Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Not reliably, unless you maintain an inventory that records who owns each agent, what data it can reach, and what it is allowed to do. The difficulty is not that employees use AI. It is that agents can appear inside approved software, on public platforms, or in something an employee assembled over a weekend, and none of those routes automatically puts the agent on anyone’s list. Gartner’s 2026 polling found that 59% of senior cybersecurity professionals suspected or had evidence of unsanctioned employee use of AI. The practical question for leaders is therefore less “is this AI?” and more “who owns it, what can it reach, and what can it do without a person reviewing it?”

What “shadow AI” covers when agents are involved

Microsoft Learn defines shadow AI by governance status rather than by how novel the technology is. It covers two things: unsanctioned AI tools that employees adopt on their own, and unmanaged agents deployed in the organization’s environment that are not registered, owned, or governed by policy. An agent that a team has carefully built can still be shadow AI if nobody in the organization knows it exists, who maintains it, or what it touches.

Unsanctioned tools

These are AI services that staff use outside approved procurement and security review. The concern is data movement. Microsoft’s description notes that unsanctioned tools can move corporate data into services that were never reviewed, so the exposure sits in the data path, not in the tool’s cleverness.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unmanaged agents

An agent is different from a chatbot because it can retrieve information, take steps across systems, and sometimes act on the result. Microsoft’s Cloud Adoption Framework describes agents as able to access data, make decisions, and take actions across business systems using delegated authority. When such an agent has no registered owner, it can escape central audit and central blocking. That is the core governance gap: not that the agent exists, but that nobody can answer for it.

How agents actually appear

Gartner’s analyst Jeremy D’Hoinne, Vice President Analyst, describes three routes: “These shadow AI agents take multiple forms: embedded in existing enterprise software, consumed directly from the Internet or created by employees leveraging recent technological progress and “vibe coding” to improve productivity.”

  • Embedded agents switch on inside enterprise applications the company already licenses, sometimes through a feature update rather than a purchase decision.
  • Consumed agents come from public software-as-a-service agent platforms that an employee signs up for with a work email.
  • Employee-built agents are created with low-code tools or by describing a task to a coding assistant, then connected to email, files, or internal systems.

Why the visibility gap matters

Each unknown agent creates four separate blind spots, and they compound. Leaders cannot see what data the agent reads or sends externally, what actions it takes, whether anyone’s activity is logged, or how to stop it quickly when something goes wrong. Missing ownership is the root of all four: without an accountable owner, there is no one to answer an audit question, approve a change, or decide on decommissioning.

The ICO’s guidance on agentic AI makes the same point from a privacy angle. It notes that staff experimentation with agents may quickly lead to personal information being processed in ways nobody anticipated, and it identifies broad access to organizational personal information and reliance on external sources as conditions that make oversight harder.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the published figures do and do not show

The following figures come from Gartner’s 30 September 2026 article. Gartner presents them as its own findings or polling. The article text available for this review does not show the survey methods, sample sizes, or question wording, so treat each figure as a reported result for the respondents Gartner surveyed rather than as a universal prevalence estimate.

Reported finding (Gartner, 2026) Figure
Organizations reporting unauthorized use of AI coding assistants 75%
Organizations reporting employee access to public SaaS generative-AI agent platforms 50%
Senior cybersecurity professionals who had observed AI-agent automation in approved enterprise software 61%
Senior cybersecurity professionals who suspected or had evidence of unsanctioned employee use 59%
Average share of standalone generative-AI prototypes that reached production (Gartner polling) 41%

Read together, the first four rows show that agents are arriving through approved software and personal accounts alike. The last row is relevant to planning: most prototypes do not reach production, which means many agents live in an unmanaged middle state for some time before they are either retired or promoted.

Personal data: why experiments can become compliance questions

The UK Information Commissioner’s Office states that existing data-protection obligations apply to organizations deploying autonomous agents. Its guidance points to two mitigations: decision-making that is documented, readable, and verifiable, and governance parameters that limit what an agent may do. It also flags that multi-agent systems can compound privacy, accountability, accuracy, and security problems, because each agent’s output becomes another agent’s input.

The guidance does not say that any particular employee agent is unlawful, and it is not a new law. Whether a specific deployment complies depends on jurisdiction and facts that require a separate legal analysis. What it does establish is that a team’s experiment is a processing activity, and a register is the first place where that processing becomes visible enough to assess.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A baseline every agent should meet

Microsoft’s Cloud Adoption Framework recommends a centralized, enforceable governance and security baseline rather than case-by-case rules. Its domains are control-plane governance (ownership, identity, lifecycle, and observability), data governance and compliance, security, and development standards. It also recommends one organizational inventory that records ownership, purpose, platform, and access scope for each agent. This is vendor guidance rather than a legal requirement, but its structure is a practical template for any organization.

In practice, the baseline translates into the following checks for every agent, whatever its risk level:

  • A named, accountable owner and a stated business purpose.
  • The platform it runs on and whether that platform is approved.
  • A distinct identity for the agent, with permissions bounded to its task.
  • The data sources and system connections it uses, including any external services.
  • A lifecycle status: pilot, active, under review, or retired, with a decommissioning path.
  • Activity logging and a way for a human to pause or stop it.
  • A named contact for incident response if the agent misbehaves.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prioritize reviews by data sensitivity and autonomy

Not every agent needs identical scrutiny. A note-summarizing tool that works on public documents does not warrant the same review as an agent that reads customer records and sends emails. Two axes do most of the sorting: how sensitive the data the agent can access or transmit is, and how much the agent can do without a person approving each step.

Tier Typical profile Review depth
Lower Drafts or retrieves public or non-sensitive content; no write access; no external transmission Registry entry, owner, purpose, and standard logging
Moderate Reads internal business documents or systems; can draft or route items, but a person approves outputs Full baseline, scoped permissions, periodic access review
Higher Reads personal or confidential data, connects to external services, or can change records or trigger actions across systems Full baseline, documented decision logic, human intervention points, incident-response test before expansion

Use these questions to place an agent in a tier:

  • Data: Which classes of information can it read, transform, or send outside the organization?
  • Action: Can it only draft or retrieve, or can it change records and execute steps across systems?
  • Identity: Does it have its own accountable identity, and are its permissions narrowly bounded?
  • Ownership: Who maintains it, and who decides when it is retired?
  • Oversight: Are its activity and decisions monitored, and can a person intervene?

Make disclosure safe before enforcing rules

Australia’s National AI Centre defines shadow AI as workplace AI use outside official policy or an approved approach. Its advice starts with making disclosure safe: staff should be able to say they built or use an agent without fear of automatic punishment. The Centre also suggests treating shadow use as a possible signal of unmet need, time pressure, or curiosity. If employees are routing around official tools, the approved option may be too slow, too hard to find, or missing a capability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That framing matters for discovery. An employee who fears blame will hide an agent, and a hidden agent is the worst outcome for the registry. Pair disclosure with clear acceptable-use guidance that explains which tools are approved, for what kinds of data, and when an agent needs review, along with training that matches the business and industry context.

A starter plan for the first quarter

  1. Open a disclosure route. Publish a simple way to report an agent, its purpose, and the work it serves. Publish the approved options and acceptable-use guidance alongside it.
  2. Create one registry. Record owner, purpose, platform, data access, system connections, and lifecycle status for each agent. Start with the four fields in Microsoft’s inventory guidance: ownership, purpose, platform, and access scope.
  3. Apply the baseline to every entry. Confirm identity, lifecycle, data access, security settings, monitoring, and an incident-response contact, even for low-risk agents.
  4. Review the higher tier first. Start with agents that touch sensitive data, hold broad permissions, connect to external services, or act with high autonomy.
  5. Pilot new agents narrowly. Follow the approach in the Australian government’s joint cybersecurity guidance announced on 1 May 2026: begin with low-risk tasks, use strict privilege controls, monitor continuously, keep strong identity management, and retain human oversight. Expand only when controls and evidence support it.
  6. Fix the routes that drive shadow use. When employees find a workaround, ask what the approved tool lacked, and close that gap where the business case justifies it.

This sequence is a synthesis of the cited guidance. It is not a claim that every listed control is legally mandatory in every jurisdiction.

What remains uncertain

  • No independently verified count of agents inside a given organization is available. The figures above describe survey respondents, not individual companies.
  • The guidance cited here does not establish a universal legal requirement for a particular registry design, so the structure you choose should follow your own regulatory obligations.
  • The capabilities described in Microsoft’s materials are vendor descriptions of its products and framework, not independent validation.

“

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.