Skipping governance is expediency — and expediency is a boomerang. See what the law expects →
Shadow AI has two faces.
Everyone knows the first: employees quietly using AI tools IT never approved. The second is newer, faster, and more dangerous — ungoverned agents acting on your data and systems with valid identity and valid authorization at every single step. No runtime tool governs that. A governance layer does.
By Lindsay Hiebert · Founder · CISSP
Two faces, one blind spot.
Humans hiding usage
The employee pasting into ChatGPT, the team that adopted a tool without procurement, the embedded AI that switched on inside a SaaS app you already had. Real, widespread — and bounded by human speed and human intent.
Ungoverned agents
An agent acting on data, systems, and flows — often via MCP — with a valid credential and permitted actions at every step, but no named owner, no declared job, and no behavioral boundary. It operates at machine speed and can drift off its purpose one quiet tool call at a time. The mass export where every single read was authorized. The agent that answered one access-denied error with days of automated retries.
The blind spot is the same for both faces: valid access. One face is hidden by people who never asked; the other hides in plain sight — every credential checks out, every action is permitted, so every dashboard stays green. Your security stack was built to catch the unauthorized, and neither face is unauthorized. What’s missing isn’t a detection. It’s the governance record: what exists, who owns each one, and what it was hired to do.
Three questions tell you whether the blind spot is yours: Can you name every AI tool and agent operating on your data today? Can you name the person accountable for each one? Can you say, in writing, what each one is supposed to be doing? If any answer is no, the exposure isn’t hypothetical — it’s just unrecorded. And “unrecorded” is the one condition a board, an auditor, and an underwriter all treat the same way.
This is not a new model — it is the sharp edge of the four layers of shadow AI. Face 2 turns layer 4 (agents acting outside your integrations) into a first-class governance problem: a non-human principal that demands greater precision, discipline, and vigilance than any human user.
The evidence, not the alarm.
non-human identities (agents, keys, tokens) now outnumber human identities
Astrix Security, via the CIS Controls v8.1 MCP Companion Guide (2026)
of enterprise AI tools are unmanaged
Zluri, State of AI in the Workplace 2025
of employees admit to hiding their AI usage from IT
Cybernews 2025 AI Workplace Survey
of 2025 detections were malware-free — up from 51% in 2020 — attackers using valid credentials, not malware
CrowdStrike 2026 Global Threat Report
The non-human identities nobody inventories, and the human identities agents borrow and attackers replay.
Independent research, one conclusion.
One voice is dismissible. The same conclusion, reached independently from different directions, is a pattern a board should act on: govern the agent at the boundary, against its declared job — not by trusting who it claims to be or what it says.
Came from NIST SP 800-207 zero trust: govern the agent against its declared job, because identity and authorization cannot tell you if it is doing that job.
Came from its own incident logs containing the agents it builds: capable models find paths no rule anticipated, so contain and supervise at the boundary.
Codified it: the Agentic Trust Framework, the OWASP Top 10 for Agentic Applications, and NIST's Cyber AI Profile and control overlays all point to boundary-level, behavior-anchored governance.
What each role has to govern — and what SanctumShield hands them.
AI governance is a brand-new literacy, and almost no one — through no fault of their own — has been taught it yet. Two years ago none of this existed. That gap, not incompetence, is the real risk. Here is the question each role owns, and the artifact that answers it.
Can we prove we exercised due care on AI?
The Quarterly Agent Governance Report, the Board Memo, and an independently verifiable URL — evidence, not assurances.
Can we scale AI without losing customer, partner, and regulator trust?
A provable, not self-attested, governance posture — the artifact chain a serious buyer or underwriter will accept.
What agents exist, who owns each one, and is it acting in-spec?
The free calculator and network-log analysis to discover both faces; the AI Acceptable Use Policy (agentic §7, deployed-agent §14); the Agent AUP one-pager and the Vendor Trust Questionnaire.
What is our regulatory exposure, and where is the evidence?
A regulation-anchored AUP, an Executive Risk Report, and a glossary that makes the domain legible — the record of due diligence, on file before the question is asked.
What am I allowed to use, and how do I ask?
The Coach and the Academy — plain-English AI-governance literacy, and an AUP they can actually acknowledge and follow.
How SanctumShield surfaces and proves it.
SanctumShield closes the due-care loop for organizations of 50 to 2,000 employees, across both faces:
- Discoverthe free calculator and network-log analysis surface both faces — hiding humans and ungoverned agents.
- Assessthe Executive Risk Report, regulation-anchored and board-ready.
- Establishthe AI Acceptable Use Policy — with agentic policy (§7) and deployed-agent policy (§14) — plus the free Agent AUP one-pager, Vendor Trust Questionnaire, and Quarterly Agent Governance Report templates.
- Provethe Board Memo and an independently verifiable URL an underwriter or board can confirm without a login.
- Understandthe Coach and the Academy — plain-English AI-governance literacy for every role.
One line matters most: SanctumShield enables and proves due care and due diligence. It does not certify you, guarantee an outcome, or replace your judgment — and it deliberately will not. The Coach will never tell you “you’re compliant.” That refusal is the point. You get the discovery, the artifacts, and the literacy to fulfill your responsibilities and to show your work — the standard is not “were you careful,” it is can you show it.
- Zluri, State of AI in the Workplace 2025 (80%+ AI tools unmanaged).
- Cybernews 2025 AI Workplace Survey (59% hide AI usage).
- CrowdStrike 2026 Global Threat Report (82% malware-free detections in 2025, up from 51% in 2020).
- Astrix Security, via the CIS Controls v8.1 MCP Companion Guide, CIS / Astrix / Cequence, April 2026 (non-human identities outnumber humans).
- Cunningham, C. Agentic Zero Trust v3.0, DrZeroTrust Research Division, May 2026. CSA Agentic Trust Framework (Feb 2026). OWASP Top 10 for Agentic Applications (2026). NIST IR 8596 Cyber AI Profile (draft, Dec 2025).
Educational content, not legal advice or a compliance certification.