CertAI
Shadow AI and autonomous agents: the risk growing faster than governance
D

Domenico Ruggiano

updated on

AI Governance

Shadow AI and autonomous agents: the risk growing faster than governance

There is a question that puts almost every management team on the spot: how many artificial intelligence tools are used in your company today? Not the IT-approved ones: all of them. The sales rep uploading the customer list to a chatbot to draft emails. The developer pasting proprietary code into a free assistant. The SaaS tool that switched on an AI agent with an update nobody asked for.

If the answer is "we don't know exactly", you're in good company: only a quarter of organisations report full visibility into how employees use AI. This is the shadow AI phenomenon, and in 2026 it has changed nature.

In short
Shadow AI is the use of artificial intelligence tools outside the company's control and approval.
With autonomous agents the phenomenon changes scale: no longer a person pasting text into a chatbot, but software that accesses data and systems and acts autonomously, continuously.
Gartner estimates that 40% of enterprise applications will embed AI agents by the end of 2026 (under 5% in 2025); only around 10% of large companies have a strategy to govern them.
Breaches involving shadow AI cost on average hundreds of thousands of euros more than an ordinary incident.
The answer is not banning, but governing: inventory, policy, access controls and a structured management system.

#From shadow IT to shadow AI

The phenomenon isn't new: it was called shadow IT when teams activated SaaS tools on the company credit card, bypassing IT. Shadow AI is its evolution, with two aggravating factors.

First: the barrier to entry is zero. Nothing to install, a browser is enough. Any employee can hand company data to an external model in ten seconds, often in good faith and trying to work better.

Second: the data leaves and doesn't come back. A confidential document pasted into a consumer tool can end up in the provider's logs, in training data, or simply outside any contractual perimeter. With unapproved tools there is no DPA, no control, no audit trail.

#The step change: autonomous agents

In 2025 the typical problem was a person pasting text into a chatbot: a single interaction, with a human in the middle. In 2026 the problem is agents: AI systems that receive a goal and act on their own. They read data, call APIs, execute chained actions across multiple systems, continuously and without step-by-step human review.

The numbers show the scale of the jump. Gartner predicts that by the end of 2026 40% of enterprise applications will embed task-specific AI agents, against under 5% in 2025. Most large companies already run active agents, often built with low-code tools by business teams. Yet only about one company in ten has a clear strategy to manage them.

The risk changes nature, because AI risk concentrates at the integration points: which APIs the agent can reach, what data scope it sees, which actions it can trigger without approval. A misconfigured agent is not a distracted employee: it is a process repeating the mistake twenty-four hours a day, at machine speed.

And agentic shadow AI is the worst of both worlds: autonomous agents nobody has inventoried, with access nobody has reviewed.

#What it costs

Research on data breach costs is consistent: about one organisation in five has suffered an incident involving shadow AI, and these incidents cost on average several hundred thousand euros more than comparable breaches, because the uninventoried tool has no logging, no contracts, and gets discovered late.

Add the regulatory front: with the AI Act in its operational phase, transparency and AI literacy obligations also apply to the tools the company "doesn't know" it uses (see our AI Act deadlines guide). The AI Act compliance perimeter is defined by an inventory, and shadow AI is, by definition, what the inventory is missing.

#Banning doesn't work. Governing does

The instinctive reaction, blocking everything, is the worst strategy: shadow AI arises precisely where a ban meets a real productivity need. Blocking pushes usage onto personal devices, where visibility is zero.

The approach that works is bringing the phenomenon into the light:

  1. An honest inventory. Map every AI tool and agent in use: approved, tolerated and submerged. Internal surveys, network traffic analysis, a sweep of active SaaS (many ship AI features enabled by default).
  2. A clear, useful usage policy. What is allowed, with which data, on which tools, plus an approved alternative for the most requested use cases. A policy that only says "no" will be ignored.
  3. Controls on agent access. Every agent has an identity, least-privilege permissions, action logs. No "superuser" agent wired to everything.
  4. Training (which is also an obligation). The AI literacy required by the AI Act is the chance to explain why certain uses are risky, not just that they are forbidden.
  5. A management system holding it all together. Inventory, risk assessment, controls and monitoring not as a one-off initiative but as a process: exactly what ISO/IEC 42001 structures (see our ISO/IEC 42001 guide), covering procured and integrated third-party AI too.

Where to start in practice, with which roles and responsibilities, is what we cover in the next article of this series (see our article on getting started with AI governance).

#How CertAI helps

CertAI starts exactly here: inventory and classification of AI systems (including the submerged ones), risk assessment, policies and controls, through to AI Act compliance and certifiable standards such as ISO/IEC 42001.

Not sure how many AI tools are really running in your company? CertAI helps you map and govern them.

Book a demo

Main sources: Gartner forecasts on AI agents in enterprise applications (2025–2026); IAPP AI Governance Profession Report; industry research on the cost of breaches involving shadow AI (including IBM Cost of a Data Breach). Last updated: July 2026.