While AI may be revolutionary, the way people are adopting it isn't. We've seen this before with technologies such as mobile and remote working tools. When something is easy to access and helps people get their jobs done quicker, adoption often moves faster than the governance around it.
That makes shadow AI as much a cultural challenge, as a technical one. If people assume security will effectively “say no”, they're less likely to tell you what they're doing. In most cases, they don’t have bad intentions. They just want to use AI to work more efficiently or solve a problem their existing tools can’t.
New research by ProofID in conjunction with Coleman Parkes shows the scale of the challenge. As many as 40% of organisations are not confident they know every AI agent operating within their business, while only 22% maintain a complete central repository of their agents.
Every organisation surveyed believes agentic AI is already being used informally somewhere in the business, and among organisations without sanctioned production deployments, 43% describe that informal use as quite extensive.
That is why people and culture have to come first. If employees feel able to raise a new AI use case early, you can assess it before it becomes another act of shadow AI. The process needs to make that easy, while technology should help to uncover the tools and agents people haven’t declared.
Start with culture: make disclosure easier
Employees are adopting AI because it helps them get work done and that reality should shape how organisations approach shadow AI.
Someone experimenting with an AI tool is not necessarily attempting to circumvent your security controls. They may have found a way to summarise documents more efficiently, automate repetitive work, or complete a task that your current systems handle poorly. If the response from security teams is an automatic prohibition, that employee has a strong incentive to keep their experiment out of sight. The harder the approved route becomes, the more attractive the unapproved route looks.
So, if security becomes the “computer says no” department, the experimentation doesn't stop. It simply becomes harder to see.
A better approach is to create an environment where an employee can say, “I've found something useful and I want to try it,” without assuming that the immediate response will be a refusal. That does not mean removing security controls completely or allowing unrestricted experimentation but instead making the safe route practical, understandable and proportionate.
Not every experiment needs the same level of scrutiny. Trying a tool with public information is very different from giving an agent access to production systems, sensitive data or the authority to make decisions. Your process should absolutely reflect that difference.
Employees should understand what the organisation's AI policy means, which tools and use cases require approval, what information should not be put into an AI system and where to go for guidance. Just as importantly, they should understand that declaring an AI tool or agent starts a conversation rather than automatically ending an idea.
The aim is to build a culture where people feel comfortable putting their hand up early. When they do, you get something technology cannot reliably provide on its own: context. You can understand why the technology is being used, the problem it is solving and what someone is trying to achieve. That makes it easier to decide whether an experiment should be formalised, controlled more tightly or stopped.
Put a process in place to support openness
Culture creates the willingness to disclose information about AI agents, but a planned process turns that willingness into something your organisation can manage. The registration process for a new AI agent needs to be straightforward enough that employees and developers will actually use it.
This process has to support the culture you're trying to create. If every new idea faces the same lengthy approval route regardless of the risk involved, that approval route quickly becomes harder to use than it needs to be.
A practical approach should aim to establish:
- Who owns the agent
- What is it intended to do
- Which systems and tools can it access
- What data it handles
- How it authenticates
- How much autonomy it has
- What controls are available if something goes wrong
Our research suggests that this lifecycle discipline is missing in many organisations. Only 14% of organisations have formal onboarding, offboarding and periodic re-certification processes for every agent, while 36% describe their lifecycle processes as informal or evolving.
Governance still needs to be there, but it should match the risk of the use case. A routine assistant working with low-risk information can be managed differently from an agent handling sensitive data or taking a high-impact action, where stronger controls or human approval may be appropriate.
A further challenge is that agents change after deployment. Models can change, tools can be added, permissions can expand and new data sources can be connected as business requirements evolve.
As a result, the register needs to remain current, with onboarding, material changes, periodic review and retirement connected to the same governance process. When an agent is no longer required, its identity, permissions and integrations should be removed. The goal is to have a maintained view of your organisation’s AI estate that supports real security decisions.
The discovery problem is bigger than sanctioned AI
Traditional technology inventories are built around systems that organisations deliberately acquire, deploy and manage. But agentic AI can enter the environment through much less formal routes.
AI agents can emerge across the enterprise in more ways than organisations may realise, including:
- Sanctioned AI platforms: approved, deployed and managed by IT as part of the organisation’s formal technology estate.
- Embedded AI capabilities: introduced through existing business applications, where new functionality can appear without being treated as a separate agent.
- Internally developed agents: built by development or business teams to automate specific workflows, tasks or decisions.
- Consumer or third-party tools: adopted by employees to solve business problems, sometimes without formal approval or visibility from IT and security teams.
- Software updates: that introduce new AI functionality into existing platforms without anyone consciously deploying a new agent.
Each route creates a potential discovery gap, making it harder to know what is operating and what access or risk sits behind it.
At the same time, agentic AI can have considerably more operational reach than a conventional productivity tool. An agent may retrieve information, interact with APIs, call other tools or make changes within business systems, all at machine speed, turning an unknown AI capability into an unknown route into enterprise data and processes.
Use technology to find what people and processes miss
Even strong disclosure and governance processes will not capture everything in your AI estate. People forget to register tools, agents can be embedded within applications and software updates can introduce new AI functionality. This is where technology completes the picture.
In practice, there isn't one source of truth that will reveal your entire AI estate. You need to build the picture from several different sources. That might include identity and access systems, network monitoring, endpoint tools, browser telemetry, cloud and agent-platform inventories, application records and AI or MCP gateway logs.
The objective is to bring multiple signals into one operational view, allowing security teams to compare declared activity with observed activity and investigate any discrepancies.
Our research shows why this matters. Only 22% of organisations maintain a complete central repository, while 82% lack full organisation-wide real-time visibility. Technology can help close that gap by identifying activity that people and processes miss, validating what has been declared and providing evidence of how agents are actually operating.
Dedicated technology can add another layer. SailPoint Shadow AI Remediation, for example, provides real-time visibility and control over how employees use generative AI tools, alongside just-in-time remediation. That can help identify activity that hasn't been declared, but it still needs to sit alongside the right culture and processes, rather than replacing them.
This context matters because technical discovery can tell you what is happening, but not always why.
Better discovery creates room for more experimentation
The instinctive response to shadow AI is often to eliminate it, but that is increasingly difficult as AI becomes embedded in how people work and learn.
Eliminating experimentation shouldn't be the objective either. Much of the behaviour behind shadow AI is exactly what businesses say they want from their people: curiosity, innovation, greater productivity and finding smarter ways to work.
The organisation's job is to give that behaviour somewhere safe to go.
The answer is to make safe experimentation easier. This starts with people who feel comfortable declaring what they are using, continues with processes that make registration and assessment proportionate to risk, and is reinforced by technology that identifies activity outside those processes.
Get the culture and process right and identity security becomes an enabler rather than a blocker. People know where to take an idea, while the technical controls help you identify what still falls outside that route.
Download the 2027 State of Agentic AI Readiness report to explore the latest research into Agentic AI readiness across 300+ organisations in the US, UK and Europe and the practical foundations for bringing your agentic AI estate under control.
Frequently Asked Questions
People are often the first to know when a new AI tool or agent is being used, particularly when it has been introduced informally to solve a business problem. If employees expect security teams to block experimentation, they may be less likely to disclose what they are using. Creating a culture where people can raise new AI use cases openly gives organisations valuable context that technical monitoring alone cannot provide.
The priority should be to understand the use case before deciding what action to take. Organisations can identify the owner, purpose, data involved, systems accessed and level of autonomy, then apply a proportionate risk assessment. Where the agent is appropriate, it can be brought into the formal governance process; where risks cannot be addressed, access can be restricted or the agent retired. Treating discovery as the start of a conversation rather than an automatic enforcement action can also encourage future disclosure.
An agent inventory needs to be connected to the wider lifecycle rather than maintained as a standalone spreadsheet. New agents should be registered during onboarding, while changes to permissions, tools, data sources or purpose should trigger review. Identity, endpoint, network, cloud, application and gateway telemetry can then provide ongoing validation, helping organisations identify agents or AI activity that has not been declared and keeping the inventory aligned with the environment.