Shadow AI agents are multiplying. Here’s how to find and secure them.

Shadow AI agents are proliferating across organizations at an alarming rate. These hidden entities have been created in popular platforms such as Salesforce Agentforce, Microsoft Copilot Studio, and Zapier, often without IT or security teams being aware of their existence. With capabilities to connect to sensitive systems and take action on their own, shadow AI agents pose a significant risk to corporate data and operations.

The problem is not just about visibility; it’s also about control. New agents can be created in minutes, connected to sensitive systems with a single click, and modified daily. This pace of creation outstrips the ability of IT and security teams to keep up, leaving them struggling to maintain oversight and ensure that these agents are operating within acceptable parameters.

The risks associated with shadow AI agents are substantial. Unlike shadow AI apps, which may only provide incorrect or misleading information, a rogue agent can cause significant harm by taking unauthorized actions on corporate systems. The potential consequences range from data breaches to system crashes, making it essential for organizations to take proactive steps to identify and secure these hidden entities.

According to recent surveys, the majority of cybersecurity professionals rank agentic AI as the most dangerous attack vector this year, while a significant number of organizations have already encountered agentic AI risks. However, only a small fraction of IT leaders say they have a mature agentic AI governance program in place, highlighting a critical gap between exposure and readiness.

To bridge this gap, it’s essential to develop a discovery strategy that can identify shadow AI agents across various platforms. One approach is through API-based discovery, which connects to platforms like Salesforce Agentforce and Microsoft Copilot Studio to gather information about agent name, creator, creation date, status, configuration, and risk insights. However, many popular agentic platforms do not offer an API or expose agent details, leaving a significant blind spot.

Nudge Security has developed a comprehensive discovery method that addresses this gap by combining API-based and browser-based approaches. The former connects to platforms with exposed APIs, while the latter uses a browser extension to passively observe employee activity on platforms without APIs, automatically adding new agents to the inventory with associated risk signals.

The importance of browser-based discovery cannot be overstated. Agents built on platforms without APIs often carry broad access and minimal oversight, making them a significant risk to corporate systems. These low-friction tools are frequently used by engineers, ops teams, and product managers who may not need IT approval to use them, leading to a lack of visibility and control.

To effectively manage shadow AI agents, it’s essential to know what each agent can actually do. This requires more than just finding the agent; it demands an in-depth understanding of its capabilities and potential risks. By developing a comprehensive discovery strategy that incorporates both API-based and browser-based approaches, organizations can better identify and secure these hidden entities, reducing the risk of unauthorized access and system compromise.

As shadow AI agents continue to proliferate across organizations, it’s crucial for IT and security teams to prioritize their identification and management. By adopting proactive measures such as comprehensive discovery strategies and continuous monitoring, organizations can mitigate the risks associated with these hidden entities and ensure a more secure digital landscape.


Source: Bleeping Computer — 2026-07-27