Shadow AI’s Rise: Understanding the Governance Gap of Autonomous Agents in Organizations
Shadow AI's Next Act: Ungoverned Agents Are Making Decisions Organizations Can't See
Security leaders warn that AI tools have quietly evolved from passive assistants into autonomous agents—and most organizations have no idea what's already running inside their systems.
The numbers are hard to argue with. According to research from ThreatDown, 74% of organizations are running more AI tools than they expected. Companies that predicted five or fewer tools in their environment found 16 or more already active in 30% of cases. Workforce adoption told an equally startling story: organizations estimated roughly a third of employees were using AI tools day-to-day. The actual median was 58%.
That is not a rounding error. It is a governance system that does not know what it is governing—and what is slipping through that blind spot is no longer a passive chatbot. Increasingly, it is an agent: software with standing permissions to read files, execute code, and access other systems via protocols like MCP (Model Context Protocol). Security leaders are now sounding the alarm about what that shift means for organizations still struggling to count what they have.
From Shadow IT to Shadow Agents
The concept of shadow IT—employees using unauthorized software without informing IT departments—is not new. But shadow AI is a different animal entirely, and the stakes are considerably higher.
"The fact that 74% of organizations found more AI tools than they expected, and that actual workforce use was a median of 58% versus an expected 33%, underscores the shadow AI reality that many organizations and CISOs are struggling with right now," said Diana Kelley, CISO at Noma Security.
Kelley's concern is that the governance gap sharpens significantly as AI use shifts from something people do to something agents do autonomously. These agents can access sensitive data, run code, and connect to other tools and services without a human initiating each action. The implications of that shift are compounding rapidly as more departments deploy tools without security oversight.
"You can't govern what you can't see, and with agentic AI, unknown access can quickly become enterprise harm," Kelley said.
Security teams, in her view, need simultaneous visibility into three things:
- What is running inside the environment
- What it can touch—data, systems, and third-party connections
- What it is actually doing at runtime
Without all three, an organization is flying blind inside its own infrastructure. And unlike a forgotten SaaS subscription, an ungoverned agent with standing permissions is not a passive liability—it is an active one.
Why Agentic AI Raises the Stakes Beyond Traditional Shadow IT
Traditional shadow IT typically meant an employee using an unsanctioned application to do their job. The risk was largely confined to data leakage or compliance gaps. Shadow AI in its agentic form introduces a fundamentally different threat profile.
An autonomous agent operating without governance can make decisions, trigger downstream actions across connected systems, and accumulate access over time—often without any individual within the organization being aware it is happening. The risks and challenges of AI in business extend well beyond productivity concerns when the systems in question are capable of acting independently at scale.
The distinction matters because the blast radius of an ungoverned agent is not limited to the tool itself. Via protocols like MCP, a single agent can serve as an entry point into a web of connected services, files, and credentials—none of which were part of the original risk assessment, assuming one was conducted at all.
The Checkpoint That Disappeared
How AI Erased a Built-In Security Control
Part of what makes shadow AI harder to contain than traditional shadow IT is that it bypasses a control organizations once relied on—often without anyone noticing it was gone.
Randolph Barr, CISO at Cequence Security, said the 74% figure does not surprise him. Most organizations are still building basic AI governance frameworks while leadership simultaneously pushes for faster adoption. Every department wants to experiment, and few think to loop in IT or security before launching a tool.
"It used to be that rolling out an application required engineering or IT, and that requirement was a built-in checkpoint," Barr said. "AI erased it. Now, anyone with a browser can wire up an agent over lunch."
That casual framing carries a serious implication. The friction that once slowed unauthorized software deployment has essentially vanished. If deploying a new AI agent takes less time than ordering lunch, the traditional approval pipeline offers no real defense. The velocity of deployment has outpaced the velocity of oversight—and that gap is widening.
Barr's prescription starts with the oldest rule in security: you cannot protect what you cannot see. But he warns against governance that arrives only after problems surface.
"If governance feels like a roadblock, people will just route around it, and you're back where you started," he said.
Building Controls That Match Agentic Behavior
The controls that matter for agents, in Barr's view, sit at the infrastructure layer. Effective governance at this level means:
- Tying every action to a verified identity rather than a borrowed or shared login
- Scoping agents to least privilege—access limited to precisely what a specific task requires
- Continuously discovering which tools and MCP connections are live, not just what was approved at the point of deployment
- Enforcing runtime behavior with a full audit trail, so a hijacked or off-script agent can be identified, contained, and reconstructed after the fact
The audit trail element is particularly significant. Without it, organizations cannot distinguish between an agent behaving as intended and one that has drifted—or been manipulated—into acting outside its sanctioned boundaries.
A Second Dataset Confirms the Blind Spot
Independent Research Points to the Same Problem
ThreatDown is not alone in its findings. Pathlock's 2026 AI Governance Gap Report, based on a May 2026 survey of 286 IT, compliance, and security decision-makers, found that 51% of organizations are not confident they know all the AI agents operating in their systems. That is a strikingly similar conclusion drawn from a different vendor surveying a different population.
"These findings mirror what we are seeing in our own research," said Chris Radkowski, GRC expert at Pathlock.
The overlap between two independent datasets points to something practitioners already suspect: AI adoption is accelerating faster than governance can keep pace with. Understanding the full scope of governance, risk, and compliance obligations in modern IT environments has become significantly more complex as agentic systems multiply across the enterprise.
Radkowski's emphasis is on treating agents as identities rather than tools—maintaining a live inventory of agents and their permissions, enforcing least privilege by task, and continuously monitoring activity across connected systems.
"Organizations also require transaction-level visibility, so they can answer not only 'What is this agent allowed to do?' but 'What is it actually doing?' across connected systems," he said.
The Gap Between Permission and Behavior
That distinction matters more than it might initially appear. Permission and behavior are not the same thing—and an agent acting within its technical permissions can still cause significant harm if its behavior drifts from its intended purpose.
An agent granted read access to a file system to summarize documents, for example, might—through misconfiguration, prompt injection, or a compromised MCP connection—begin exfiltrating data in a format that bypasses existing data loss prevention controls. Technically permitted. Entirely harmful. And without runtime monitoring, entirely invisible. The OWASP Top 10 for Large Language Model Applications outlines several attack vectors of this nature that security teams should be actively accounting for in any agentic deployment.
What Effective Governance Looks Like in Practice
The consistent message from security leaders is not to block AI adoption outright. That approach tends to push usage further underground rather than eliminate it. The practical alternative is to build governance that assumes agentic behavior from day one:
- Real-time discovery of what is actually running, not periodic audits of what was approved
- Identity-based access scoped to specific tasks rather than broad system permissions
- Runtime monitoring capable of catching an agent acting outside its intended lane before it becomes an incident
- Clear escalation paths so that anomalous behavior triggers a human review rather than silent continuation
Both surveys agree on the scale of the blind spot. What is happening inside it remains largely unmonitored—and closing that gap is the most urgent task security teams face heading into the second half of 2026.
The organizations that move first on this will not just reduce their exposure. They will build the institutional muscle to govern whatever comes after agents—and in the current environment, something always comes after.
How you can use this information:
- Security and IT leaders can benchmark their own AI tool inventory against the ThreatDown and Pathlock findings to identify whether their governance gap matches or exceeds the industry median.
- Compliance and risk teams can use the agent-as-identity framework to update access control policies before regulators require it.
- Department heads outside IT can use this research to understand why looping in security before deploying AI tools protects their teams as much as it protects the organization.