Close Menu
NCIJ Network NCIJ Network
    What's Hot

    India’s ‘Cockroach’ Protesters Disperse, But Questions Remain on Education and Dissent

    July 27, 2026

    Ukraine dismisses Iranian threats as Caspian Sea strike directly links wars

    July 27, 2026

    Costco will take your old tech and gift you a gift card – here’s what to know

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • India’s ‘Cockroach’ Protesters Disperse, But Questions Remain on Education and Dissent
    • Ukraine dismisses Iranian threats as Caspian Sea strike directly links wars
    • Costco will take your old tech and gift you a gift card – here’s what to know
    • PTC Windchill Vulnerability Exploited in Ransomware Campaign
    • Bitmine Nears Goal of Controlling 5% of Ethereum Supply With $11.8 Billion Treasury
    • NASA to Cover Three US Spacewalks, Host Preview News Conference
    • Covid vaccines don’t raise your risk of miscarriage – Full Fact
    • Guyana Ferry Tragedy Exposes Political Rifts in Oil-Rich Country
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Shadow AI agents are multiplying. Here’s how to find and secure them.

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Your workforce is building agents in Salesforce Agentforce, Microsoft Copilot Studio, Cursor, Zapier, Retool, and a dozen other tools, often without visibility or approval from IT or security.

    For IT and security teams, the decision of whether or not agents should be used has already been made by the business, one shadow agent at a time. The challenge now is keeping up. New agents can be created in minutes, connected to sensitive systems in a click, and changed daily.

    The job is to maintain visibility and control (who built it, what it can access, what it can do) while enabling the workforce to keep experimenting, automating, and moving fast.

    That’s exactly what Nudge Security does.

    Why shadow AI agents are riskier than shadow AI apps

    AI chatbots are a known problem by now. Shadow AI agents are a different, and arguably bigger, one. An agent holds persistent permissions. It connects to your corporate apps and data. It takes action on its own, without waiting for someone to hit send.

    When an unmanaged agent goes wrong, the result isn’t a bad response in a chat window. It’s a system that got touched.

    The numbers back this up:

    • 48% of cybersecurity professionals rank agentic AI as the most dangerous attack vector of 2026 (Dark Reading).
    • 80% of organizations say they’ve already encountered agentic AI risks (SailPoint).
    • Only 21% of IT leaders say they have a mature agentic AI governance program in place (Deloitte).

    That gap between exposure and readiness is exactly where shadow AI agents live.

    Learn how each approach works, what it actually detects, and where the blind spots are, so you can build a discovery strategy that matches your real agent risk surface.

    As AI agents multiply across your stack, the gaps between methods are where risk hides.

    Read the Guide →

    Day One: Find shadow AI agents

    You can’t govern an agent you don’t know exists. Nudge Security gives you an immediate inventory of AI agents, across the most popular agentic platforms including Microsoft Copilot, Google Gemini, ChatGPT, Claude Managed Agents, Tines, ServiceNow, Salesforce Agentforce, Cursor Automations, and many more.

    No spreadsheets. No self-reporting. No waiting for an incident to find out what’s already running in your environment.

    See new AI agents as they are created with Nudge Security
    See new AI agents as they are created with Nudge Security

    Shadow AI agent discovery: How it works

    Most AI agent discovery methods have the same blind spot: they only see what agentic platform vendors choose to expose through a public API. That leaves out an enormous amount of shadow AI activity, because a lot of the platforms where employees build agents don’t offer an API, or don’t expose agent details through it.

    Nudge Security closes that gap with two complementary discovery methods:

    API-based discovery connects to the platforms that do expose agent data: Salesforce Agentforce, Microsoft Copilot Studio, Google Gemini, ServiceNow, n8n, Tines, ChatGPT, Abacus.AI, and Workato. It continuously pulls agent name, creator, creation date, status, configuration, and risk insights.

    Browser-based discovery, through the Nudge Security browser extension, covers the platforms that don’t expose an API at all: Cursor automations, OpenAI Agent Workflows, ChatGPT workspace agents, Zoom AI Workflows, Atlassian Rovo, Retool, Zapier Agents, and HyperAgent. The extension passively observes the moment an employee views, lists, or creates an agent, then adds it to your inventory automatically, with the creator, connected apps, permissions, and risk signals already attached.

    Between the two channels, Nudge Security covers 17+ agentic platforms today, and the list keeps growing based on where customers are actually seeing agent activity.

    AI agent inventory in Nudge Security
    AI agent inventory in Nudge Security

    Why browser-based shadow AI agent discovery matters

    The agents built on platforms without APIs aren’t a minor edge case. They’re often where the real shadow AI lives. These are the fast, low-friction tools your engineers, ops teams, and product managers already love, precisely because nobody has to ask IT for permission to use them.

    That’s also why they tend to carry the broadest access and the least oversight. An agent built in an afternoon to save someone twenty minutes can end up with standing access to a CRM, a code repository, or a shared drive, and no one outside the person who built it knows it’s there.

    Assess: know what each agent can actually do

    Finding an agent is only useful if you know what it’s capable of. For every agent it discovers, Nudge Security automatically surfaces these agentic AI risks:

    • Publicly accessible agents that anyone in the org can use
    • Agents with excessive, write, or destructive permissions
    • Hardcoded credentials or PII sitting in agent instructions
    • Unauthenticated MCP connections
    • Dormant agents that still retain active access
    • Agents whose creators have already left the organization
    Agentic AI risk findings in Nudge Security
    Agentic AI risk findings in Nudge Security

    Govern: close the loop without becoming the bottleneck

    Discovery tells you what’s out there. Governance is what you do about it, and Nudge Security is built so that step doesn’t require your team to chase down every agent creator one by one.

    Once an agent is in your inventory, you can:

    • Set an approval status: Approved, Allowed, In Review, or Not Permitted, for every agent in your environment.
    • Assign an owner. A technical contact who’s accountable going forward, which may or may not be the same person who originally built the agent.
    • Nudge the owner directly, through the browser extension, Slack, Teams, or email, to confirm intent, justify access, or fix a risky configuration. Their response is captured automatically in the agent record.

    It’s proactive AI governance that doesn’t ask you to play whack-a-mole with every new agent that pops up, and it doesn’t ask your workforce to slow down to get security’s blessing before they build something useful.

    Nudging a user to fix a risk finding with an AI agent they manage
    Nudging a user to fix a risk finding with an AI agent they manage

    The bottom line

    Your job isn’t to stop people from building agents. It’s to make sure that when they do, someone knows it happened, knows what the agent can touch, and can act fast if something looks wrong.

    Nudge Security gives you Day One AI agent discovery with risk context and governance workflows across the agentic platforms your employees are actually using.

    Ready to see the agents that are already running in your environment? Start a free 14-day trial.

    Sponsored and written by Nudge Security.

    Agents find Heres multiplying secure Shadow
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Costco will take your old tech and gift you a gift card – here’s what to know

    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    New GitHub, PyPI Policies Boost Supply Chain Security

    MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

    Here’s why India’s cockroach protests were such a success – and why the Mamdani effect means more to come | Mukul Kesavan

    Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    India’s ‘Cockroach’ Protesters Disperse, But Questions Remain on Education and Dissent

    July 27, 2026

    Ukraine dismisses Iranian threats as Caspian Sea strike directly links wars

    July 27, 2026

    Costco will take your old tech and gift you a gift card – here’s what to know

    July 27, 2026

    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    July 27, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    India’s ‘Cockroach’ Protesters Disperse, But Questions Remain on Education and Dissent

    July 27, 2026

    Ukraine dismisses Iranian threats as Caspian Sea strike directly links wars

    July 27, 2026

    Costco will take your old tech and gift you a gift card – here’s what to know

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.