Shadow AI Agents: How to Discover and Govern Unapproved AI Automation
Where shadow AI agents come from, the risks of unapproved automations, a discovery checklist and a governance approach that does not rely on bans.
Quick answer
Shadow AI agents are automations and agents running in your organization without approval or oversight: employee-built agents in no-code tools, AI features switched on inside SaaS products, personal assistants connected to work accounts, coding agents with unvetted MCP servers, and scripts using personal API keys. They create data, security, compliance and cost risks precisely because nobody knows they exist. Do not respond with a blanket ban; discover them, classify them by risk, decide whether to approve, migrate or retire each one, secure the ones you keep, register them and review regularly, while giving people approved tools that meet the same needs.
From shadow IT to shadow agents
Shadow IT used to mean unapproved apps. Shadow AI added unapproved chat tools, mostly a data-leakage concern. Shadow agents raise the stakes again because they act: an automation that reads a shared mailbox and posts summaries to an external tool, an agent with write access to the CRM, a coding agent connected to a production database through an MCP server. The usage is real and widespread; Microsoft's Work Trend Index research found that most people using AI at work were bringing their own AI tools.
Where shadow agents hide
| Source | Example | Typical access |
|---|---|---|
| No-code automation and agent builders | Agent that triages a shared inbox and updates a spreadsheet | OAuth to mail, drive, CRM |
| SaaS products with built-in agents | AI features enabled by a team admin in a helpdesk or CRM | Vendor-side access to company data |
| Personal AI assistants | Assistant connected to a work calendar and email | Delegated user access |
| Coding agents and MCP servers | Community MCP server connected to an internal database | Credentials on developer machines |
| Scripts and notebooks | Scheduled script calling a model API with a personal key | Hard-coded keys, broad data exports |
| Browser extensions | Extension that reads pages to summarize them | Everything the browser can see |
The risks
| Risk | How it shows up |
|---|---|
| Data leakage | Customer or confidential data sent to unvetted services or stored outside policy |
| Uncontrolled actions | Records changed, messages sent, tickets closed without review or audit |
| Security blind spots | Long-lived tokens and API keys nobody rotates; unvetted MCP servers |
| Compliance | Regulated data processed without assessment, records or consent |
| Duplicated automation | Several teams building the same agent differently |
| Vendor risk | Data terms nobody reviewed; tools without security commitments |
| Unpredictable cost | Usage-based AI spend on personal cards and team budgets |
Key takeaway
Shadow agents usually exist because people found real value. Treat discovery as a source of use cases to support properly, not only as a list of violations.
Shadow AI agent discovery checklist
- OAuth grants and connected apps in your identity provider and major SaaS admin consoles
- API keys, service accounts and personal access tokens with access to company data
- Workspaces in automation and agent-builder platforms used with company accounts
- AI features enabled inside SaaS tools (helpdesk, CRM, docs, project management)
- Network or secure web gateway logs for AI service domains
- AI client configurations on managed devices, including MCP server lists
- Expense reports and card spend on AI subscriptions and API usage
- Code repositories for model API keys and agent frameworks
- A short, no-blame survey asking teams what they use and why
Shadow AI governance framework
Discover → inventory every agent, automation and AI connection found
Classify → risk tier: data, actions, external reach, volume
Decide → approve as is | migrate to approved platform | retire
Secure → own identity, scoped credentials, logging, limits
Register → add to the agent inventory with owner and review date
Review → re-check on schedule and when access or tools changeMake the approved path easier
People build shadow agents when the approved route is slow or missing. Provide a short list of approved AI tools and agent platforms, a lightweight request process with clear turnaround, templates for common automations, and guidance on what data may be used where. For developers, central controls such as managed MCP allowlists help; see MCP governance and AI coding policy. The broader policy layer is covered in AI governance framework.
Need to find out what AI is really running in your business?
ZSpace Labs runs shadow AI discovery across identity, SaaS and code, then migrates valuable automations onto governed, supported platforms. See AI automation services.
Common mistakes
- Announcing a ban without offering alternatives
- Discovering agents once and never again
- Revoking access abruptly and breaking processes people rely on
- Ignoring AI features enabled inside approved SaaS tools
- Treating developer tools and MCP servers as out of scope
Classifying what you find
Use the same risk dimensions as for approved agents (data sensitivity, actions, external reach, volume) and decide quickly. Most findings fall into a few patterns.
| Finding | Typical risk | Typical decision |
|---|---|---|
| Personal assistant summarizing a user's own email | Medium (data use terms) | Move to an approved assistant with business data terms |
| Team automation posting internal data to an external tool | High (data leakage) | Migrate to an approved platform or retire |
| SaaS AI feature enabled by a team admin | Varies | Assess vendor terms; configure scopes; register |
| Coding agent with a community MCP server on a database | High (access, supply chain) | Remove; provide an approved server with read-only access |
| Script with a personal API key processing customer data | High | Rotate key; rebuild under a service identity or retire |
| Low-risk productivity agent on public information | Low | Approve and register with an owner |
Who should own the response
Discovery usually sits with security or IT, but decisions need the business owner of each automation and, for bigger programmes, an AI automation function that can provide approved alternatives (see AI automation center of excellence). Keep the process collaborative: an amnesty window, quick decisions, help migrating valuable automations, and clear rules for what happens to automations nobody claims.
Conclusion
Shadow AI agents are a symptom of demand. Discover them systematically, classify by risk, keep and secure what is valuable, retire what is not, and make the approved path faster than the shadow one. Then manage every kept agent through its lifecycle; see AI agent lifecycle management and AI agent governance.
Common questions.
AI tools and automations used in an organization without the knowledge or approval of IT, security or governance teams. Shadow AI agents are the subset that can act: automations, bots and agents that read data, call tools or change systems.