Shadow AI Isn't Coming, It's Already There
Shadow IT used to mean an employee signing up for a SaaS tool without going through procurement. Shadow AI is a different scale of problem entirely. Recent research from Token Security found that 82% of organisations have already discovered AI agents operating in their environment that nobody formally approved. This isn't a hypothetical risk to plan around. For most organisations, it has already happened, and the open question is simply whether anyone has found it yet.
The reason this spread so quickly is structural. Building and deploying an AI agent has become genuinely easy, often requiring no procurement process, no security review, and no IT involvement at all. An employee wanting to automate a repetitive task can spin one up directly inside Copilot Studio or a similar platform in minutes. That's a real productivity win. It's also how an organisation ends up with agents running that nobody outside the person who built them knows exist.
of organisations have found AI agents they never approved
have a proper process to shut an agent down once it's no longer needed
Why This Is a Different Risk Than Traditional Shadow IT
A rogue SaaS subscription is a cost and compliance problem, but it's largely passive, it sits there until finance notices the invoice. An unapproved AI agent is active. It can read data, connect to services, and take actions on its own, depending on what permissions it was granted at creation. Security researchers now talk about non-human identities, agents, service accounts, and API keys, outnumbering human employees by more than 100 to 1 in the average enterprise. Each one carries its own access, its own credentials, and in a shadow AI scenario, none of it was reviewed before it started operating.
CrowdStrike's CTO summed up why this is genuinely hard to govern: an agent's actions can look indistinguishable from a human's, technically. What's difficult to observe isn't the action itself, it's the intent behind it, and whether that intent still matches what the agent was originally built to do.
The Part That Gets Less Attention: What Happens After
Most shadow AI conversations focus on discovery, finding out what exists. Fewer focus on what happens next. The same research found that only 21% of organisations have a proper process to decommission an agent once it's no longer needed. Agents get created quickly, accumulate permissions as they're used, and then simply keep running, and keep their access, long after the task they were built for has changed or ended.
This creates a specific and often overlooked risk: an agent that was reasonable when it was built, scoped to a small team, connected to a limited set of data, can become a genuine liability months later if that team's needs change, the agent's connections aren't revisited, and nobody remembers it's still there.
Not "what data are employees putting into AI tools," but "which agents are actually operating in the environment, and what were they given access to." The second question is the one that defines real exposure.
Why Ownership Is the Question That Actually Matters
Answering it requires treating every AI agent the way an organisation would treat any other identity: continuous discovery of what exists, clear ownership assigned to each one, scoped access that matches actual need, and a defined lifecycle from creation through eventual retirement. Most organisations have some version of this discipline for employee accounts. Very few have extended it to agents yet.
Getting an Honest Answer for Your Own Tenant
This is exactly what Copilot Safe Scan and CopilotIQ are built to surface together. Safe Scan identifies exposure and access risk across the tenant, including agents connected to sensitive data sources they may not need, more detail on how that assessment works is available on the Copilot Safe Scan page. CopilotIQ provides the full agent inventory, ownership, channels, authentication methods, and usage, so instead of an estimate, there's an actual answer to how many agents exist and who's responsible for each one.
The organisations ahead of this problem aren't the ones with zero shadow AI. Given the numbers, that's genuinely rare. They're the ones who found it before it became an incident, rather than after.




