The problem · Shadow AI
Shadow AI agents: finding the ones already in your estate
Shadow AI used to mean someone pasting a spreadsheet into a chatbot. Now it means software that can read your repository, run a terminal command and call an internal API, installed by one person and known to nobody else.
Why agents are different from shadow IT
An unsanctioned SaaS app holds data. An agent acts. It inherits the permissions of whoever installed it, can chain tools together through MCP servers, and can be steered by text it reads: a web page, a README, an email. That last property is prompt injection, and it turns an agent into an insider that takes instructions from strangers.
This isn’t theoretical. CrowdStrike’s 2026 Global Threat Report found adversaries had injected malicious prompts into legitimate GenAI tools at more than 90 organizations to generate commands for credential theft. (CrowdStrike, 24 February 2026.)
The four places they hide
Developer tooling
Coding assistants and agentic IDEs, often installed per-user and never reported.
Desktop and browser agents
Assistants with file-system or browser control.
MCP servers
Local connectors that hand an agent new tools. One poisoned tool description is enough.
Dormant installs
Agents installed, used once, and still sitting there with credentials cached.
Why network tools miss half of them
A proxy, CASB or AI gateway sees an agent when it sends traffic. It can’t see an agent that’s installed but idle, one calling a model directly off-network, or what a prompt did on the machine after the response came back. Finding all four categories above means looking on the endpoint.
A practical order of operations
- 01
Inventory first, policy second
You can’t govern what you haven’t found.
- 02
Observe before you enforce
A week of baseline tells you which agents do real work.
- 03
Define sanctioned AI in writing
Tools, destinations and data that may not leave.
- 04
Enforce on a pilot group
Then widen.
- 05
Assign an owner for the detections
An alert nobody triages is a log entry.
Start with a readout
The AI Agent Readout runs CrowdStrike Falcon® Guardian discovery on a pilot group and hands you a named list: every agent found, whether active, dormant or unsanctioned, what it can reach, and what we’d watch first.