[ DISCOVERY / SHADOW_AI ]

What is shadow AI?

Shadow AI is any AI system running inside a business that IT never approved, deployed, or inventoried, including agents a vendor switched on inside software you already bought. Centurian finds them by reconciling activity signals against the registered-agent list, so discovery does not depend on anyone remembering to declare.

Three kinds, and the third is the one that hurts

Most shadow-AI writing describes employees pasting company data into a chatbot. That is real, and it is the easiest category to address, because it involves a person making a choice you can train against. The second category is engineer-built: models, scripts, and automations that work correctly and were simply never registered anywhere.

The third category is vendor-deployed, and it behaves differently from the other two. An agent arrives inside a product you already licensed, enabled by an update you did not review, doing work nobody in your business asked for. There is no adopter to train and no builder to remind. It shows up as activity with no owner. This is why 67% of CIOs report accountability for AI they do not control (IBM Institute for Business Value, 2026): the accountability arrived without the deployment decision.

Detection is reconciliation, not a survey

Asking each team what AI they run returns what they remember and chose to mention. It cannot return the vendor-deployed category at all, because the team never knew. A survey of a problem defined by what people do not know is structurally incapable of measuring it.

Reconciliation works instead. Pull activity signals from the platforms agents actually execute on, starting with AWS CloudTrail, and diff that against the registry of agents someone formally registered. What is active in the signal and missing from the registry is a shadow agent, established without anyone self-reporting. Notification routes to the team admin first and escalates to the org admin after seven days if it stays unaddressed. See AI agent inventory for how the two lists are built, and agentic sprawl for what happens when the gap between them keeps widening.

Quarantine beats blocking

The instinct on finding an unregistered agent is to kill it. That is usually wrong: the agent is often doing real work, and cutting it off breaks an operation nobody documented. Centurian quarantines on first sight instead. The agent keeps running under a restricted registration tier while its owner, access scope, and cost get established, and it earns its way up as those questions get answered. Trust is granted incrementally rather than assumed at deployment or withdrawn in a panic. Every action it took while quarantined still lands in the audit trail, so the period before it was known is still evidenced.

Why the deadline changes the math

EU AI Act high-risk obligations under Annex III apply from 2 December 2027, with Annex I products following on 2 August 2028, and Article 50 transparency obligations already in force. The relevant part for shadow AI is not the penalty. It is that record-keeping obligations attach to systems in scope, and a system nobody inventoried produced no records for the period it ran unobserved. Evidence cannot be generated retroactively for a window you did not instrument, which makes the discovery date, not the deadline, the thing that constrains you. See the EU AI Act dossier.

FAQ

What is shadow AI?

+
Shadow AI is any AI system running inside a business that IT never approved, deployed, or inventoried. It covers three distinct things: tools employees adopt on their own, models and scripts engineers build without registering, and agents a vendor switched on inside software the business already bought. The third category is the one most organizations miss entirely, because nobody chose to deploy it.

What is an example of shadow AI?

+
A freight brokerage buys a transport management system. The vendor ships an update that enables an automated rate-quoting agent by default. That agent now reads customer contract data and sends quotes under the company's name, and it appears on no inventory, has no named owner, and produces no audit trail. Nobody in the business made a decision to deploy it, so nobody thinks of it as theirs to govern.

What are the risks of shadow AI?

+
Four, in the order they usually bite. Data exposure, because an unregistered agent's access scope was never reviewed. Unattributed cost, because its spend lands in a shared bill with no owner. Regulatory exposure, because the EU AI Act's high-risk obligations from 2 December 2027 assume you can produce records for every system in scope. And unexplainable incidents: when something goes wrong and no one can name the agent's owner, the investigation stalls before it starts.

How do you detect shadow AI?

+
By reconciliation, not by survey. Asking teams what they run finds only what they remember and chose. Detection works by pulling activity signals from the platforms agents actually run on, starting with AWS CloudTrail, and comparing that list against the registry of agents someone formally registered. Anything present in the signal and absent from the registry is a shadow agent by definition, and no self-reporting was required to find it.

How do you prevent shadow AI?

+
You cannot prevent it, and treating it as preventable is why it accumulates. Vendors will keep enabling agents inside products you already own, and that decision is not yours to block. What is controllable is the gap between an agent starting work and someone knowing it exists. Centurian quarantines unknown agents on first sight rather than blocking them outright, so the agent keeps working while its owner, scope, and cost get established.

How do you discover shadow AI across an enterprise?

+
The discovery has to be cross-vendor to be worth running. A hyperscaler's native agent registry sees only agents built on its own platform, which means a scan that comes back clean can still miss every agent running somewhere else. Centurian registers agents from Salesforce Agentforce, AWS Bedrock, Microsoft Foundry, Google Vertex, Copilot Studio, and custom code through one MCP front door, so the inventory is one list rather than one list per vendor.

What are shadow AI management best practices?

+
Inventory before policy. A rule you cannot enforce against an agent you cannot see is documentation, not governance. Then give every agent an owner and a credential that expires, so trust has to be renewed rather than assumed. Then attribute cost per agent, because an unowned line item is how a shadow agent survives a budget review. Write the evidence down as you go: a report covering a period you did not instrument cannot be produced retroactively.
Get early access →

First agent free, forever · No credit card