Your enterprise has more AI agents than employees. Most don’t have identities, owners, or audit trails. Agent identity is the reliability surface that everything else depends on — and the control plan
This is a sharp way to frame shadow agents. They feel like the next version of shadow IT because the risk is not just unsanctioned software. It is unsanctioned authority. I would separate discovery from control: inventory tells you what exists, but the harder question is which agent can still act after its purpose, owner or data boundary has changed.
Budget is definitely an aspect to focus the baselines on, appreciate the insights Souraya. There are other aspects too, like the security, guardrails, operations etc
This is a sharp way to frame shadow agents. They feel like the next version of shadow IT because the risk is not just unsanctioned software. It is unsanctioned authority. I would separate discovery from control: inventory tells you what exists, but the harder question is which agent can still act after its purpose, owner or data boundary has changed.
Budget is definitely an aspect to focus the baselines on, appreciate the insights Souraya. There are other aspects too, like the security, guardrails, operations etc
You will probably see both for a while until things converge into a manageable tooling that can support both humans and AI Agents