Most AI governance programs begin with an inventory. Which agents do we have, who owns them, what can they touch?
It's the right first step. It also tends to produce a reassuring list of the agents the organization already knew about: the ones a team registered, the ones a platform vendor shipped, the ones that went through review.
The agents that matter most are usually not on it.
Where the other agents come from
They arrive the way most shadow technology arrives: because someone had a problem and the sanctioned route was slower.
- An employee installs an open-source personal agent on a work laptop with a single command and gives it access to email and calendar.
- A developer adds a model provider's SDK to a script, and it quietly becomes part of a nightly job.
- Someone creates an API key on a personal card to try something over a weekend, and the experiment becomes a workflow.
- A SaaS application ships an agent feature, switched on by default.
- A team builds a helpful assistant in a no-code tool, connects it to a shared drive, and shares it with the department.
None of these people are acting in bad faith. Most of them are doing exactly what their organization asked for: finding ways to use AI. The result is still a population of agents with real access to real data, and nobody accountable for what they do.
The cost is measurable. IBM's 2025 Cost of a Data Breach report found that shadow AI added about $670,000 to the average cost of a breach, and that 63% of the organizations it studied had no AI governance policies in place to manage AI or prevent shadow AI.
The signals already exist
The good news is that most organizations already collect evidence of these agents. It's just scattered.
Code scanning tools can see when a repository imports a model provider's library. Secrets and identity systems can see when credentials to AI services are created. Network tools can see traffic to model endpoints. Endpoint security can see new agent software on laptops. SaaS admin consoles can see which AI features are switched on.
No single tool sees all five, and that's fine. The problem is where the signal goes. Today, a discovered agent usually lands in a security console as a finding. Someone may close the ticket. Rarely does the discovery turn into what actually matters: an owner, a purpose, a set of boundaries and a record, or a deliberate decision to retire it.
Discovery without a path to governance is just a longer list of worries.
Banning doesn't work. A faster sanctioned path does.
The instinctive response to shadow agents is to block them. It rarely lasts. People found the unsanctioned route because it was faster, and blocking it doesn't make the sanctioned route any quicker. The work moves somewhere less visible.
The more durable answer is to make the governed path the easier one. If registering an agent, giving it an owner and setting its boundaries takes an afternoon rather than a quarter, most people will choose it. If bringing an existing agent under governance means wrapping what already works rather than rebuilding it, teams will do it willingly.
The goal isn't fewer agents. It's no agents without an owner.
The industry needs a common language for discovery
Other kinds of operational data went through this same fragmentation, and the answer each time was an open standard. Observability converged on OpenTelemetry. Security events have OCSF. Once there was a common format, every tool that produced the data could feed every tool that used it, and buyers stopped paying for custom integrations.
Agent discovery needs the same thing: a shared way to say "this agent exists, here is what it touches, here is who found it and when," so any discovery tool can hand its findings to any governance process.
Until that exists, buyers can speed it up with two questions:
- To your security vendors: can you export the AI agents and AI usage you detect, in an open format, to a destination we control?
- To anyone selling you agent governance: can you take in discovery findings from the tools we already own, and turn each one into a governed agent or a retirement decision?
Three questions for the leadership team
- How many AI agents are running in our organization today?
- How do we know?
- What happens in the hour after we find one we didn't know about?
If the third answer is "a ticket is opened," you have discovery. If it's "it gets an owner, boundaries and a record, or it's switched off," you have governance.
In the final article of this series: why so many AI platforms that win the demo lose in procurement.