Skip to main content

The problem · Shadow AI

Shadow AI agents: finding the ones already in your estate

Shadow AI used to mean someone pasting a spreadsheet into a chatbot. Now it means software that can read your repository, run a terminal command and call an internal API, installed by one person and known to nobody else.

The distinction

Why agents are different from shadow IT

An unsanctioned SaaS app holds data. An agent acts. It inherits the permissions of whoever installed it, can chain tools together through MCP servers, and can be steered by text it reads: a web page, a README, an email. That last property is prompt injection, and it turns an agent into an insider that takes instructions from strangers.

This isn’t theoretical. CrowdStrike’s 2026 Global Threat Report found adversaries had injected malicious prompts into legitimate GenAI tools at more than 90 organizations to generate commands for credential theft. (CrowdStrike, 24 February 2026.)

Where they are

The four places they hide

Developer tooling

Coding assistants and agentic IDEs, often installed per-user and never reported.

Desktop and browser agents

Assistants with file-system or browser control.

MCP servers

Local connectors that hand an agent new tools. One poisoned tool description is enough.

Dormant installs

Agents installed, used once, and still sitting there with credentials cached.

The gap

Why network tools miss half of them

A proxy, CASB or AI gateway sees an agent when it sends traffic. It can’t see an agent that’s installed but idle, one calling a model directly off-network, or what a prompt did on the machine after the response came back. Finding all four categories above means looking on the endpoint.

What to do

A practical order of operations

  1. 01

    Inventory first, policy second

    You can’t govern what you haven’t found.

  2. 02

    Observe before you enforce

    A week of baseline tells you which agents do real work.

  3. 03

    Define sanctioned AI in writing

    Tools, destinations and data that may not leave.

  4. 04

    Enforce on a pilot group

    Then widen.

  5. 05

    Assign an owner for the detections

    An alert nobody triages is a log entry.

Start here

Start with a readout

The AI Agent Readout runs CrowdStrike Falcon® Guardian discovery on a pilot group and hands you a named list: every agent found, whether active, dormant or unsanctioned, what it can reach, and what we’d watch first.