Your Company Has Shadow AI Agents. Here's How Many You Don't Know About
A new CSA and Token Security survey finds 68% of organizations feel confident in their AI agent visibility, yet 82% discovered an agent security or IT never knew about in the past year, and 65% had an actual agent security incident. Here's the gap.

The Confidence Gap: Everyone Feels Visible. Almost Nobody Actually Is.
Ask most security or IT leaders whether they know what AI agents are running across their company, and the answer is confident. According to Autonomous but Not Controlled, a new survey report from the Cloud Security Alliance (CSA) and Token Security covered in CSA's own analysis of the findings, 68 percent of organizations say they have high visibility into their AI agents and autonomous workflows.
Here's the problem: in the past year, 82 percent of those same organizations discovered at least one AI agent or workflow that security or IT didn't previously know existed. And 65 percent had an actual AI agent security incident in the past twelve months — every single one of which reported real business impact, most commonly data exposure. Confidence and reality are pointing in opposite directions.
Visibility Isn't the Same Thing as Assurance
CSA's analysis draws a distinction worth sitting with: operational visibility versus assurance-grade oversight. Operational visibility just means a team has a reasonable sense of what's running — enough to support day-to-day deployment and troubleshooting. Assurance-grade oversight is a much higher bar: confidence that every agent, authorized or not, is identified, scoped, and subject to an actual control pathway.
That distinction matters because modern AI agent governance increasingly relies on bounded autonomy — letting agents operate inside defined limits and stepping in only when risk increases. That model only works if the agent is known about in the first place. An unknown agent doesn't respect a governance diagram just because one exists.
Where Shadow Agents Actually Come From
The report's most useful finding isn't that shadow agents exist — it's where they're showing up, and it's not some obscure corner of the company. The most common sources CSA identified:
- Internal automation or scripting environments
- LLM platforms, including custom tools, assistants, and plugins
- SaaS tools with built-in automation features
- Developer-created workflows
These are exactly the environments built for speed and decentralized problem-solving — the same places that produce legitimate, valuable automation. An agent doesn't need a formal procurement process to start making decisions; it can arrive as a plugin, a no-code workflow, or a quick internal script that quietly gains access to several systems.
Why "Mostly Visible" Is a Governance Failure Waiting to Happen
CSA lays out the downstream cost of incomplete visibility plainly. When an agent isn't known:
- Approval pathways weaken — security can't define when an agent needs human sign-off if it doesn't know the agent exists.
- Least-privilege decisions break down — unknown agents can inherit permissions through existing tools or service accounts.
- Incident response gets harder — when something behaves unexpectedly, responders need to know what triggered it and who owns it.
- Nothing gets retired — an agent that was never formally onboarded is unlikely to ever be formally decommissioned.
Unlike a static piece of infrastructure, the report notes, an AI agent can evolve through updates or prompt changes, expand scope through new integrations, and act at machine speed without continuous human review. "Mostly visible" compounds risk in a way a forgotten spreadsheet macro never did.
What CSA Recommends Doing About It
The report doesn't call for shutting down the experimentation that produces shadow agents in the first place — that same environment produces real business value. Instead, its practical shifts are:
- Treat AI agent visibility as an ongoing governance capability, not a one-time asset inventory.
- Expand onboarding expectations beyond traditional software — a new automation or custom assistant should trigger ownership and permission review, same as any other system.
- Focus governance on where agents can emerge (automation platforms, LLM tools, SaaS ecosystems), not just where they're formally approved.
- Define expected agent behavior and boundaries before exceptions occur, so exception-based governance actually has something to check against.
- Close the loop between visibility and lifecycle management — an org that can't discover agents at creation will struggle even more to retire them later.
What This Means for Any Team Rolling Out Agents on Purpose
The gap here isn't really about shadow IT in the old sense — it's misplaced confidence. Organizations that report high visibility (68 percent) at the same time as high rates of discovering unknown agents (82 percent) aren't lying to the survey; they're describing two different bars for "knowing what's running," and only one of them is good enough for real governance. For any team deploying agents deliberately, the practical takeaway is to build the ownership, permission review, and approval pathway into the rollout from day one, rather than assuming visibility will hold up on its own once an agent is live.
Frequently Asked Questions
How common are shadow AI agents in a typical organization? Very common. CSA and Token Security's survey found 82 percent of organizations discovered at least one AI agent or workflow that security or IT didn't previously know about, in just the past year.
Does having AI agent security incidents mean a company has bad security overall? Not necessarily unusual — the same survey found 65 percent of organizations had an AI agent security incident in the past year, with data exposure the most common impact, suggesting this is a widespread industry-level gap rather than an isolated failure.
What's the difference between "visibility" and "assurance" in AI agent governance? Visibility means a team has a general sense of what agents are running. Assurance means every agent, authorized or not, is identified, scoped, and subject to an actual control pathway — CSA's research shows most organizations have the former without the latter.
Workmate
See what an agent team would do for your business.
Keep reading

AI Agents for Healthcare Teams: Scheduling, Billing, and Follow-Up Care
Half of US healthcare orgs have now implemented gen AI, and agentic AI is next in line for the scheduling, billing, and follow-up work that's been stuck in staffing shortages for years. Here's what McKinsey's own late-2025 survey data shows is actually working.

AI Agents for Retail Teams: Inventory, Customer Service, and Order Management
86% of retailers already have AI governance policies in place, per NRF's 2025 survey of 56 AI leaders, and shoppers are already bringing their own AI assistants into the buying journey. Here's where retail AI agents are delivering results today, and where it's still early.

AI Agents for Legal Teams: Faster Contracts, Research, and Client Intake
79% of legal professionals already use AI, and agentic AI is the next wave, per Clio's 2025 Legal Trends Report and the Thomson Reuters Institute. Here's how firms are automating contracts, research, and intake, and what's still holding agentic AI back.