Blog

From Shadow IT to Shadow Agents: do you really know which AIs are working in your organization?

For years, IT departments have dealt with Shadow IT: the software, cloud services, applications, and devices introduced into the company without necessarily going through official IT processes. The phenomenon often arose from a perfectly legitimate intention. An employee discovers a more practical tool, creates an account, uploads a few documents, and starts using it with colleagues to work faster or to solve a problem the official tools address poorly.

The arrival of generative artificial intelligence gave the phenomenon a new dimension. With Shadow AI, employees began using models and applications sometimes unknown to the organization, sending them documents, data, source code, customer information, or part of the company's knowledge. The governance problem was already becoming more complex, since the tool no longer merely hosted or transported information: it could now interpret it, transform it, summarize it, and combine it with other data.

A third stage is now appearing with AI agents. An employee can progressively create or install a system able to access several applications, search for information, use tools, communicate with other services, and execute actions. The major technology platforms are rapidly making this creation easier and are embedding agentic capabilities directly into the productivity environments used daily in companies.

This shift changes the nature of the problem. Shadow AI can expose or process information outside the intended governance mechanisms. Shadow Agents add the ability to act. An individual initiative can thus gradually become a digital actor connected to the company's processes without the organization necessarily having a complete view of its existence, its permissions, the knowledge it uses, or the actions it can perform.

An employee who quietly uses an artificial intelligence tool to summarize a document already creates various risks. The organization may not know where the information was sent, how long it will be retained, in which jurisdiction it will be processed, which vendors are involved in the process, and which contractual or technical policies apply to its use. An agent can go much further because it becomes an active participant in the information system.

Depending on the permissions granted to it, it can consult an email inbox, browse files, query a CRM, use a calendar, communicate with various applications, produce documents, modify certain data, or trigger processes. NIST describes this very shift as the move from a generative AI mainly intended to produce content toward agentic systems capable of carrying out actions in external environments. The identity and authorization of these agents therefore become fundamental dimensions of their governance.

Shadow Agents appear when part of this activity develops without sufficient organizational visibility. This in no way means that an employee is deliberately trying to circumvent the rules. A sales representative may create an agent to prepare customer follow-ups, a manager may automate their weekly report, an analyst may connect a few data sources in order to eliminate several hours of manual work, and a developer may build an agent tasked with reviewing certain requests and then proposing fixes. Each one is simply trying to improve their work.

The problem builds up gradually. The agent proves useful and receives a new connection. A second application is added. A colleague starts using it. An automation then allows it to write into a system rather than simply consult it. A few months later, an individual experiment has become a component of an operational process without necessarily appearing in any official organizational inventory.

This progression resembles several phenomena companies have already experienced with spreadsheets, personal databases, SaaS applications, collaboration tools, and no-code automations. Some organizations today hold thousands of files or small applications whose dependencies nobody fully understands. Agents can reproduce this phenomenon on a far larger scale, since they can take certain initiatives and act on other systems.

The democratization of their creation could considerably accelerate this proliferation. Employees will not necessarily need to know how to program. Platforms will progressively allow them to describe what they want to accomplish, select a few information sources, add connectors, and build an agentic automation. When a technology becomes simple to create, relatively inexpensive, and capable of saving a great deal of time, its proliferation becomes predictable.

Gartner now uses the expression agent sprawl to describe this phenomenon and estimates that an average Fortune 500 company could be using more than 150,000 agents in 2028, compared with fewer than fifteen in 2025. The firm also indicated in the spring of 2026 that only 13% of organizations considered they had adequate governance of their AI agents. These projections naturally remain estimates, but they illustrate the scale the problem could quickly reach when creating agents becomes accessible to a large share of employees.

One elementary question could then become particularly hard to answer: how many agents are actually working in the organization? Mature companies generally have an inventory of their users, their equipment, and a significant portion of their software. They know who can access the main systems and have processes for creating, modifying, and then deleting accounts. The agentic environment will progressively require comparable discipline.

It will be necessary to know which agents are active, who created them, who assumes organizational responsibility for them, which models they use, which data they can consult, which applications are accessible to them, which actions they can execute, which external services they communicate with, and which other agents can interact with them. It will also be necessary to determine which ones are still needed.

This last question is particularly important. Abandoned agents could become a new generation of orphan accounts. An employee creates an agent for a particular project, grants it various accesses, then changes roles or leaves the organization. The agent can continue to exist, its credentials can remain valid, and its connections can stay active. Governance must therefore cover its entire life cycle, from creation through to deactivation.

Here we find a fundamental principle of cybersecurity: an organization has difficulty protecting what it does not know exists. This reality becomes even more important when we are no longer dealing solely with a piece of software or an account, but with a digital identity capable of consulting information, using tools, and executing actions.

The question of identity thus becomes central. When an agent acts across several systems using the credentials of the employee who created it, logs can hardly distinguish human actions from automated ones. This confusion affects traceability and can also considerably widen the agent's capabilities. A human may hold certain permissions because they exercise judgment, know the company's policies, and remain responsible for their decisions. Automatically passing all of those privileges to an agent amounts to assuming that every capability granted to the person can also be exercised automatically.

NIST's work on agent identity proposes precisely that they be treated as distinct entities with their own identities and authorizations. This approach makes it possible to know which agent consulted a piece of information, triggered an operation, or requested an access. It also facilitates auditing, the revocation of privileges, and the distinction between a human action and an automated one.

This discipline connects directly to AI Onboarding. When a new agent enters the organization, its mandate must be defined, its knowledge identified, its identity created, its permissions determined, its level of autonomy established, and its organizational owner designated. When its role changes, these elements must be reassessed. When it no longer has a reason to exist, its accesses and capabilities must disappear with it.

The agent's initial creation is nevertheless only part of the problem. Its permissions naturally tend to evolve along with its usefulness. A sales agent may start with read access to the CRM, then receive authorization to create a note in it. It is then allowed to prepare an email, then to send it. A few months later, it may modify an opportunity, generate a proposal, and trigger certain administrative steps. Each permission has a perfectly understandable operational justification, yet their accumulation ends up creating a capability very different from the one that was evaluated at the outset.

Gartner uses the expression agent authority drift to describe this growth of agentic authority when decision-making and operational capabilities evolve faster than the mechanisms designed to supervise them. This drift becomes particularly difficult to detect when agents are numerous and interconnected.

One agent may hold a reasonable permission and a second may have another, equally justifiable authorization. When the first can communicate with the second, their combination may eventually enable an action that neither of them was meant to be able to carry out individually. Governance must then go beyond each agent's own permissions and also encompass their interactions, their delegations, and the chains of actions they can form.

This dimension illustrates why agentic risk becomes an architectural problem. Securing each component individually does not guarantee that their interactions will produce a secure environment. Identities, permissions, APIs, tools, data, models, vendors, humans, and other agents progressively form a system in which new paths of action can appear.

Shadow Agents also raise a question of knowledge governance. To be useful, an agent often has to know the products, the customers, the policies, the processes, the projects, the contracts, or certain internal decisions. It can access documents from several departments and create relationships between pieces of information that were previously scattered.

This capability is precisely one of the great strengths of artificial intelligence, but it also increases the importance of understanding what an agent can know. A system quietly created by an employee can gradually become a point of concentration for a considerable amount of knowledge about the company. When nobody has a complete view of its existence, nobody genuinely determines whether all of that information should be able to be brought together, interpreted, and used as a whole.

The problem therefore goes beyond the confidentiality of each individual document. It also concerns the ability to reconstruct organizational knowledge from multiple sources. This is precisely why the Qb Knowledge Standard – AI Readiness & Knowledge Governance takes on particular importance in an agentic environment. The organization must know which knowledge exists, which is authoritative, how it is classified, who can access it, and how it can be used by people as well as by agents.

Faced with these risks, the most immediate reaction might be to ban agents that are not officially approved. Such a measure can be perfectly justified in certain environments or for certain categories of data and actions. It becomes far harder to maintain as a general strategy, however, when agentic capabilities are progressively built into the productivity tools employees already use every day.

Excessively heavy governance can also produce the opposite of the intended effect. When every experiment requires several weeks of approval, some users will naturally look for faster solutions outside official processes. An absence of governance produces the opposite risk by allowing an uncontrolled proliferation of agents, connections, and permissions. Maturity therefore consists of adapting the level of control to the level of risk.

An agent that summarizes public documents in an isolated environment does not necessarily warrant the same controls as a system connected to the CRM, to email, and to financial information. The level of autonomy, the sensitivity of the accessible knowledge, the connected systems, and the ability to execute actions must determine the depth of governance. This approach makes it possible both to preserve innovation and to concentrate the most rigorous controls where the potential consequences are greatest.

The first response to Shadow Agents ultimately remains fairly simple: know what exists. Organizations will progressively have to create a registry of their AI agents. It should go well beyond a list of names and make it possible to know each agent's role, its organizational owner, the models and vendors used, the knowledge and data accessible, the connected systems, the permissions granted, the level of autonomy, the other agents it can interact with, and the date of its last review.

Gartner now explicitly recommends a centralized inventory that makes it possible to discover, classify, and govern agents according to their level of risk. This practice could quickly become as normal as the inventory of IT assets and lead to an even more interesting representation: a genuine agentic map of the organization.

Companies know their human org chart and hold various representations of their technology architecture. A third map will progressively have to show which agents take part in processes, which people they work with, which knowledge they use, which systems are accessible to them, which actions they can trigger, and how they interact with one another. This representation will give executives a far more faithful view of an organization in which humans and agentic capabilities now contribute to the same processes.

Such governance cannot fall exclusively to IT or cybersecurity. Sales must know which agents communicate with their customers. Finance must know which ones can intervene in financial processes. Human resources must understand which ones access employee information, while legal teams must know the situations in which an agent can process regulated information or help create a commitment. IT controls the systems and identities, cybersecurity analyzes the permissions and flows, and leadership must determine the level of autonomy the organization is willing to grant.

Agentic governance therefore necessarily becomes cross-functional. This is precisely the space in which an AI Governance Office can operate alongside internal teams in order to maintain a shared view of the AI environment, establish responsibilities, define acceptable levels of autonomy, and track how agents evolve. AI Onboarding structures the entry and life cycle of each new capability, while IAM, Zero Trust, and Continuous Trust frame identities and permissions. The Qb Knowledge Standard governs the accessible knowledge, and agentic cyber vigilance makes it possible to verify that behaviors and capabilities remain consistent with the mandates established.

As this environment grows more complex, Hypersecurity makes it possible to widen the thinking beyond the individual protection of each agent. Cybersecurity remains essential to protect identities, accesses, data, applications, and communications. Hypersecurity makes it possible to add governance, interactions between agents, dependencies on vendors, the evolution of capabilities, resilience, and the organization's ability to retain its decision-making autonomy when its technology environment changes.

Quantum Beyond can support organizations through this evolution by working with their teams to progressively build this agentic management architecture. The objective is to provide enough visibility and control for the most useful individual initiatives to become well-governed organizational capabilities, rather than letting innovation gradually turn into an ecosystem of agents of which nobody has a complete view.

Shadow IT appeared when employees found useful technologies faster than organizations could integrate them. Shadow AI reproduced the phenomenon with systems capable of receiving, processing, and interpreting part of the company's knowledge. Shadow Agents now add a far more operational dimension: these systems can also act.

This evolution could advance rapidly because creating agents is becoming increasingly accessible and is being built directly into the platforms used every day. Organizations could thus move from a few visible experiments to dozens, hundreds, or eventually thousands of agentic capabilities spread across their processes. Some will be officially deployed, others will appear at the initiative of teams, and a few may continue to exist long after the need that justified their creation has disappeared.

The answer is to build governance proportionate enough to sustain innovation while giving the organization a real view of its environment. It must know which agents exist, who is responsible for them, which knowledge they hold, which systems they use, which actions they can perform, which other agents they collaborate with, and how their permissions evolve. It must also be able to detect agents that have become unnecessary, reassess their autonomy, and withdraw their accesses when their role disappears.

Quantum Beyond can support this transformation alongside internal teams by connecting AI Onboarding, AI Governance Office, IAM, Zero Trust and Continuous Trust, Qb Knowledge Standard, agentic cyber vigilance, cyber resilience, and Hypersecurity architecture. Together, these disciplines make it possible to turn the proliferation of agents into a governed capability rather than a new form of invisible IT.

The real risk of Shadow Agents could thus emerge far more quietly than a spectacular incident. It will emerge once enough agents have found their place in operations that nobody any longer has a complete view of the ecosystem they form. Maturity will then begin with a very simple question: do we really know which agents are working in our organization, which knowledge is accessible to them, which authorities we have progressively granted them, and how far they can now act on our behalf?