remains a draft concept paper, not a finished standard, as of August 2026.

None of it works without discovery first. Logging alone will not save anyone here, because logs describe what already happened. They cannot stop an action an agent already took at machine speed. Real governance needs behavioral monitoring and policy enforcement that intercepts before execution, not forensic tooling that explains the damage afterward.

Irreversible actions need a human in the loop by design: anything financial, external, privileged, safety-related, or impossible to roll back should require approval as a distinct control layer, not a footnote to logging. And failure cases need testing on purpose: prompt injection buried in retrieved content, cross-tenant access attempts, stale approvals nobody revoked, duplicate or half-finished actions, unsafe output, rollback that quietly fails. Skip that testing and the first time any of it happens will be in production, with a customer watching. Discovery must come before monitoring: 43% of organizations cannot produce an AI inventory (you cannot monitor what you have not found), inventory agents separately from ordinary chat tools. NIST AI RMF Govern-Map-Measure-Manage functions applied to the full agent system: model, prompts, tools, data, memory, users, vendors, and operational context (governance scope is broader than the model itself).

Building a governance program that keeps pace with agent proliferation

Blocking does not work, and pretending otherwise wastes time everyone involved could spend building something better. Google Cloud's Cybersecurity Forecast 2026 is blunt about the mechanism: banning agents just drives usage off the corporate network, trading visibility for the illusion of control. The only strategy that survives contact with actual employee behavior is one that gives people sanctioned, safe ways to build what they were going to build anyway, while keeping the whole thing inside a governance perimeter that can see it.

Discovery has to come first, and it has to be separate from the existing SaaS inventory, because an agent built inside Copilot Studio or a no-code platform simply will not show up on a SaaS list no matter how carefully that list gets maintained. That inventory needs to capture MCP server connections too, not just the chat tools everyone already knows about.

Everything downstream, the authority classification, the identity controls, the approval gates, the abuse testing, only works once the inventory exists. Skipping straight to policy without first knowing what's actually running is how 82% of executives end up confident in protections that only cover the 21% of agents anyone can actually see LayerX beam.ai. The order matters. Find them first. Govern what you found. Anything else is theater.

Filed underShadow AI

More in Shadow AI