Shadow AI has two faces.
Everyone knows the first: employees quietly using AI tools IT never approved. The second is newer, faster, and more dangerous — ungoverned agents acting on your data and systems with valid identity and valid authorization at every single step. No runtime tool governs that. A governance layer does.
By Lindsay Hiebert · Founder · CISSP
Two faces, one blind spot.
Humans hiding usage
The employee pasting into ChatGPT, the team that adopted a tool without procurement, the embedded AI that switched on inside a SaaS app you already had. Real, widespread — and bounded by human speed and human intent.
Ungoverned agents
An agent acting on data, systems, and flows — often via MCP — with a valid credential and permitted actions at every step, but no named owner, no declared job, and no behavioral boundary. It operates at machine speed and can drift off its purpose one quiet tool call at a time. The 45,000-record export where every read was authorized. The agent that ran 41 access attempts after a single access-denied error.
This is not a new model — it is the sharp edge of the four layers of shadow AI. Face 2 turns layer 4 (agents acting outside your integrations) into a first-class governance problem: a non-human principal that demands greater precision, discipline, and vigilance than any human user.
The evidence, not the alarm.
of enterprise AI tools are unmanaged
Zluri, State of AI in the Workplace 2025
of employees admit to hiding their AI usage from IT
Cybernews 2025 AI Workplace Survey
of 2025 detections were malware-free — up from 51% in 2020 — attackers using valid credentials, not malware
CrowdStrike 2026 Global Threat Report
non-human identities (agents, keys, tokens) now outnumber human identities
Astrix Security, via the CIS Controls v8.1 MCP Companion Guide (2026)
Independent research, one conclusion.
One voice is dismissible. The same conclusion, reached independently from different directions, is a pattern a board should act on: govern the agent at the boundary, against its declared job — not by trusting who it claims to be or what it says.
Came from NIST SP 800-207 zero trust: govern the agent against its declared job, because identity and authorization cannot tell you if it is doing that job.
Came from its own incident logs containing the agents it builds: capable models find paths no rule anticipated, so contain and supervise at the boundary.
Codified it: the Agentic Trust Framework, the OWASP Top 10 for Agentic Applications, and NIST's Cyber AI Profile and control overlays all point to boundary-level, behavior-anchored governance.
What each role has to govern — and what SanctumShield hands them.
AI governance is a brand-new literacy, and almost no one — through no fault of their own — has been taught it yet. Two years ago none of this existed. That gap, not incompetence, is the real risk. Here is the question each role owns, and the artifact that answers it.
Can we prove we exercised due care on AI?
The Quarterly Agent Governance Report, the Board Memo, and an independently verifiable URL — evidence, not assurances.
Can we scale AI without losing customer, partner, and regulator trust?
A provable, not self-attested, governance posture — the artifact chain a serious buyer or underwriter will accept.
What agents exist, who owns each one, and is it acting in-spec?
The free calculator and network-log analysis to discover both faces; the AI Acceptable Use Policy (agentic §7, deployed-agent §14); the Agent AUP one-pager and the Vendor Trust Questionnaire.
What is our regulatory exposure, and where is the evidence?
A regulation-anchored AUP, a documented risk assessment, and a glossary that makes the domain legible — the record of due diligence, on file before the question is asked.
What am I allowed to use, and how do I ask?
The Coach and the Academy — plain-English AI-governance literacy, and an AUP they can actually acknowledge and follow.
How SanctumShield surfaces and proves it.
SanctumShield closes the due-care loop for organizations of 50 to 2,000 employees, across both faces:
- Discoverthe free calculator and network-log analysis surface both faces — hiding humans and ungoverned agents.
- Assessthe Executive Risk Report, regulation-anchored and board-ready.
- Establishthe AI Acceptable Use Policy — with agentic policy (§7) and deployed-agent policy (§14) — plus the free Agent AUP one-pager, Vendor Trust Questionnaire, and Quarterly Agent Governance Report templates.
- Provethe Board Memo and an independently verifiable URL an underwriter or board can confirm without a login.
- Understandthe Coach and the Academy — plain-English AI-governance literacy for every role.
One line matters most: SanctumShield enables and proves due care and due diligence. It does not certify you, guarantee an outcome, or replace your judgment — and it deliberately will not. The Coach will never tell you “you’re compliant.” That refusal is the point. You get the discovery, the artifacts, and the literacy to fulfill your responsibilities and to show your work — the standard is not “were you careful,” it is can you show it.
- Zluri, State of AI in the Workplace 2025 (80%+ AI tools unmanaged).
- Cybernews 2025 AI Workplace Survey (59% hide AI usage).
- CrowdStrike 2026 Global Threat Report (82% malware-free detections in 2025, up from 51% in 2020).
- Astrix Security, via the CIS Controls v8.1 MCP Companion Guide, CIS / Astrix / Cequence, April 2026 (non-human identities outnumber humans).
- Cunningham, C. Agentic Zero Trust v3.0, DrZeroTrust Research Division, May 2026. CSA Agentic Trust Framework (Feb 2026). OWASP Top 10 for Agentic Applications (2026). NIST IR 8596 Cyber AI Profile (draft, Dec 2025).
Educational content, not legal advice or a compliance certification.