What is shadow AI?
Shadow AI is any AI system running inside a business that IT never approved, deployed, or inventoried, including agents a vendor switched on inside software you already bought. Centurian finds them by reconciling activity signals against the registered-agent list, so discovery does not depend on anyone remembering to declare.
Three kinds, and the third is the one that hurts
Most shadow-AI writing describes employees pasting company data into a chatbot. That is real, and it is the easiest category to address, because it involves a person making a choice you can train against. The second category is engineer-built: models, scripts, and automations that work correctly and were simply never registered anywhere.
The third category is vendor-deployed, and it behaves differently from the other two. An agent arrives inside a product you already licensed, enabled by an update you did not review, doing work nobody in your business asked for. There is no adopter to train and no builder to remind. It shows up as activity with no owner. This is why 67% of CIOs report accountability for AI they do not control (IBM Institute for Business Value, 2026): the accountability arrived without the deployment decision.
Detection is reconciliation, not a survey
Asking each team what AI they run returns what they remember and chose to mention. It cannot return the vendor-deployed category at all, because the team never knew. A survey of a problem defined by what people do not know is structurally incapable of measuring it.
Reconciliation works instead. Pull activity signals from the platforms agents actually execute on, starting with AWS CloudTrail, and diff that against the registry of agents someone formally registered. What is active in the signal and missing from the registry is a shadow agent, established without anyone self-reporting. Notification routes to the team admin first and escalates to the org admin after seven days if it stays unaddressed. See AI agent inventory for how the two lists are built, and agentic sprawl for what happens when the gap between them keeps widening.
Quarantine beats blocking
The instinct on finding an unregistered agent is to kill it. That is usually wrong: the agent is often doing real work, and cutting it off breaks an operation nobody documented. Centurian quarantines on first sight instead. The agent keeps running under a restricted registration tier while its owner, access scope, and cost get established, and it earns its way up as those questions get answered. Trust is granted incrementally rather than assumed at deployment or withdrawn in a panic. Every action it took while quarantined still lands in the audit trail, so the period before it was known is still evidenced.
Why the deadline changes the math
EU AI Act high-risk obligations under Annex III apply from 2 December 2027, with Annex I products following on 2 August 2028, and Article 50 transparency obligations already in force. The relevant part for shadow AI is not the penalty. It is that record-keeping obligations attach to systems in scope, and a system nobody inventoried produced no records for the period it ran unobserved. Evidence cannot be generated retroactively for a window you did not instrument, which makes the discovery date, not the deadline, the thing that constrains you. See the EU AI Act dossier.
FAQ
First agent free, forever · No credit card