AI agents are the new shadow IT (and they’re harder to see)
August 5, 2026
5 minute read
Shadow IT used to mean a marketing coordinator expending a project management tool without looping in IT. Annoying, sure, but contained. You could find it eventually with an invoice, a login, and a data flow into a system you could audit.
Shadow AI agents blow that process out of the water.
Somewhere in your organization right now, an employee has probably built a custom GPT to draft client emails. Someone in finance may have set up a Copilot agent to reconcile spreadsheets. Someone in sales might be running a Claude-connected workflow that pulls data from your CRM and pushes updates back into it, automatically, on a schedule, without asking anyone first.
None of that shows up in your SaaS inventory and unlike your shadow IT program was built to catch, these agents don’t just hold data, they act on it.
What is agent sprawl?
Agent sprawl is the uncontrolled proliferation of AI agents across an organization, created by individual employees or teams using tools like ChatGPT, Microsoft Copilot, Claude, custom GPTs, and no-code automation platforms, without IT’s knowledge, approval, or oversight. Each agent typically has its own permissions, integrations, and access to company systems and most are never inventoried, reviewed, or governed the way traditional software is.
The term is showing up more often for a reason. By the end of 2026, Gartner estimates 40% of enterprise applications are expected to be integrated with task-specific AI agents, up from less than 5% in 2025. Active agents in the Microsoft 365 ecosystem alone grew 15 times year over year. That growth is happening largely outside procurement, outside security review, and outside the systems IT normally uses to see what’s running in the environment.
Shadow AI agents vs. shadow SaaS: why this round is different
Shadow SaaS has been an IT headache for well over a decade and most CIOs have some version of a program to deal with it. This program usually includes discovery tools, access reviews, and onboarding checklists.Â
This worked great for shadow SaaS since sanctioned and sanctioned apps are black and white, but AI agents are a different category entirely, for three reasons:
They take actions, not just store data. A shadow SaaS app sits there holding information until a human does something with it. An AI agent can read a file, draft a message, update a record, trigger a workflow, or call an API on its own, without a human approving each step. If it has access to the wrong system, the damage isn’t a data exposure sitting quietly in a database. It’s an action already taken.
They’re built inside tools you already sanctioned. This is the part that makes agent sprawl so hard to catch with traditional shadow IT detection. An employee isn’t signing up for a new vendor with a company credit card, which is the trail your discovery tools are built to follow. They’re building a custom GPT inside ChatGPT or standing up an agent inside Copilot Studio which your organization may have already approved at the platform level. The agent itself was never reviewed, it just inherited trust from the platform it lives in.
They multiply fast, and quietly. Building an agent doesn’t require a procurement cycle. It takes minutes, no code, and no one else in the loop.
How should IT security teams adapt their governance strategy for emerging shadow technologies?
| Shadow SaaS | Shadow AI Agents |
|---|---|
| Acts as a passive repository for organizational information | Executes independent workflows and system operations |
| Leaves a clear financial and procurement trail | Inherits platform trust and bypasses traditional discovery |
| Requires formal onboarding and procurement cycles | Multiplies rapidly without external oversight |
The visibility gap is bigger than most IT leaders think
If you assume you’d know if this were happening in your organization, the data suggests otherwise.
While 68% of organizations report high visibility into their AI agents and autonomous workflows, 82% discovered at least one agent that security or IT didn’t previously know about in the past year, according to CSA and Token Security’s “Autonomous but Not Controlled” report. Confidence and actual visibility are two different things, and right now the gap between them is where the risk lives.
That gap has consequences. Only 24.4% of organizations have full visibility into which AI agents are communicating with each other, and nearly half of all agents run without any security oversight or logging. Eighty-eight percent of organizations reported confirmed or suspected AI agent security incidents in the past year. Only 14.4% of organizations send AI agents to production with full security or IT approval. (Gravitee’s 2026 State of AI Agent Security survey, cited by TheStreet)
Permissions matter more here than they did with shadow SaaS too. Organizations enforcing least-privilege access for AI agents report a 17% incident rate, compared to 76% for those without it, according to Teleport research cited by TheStreet. An agent built with broad, default access, because nobody scoped it down, is a much bigger liability than an app someone forgot to log out of.
What this looks like in practice
Agent sprawl rarely announces itself. It tends to show up as:
- A custom GPT built by a sales rep that pulls prospect data from a CRM and drafts outreach, with no review of where that data goes or how it’s stored.
- A Copilot Studio agent built by an ops team to auto-approve expense reports above a threshold nobody signed off on.
- A no-code automation connecting a company Slack workspace to a personal AI account, so a workflow “just works,” with no visibility into what’s being shared on the other end.
- A finance analyst chaining a public LLM to an internal reporting tool to save a few hours a week, unaware that the connection persists long after the task is done.
Individually, each of these looks like a productivity win. Collectively, they’re an unmapped set of systems with standing access to company data and the ability to act on it, none of which IT provisioned, reviewed, or can currently see.
What IT and security leaders can do now
Blocking AI outright isn’t a real option at this point and it tends to backfire. Employees who lose access to unsanctioned tools don’t stop using AI. They move to personal accounts, which is a worse outcome for visibility, not a better one. The goal is to bring agent creation into the same governance lifecycle as everything else IT manages.
A few places to start:
Treat agent creation as a governance event, not a side project. Whether an agent is built in a developer environment, a SaaS platform, or an LLM tool, it should trigger the same basic questions you’d ask of any new system: who owns it, what is it for, and what should it actually be allowed to touch.
Extend discovery beyond your SaaS inventory. The tools generating the most agent sprawl right now are automation platforms, LLM builders, and the AI features embedded inside apps you’ve already approved. If your visibility program only tracks new vendor sign-ups, it’s missing where agents are actually being built.
Default to least privilege and audit it. Scope every agent’s access to exactly what its task requires, then review that access on a schedule. The gap in incident rates between organizations that enforce this and those that don’t isn’t small.
Make the approved path faster than the workaround. Employees build shadow agents because the sanctioned alternative is slower or doesn’t exist. A clear, fast process for requesting and approving agent-building tools closes that gap before it opens.
Build an inventory you can actually produce on demand. Regulatory frameworks are starting to require it. Being able to answer “what AI agents exist in our environment, and what can each one access” is quickly becoming a baseline expectation, not a stretch goal.
Frequently asked questions
What is agent sprawl? Agent sprawl is the rapid, decentralized growth of AI agents across an organization, built by employees using tools like ChatGPT, Copilot Studio, or custom GPTs, without central IT review, standardized permissions, or an inventory tracking what each agent can access.
What are shadow AI agents? Shadow AI agents are AI-driven tools or workflows that take autonomous action, such as reading files, updating records, or calling APIs, that were created and deployed without IT’s knowledge or approval. They’re distinct from general shadow AI (unsanctioned chatbot use) because they can act on systems, not just process information.
How is agent sprawl different from traditional shadow IT? Traditional shadow IT is largely a data visibility problem: an unsanctioned app stores information IT can’t see. Agent sprawl is an action problem: an unsanctioned agent can take steps inside company systems on its own, often with access inherited from a platform IT already approved, which makes it harder to catch with standard shadow IT detection.
Why can’t IT just block unauthorized AI tools? Blocking tends to push usage further out of sight rather than eliminating it, since employees who lose access to approved tools often shift to personal, ungoverned accounts. Most security guidance now points toward governed enablement: giving employees vetted tools and clear rules, rather than prohibition alone.