Shadow AI Agents Are the New Shadow IT, and Most Businesses Aren't Tracking Them
AI agents, autonomous software tools that can complete tasks and even spawn their own sub-agents, are spreading through businesses faster than most security teams can track. Unlike traditional software, these agents behave unpredictably and can take actions their creators never intended, from writing critical content unprompted to bypassing access controls on other systems entirely.
According to IBM's 2026 Cost of a Data Breach report, 68 percent of organisations now lack proper governance to manage AI or detect unauthorised (shadow) AI use, up from 63 percent the previous year. At the same time, fewer businesses are requiring IT approval before deploying AI tools, down to 38 percent from 45 percent. Security vendor DigiCert argues this is because the appeal of AI's capabilities is pushing organisations to adopt it quickly, often at the expense of basic controls.
DigiCert has proposed a governance framework called AI Trust, which uses identity and encryption tools to help businesses answer key questions: what sensitive data agents can access, whether a compromised agent can be shut down quickly, and whether incidents can be traced afterwards. The company notes that many organisations fail at the first step, since employees and developers often deploy agents, or let agents create further sub-agents, without any central visibility or approval.