Unauthorized AI agents are now running inside corporate networks with little to no visibility from IT teams, creating a security gap that exceeds the traditional shadow IT problem by orders of magnitude, according to a new analysis published by CIO.com. While shadow IT tools primarily accessed or handled data without proper authorization, these agents can act on that data by pulling records, sending messages, and making changes with minimal oversight. The report warns that most companies currently have no way to see or control this emerging threat.

The analysis describes a scenario where a marketing executive activates an agent from Marketo without informing their IT team, giving that shadow agent access to customer data with little oversight and no clear adherence to company security or compliance policies. When multiplied across every department, plus agents that vendors in HR, finance, and other areas run inside company systems, the situation escalates to hundreds of vendors each running multiple agents, moving between the company, their own operations, and the supply chain. This creates thousands of agents with no consistent tracking mechanism. Microsoft data cited in the report shows AI-generated phishing is now three times more effective than traditional campaigns, a dramatic shift from just a year ago when AI-written phishing attempts were easy to spot due to poor grammar or strange tone.

When asked if they maintain a robust inventory of agents operating on their network, most companies answer no, the report states. Even if a company scanned its network, the analysis notes it's unclear whether agents are what they claim to be, leaving an unknown number of agents from unverified sources performing numerous tasks and data exchanges on company networks. The report emphasizes that security teams often say you can't protect what you can't see, a principle that was true when the invisible thing was a spreadsheet but reaches another level when an agent has login credentials and knows what to do with them. According to the analysis, the issue becomes even more complex if the agent originates from a known AI company but acts on behalf of an untrusted or unknown user, such as a ChatGPT agent receiving instructions from a criminal.

The report proposes applying the DMARC model that solved email authentication a decade ago, now used across roughly 1 million domains, to verify agents before they gain system access. An agent claiming to represent Salesforce or any vendor can be checked against that company's DNS-secured record before access is granted, answering whether the agent is who it says it is and whether the company it claims to represent actually authorized it. The analysis recommends a layered approach with zero trust upfront, similar to a bouncer at a nightclub who checks a finite short list rather than trying to identify every possible person, followed by deeper inspection of what remains. The report distinguishes between identity verification—confirming who an agent is—and permission management—determining what it's allowed to do, comparing these to a passport and visa issued by different authorities for different reasons. For the marketer turning on the Marketo agent, what would catch it isn't a smarter firewall or a longer policy document but a verification check run before access is granted, confirming the agent is who it claims to be and that someone actually authorized it, followed by continuous permissioning and logging. The fundamental shift, according to the analysis, is to verify an agent's identity before it gets anywhere near the door, applying a fix that email already proved works at scale rather than inventing something new for what is essentially the same problem in a different form. As AI deception capabilities improve exponentially—a progression human brains struggle to grasp—the combination of better impersonation and expanded access creates a threat that grows faster than organizations can anticipate. The industry learned from shadow IT that securing what you don't know is running inside your systems is impossible, and shadow agents are now teaching that lesson again with considerably higher stakes.