The First Control Is Visibility

The phrase "shadow AI" can sound like a technology category. In practice, the more useful question is operational: can the organization identify the software actor that is doing work? NIST's February 2026 announcement on software-agent identity and authority focuses on the risks created when agents receive access to data, tools, and applications. [1] That makes discovery the first control. You cannot make a sound access decision for an actor that does not appear in the inventory.

Identity Is the Bridge Between the Agent and the Business

A workforce agent exists because someone wanted a business task completed. That human intent should remain visible after the agent starts operating. CyberArk's 2026 analysis argues that risk sits not only in the model but also in the identities and privileges used to configure and operate it. [2] The practical response is to preserve a chain of accountability: a human sponsor, a defined purpose, an agent or workload identity, approved access, and a lifecycle decision.

Discovery Has to Reach the Places Agents Actually Appear

Agents can be created inside SaaS products, cloud platforms, developer tools, browsers, low-code environments, and local endpoints. That distribution makes a single API inventory incomplete in many environments. Nudge Security's May 2026 announcement describes its own browser-based approach to finding agents that are not fully exposed through public APIs. [5] The vendor claim is not evidence that every organization needs the same product. It does illustrate the underlying design requirement: discovery should cover the paths through which agents are actually created and used.

Ownership Turns Discovery Into Governance

Finding an agent without naming an owner produces a new backlog, not a new control. SailPoint's March 2026 agent-identity guidance emphasizes aggregation, ownership, access certification, least privilege, and lifecycle management. [3] The operating principle is simple: every agent with meaningful access should have a person who can explain its purpose, approve its continued use, and participate in decisions when the workflow changes.

Two Identities May Be Involved in One Action

When a person asks an agent to perform work, the downstream system may need to understand both who initiated the task and which software actor executed it. Netskope's June 2026 identity discussion highlights the need to consider the human actor and agent actor together rather than treating the agent as an anonymous extension. [4] This matters for auditability, least privilege, delegated authority, and incident review.

Ownership Alone Does Not Make Access Safe

A named sponsor can explain the business purpose, but the technical authority still needs its own review. An agent may be well owned and still hold a broad service account, persistent API key, or delegated token that reaches more systems than the task requires. Treat ownership and authorization as separate gates: one answers why the workflow exists; the other answers what the software actor is allowed to do.

Lifecycle Changes Are Security Events

Agent identity decisions should be revisited when the workflow changes. Adding a connector, moving from read-only analysis to write access, switching the sponsoring team, using a new model or tool layer, or expanding to sensitive data can change the authority of the workflow without changing its name. A small change log tied to the agent record helps the organization know when a new review is required instead of relying only on an annual access certification.

CyberTech Intelligence Perspective

Do not begin with a universal policy for "AI agents." Begin with a decision record for each material workflow. The record should answer: What is the agent? Who owns it? What identity or credential does it use? What can it reach? Which actions can change the business? Which controls limit that authority? When should access expire? If those questions are answerable, the organization can govern the workflow without slowing every experiment by default.

Build the Model Before You Scale It

  • Create a single inventory record that links agent, owner, purpose, credential path, tools, data reach, and lifecycle status.
  • Prioritize agents that can write, delete, deploy, send, approve, or transact over read-only assistants.
  • Separate the human who requested the task from the identity that executed the task wherever the platform supports it.
  • Review OAuth grants, service accounts, tokens, and API keys against the current task rather than the original proof of concept.
  • Require explicit approval or deterministic policy for actions with high business impact.
  • Retire or re-register agents when the owner, platform, business purpose, or permission model materially changes.

Shadow Agent Identity Decision Model

Figure 1. CyberTech Intelligence Shadow Agent Identity Decision Model

Decision Question

Required Evidence

Action

Can we see the agent?

Platform, endpoint, SaaS, browser, cloud, or application evidence.

Create or update the agent record.

Can we name an owner?

Human sponsor or accountable business owner.

Assign ownership before expanding access.

Can we identify the credential path?

Agent identity, user context, service account, OAuth grant, token, key, or role.

Classify and review the identity.

Can we explain the authority?

Approved task, data reach, tools, APIs, and high-impact actions.

Right-size functionality and permissions.

Can we observe important actions?

Logs, audit events, alerts, approvals, and exception handling.

Add monitoring and escalation.

Can we end the access cleanly?

Expiry, offboarding, revoke, disable, or decommission process.

Retire access when purpose ends.

Map One Shadow Agent Path

Choose one real workforce workflow and map it from human request to agent identity, credential, tool access, data reach, approval point, and offboarding action. The output should be one page that both Security and the business owner can understand.

About CyberTech Intelligence

CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.

Evidence and Citation Note

External sources are used only within their stated scope. Government and standards material supports risk-management and control context; vendor material supports the publisher's own product, research, or operating-model statements. CyberTech Intelligence does not infer that a named organization has a shadow AI agent, an identity weakness, a current incident, a specific product need, or buying intent unless direct evidence establishes that fact.

References

[1] National Institute of Standards and Technology, “New Concept Paper on Identity and Authority of Software Agents,” February 5, 2026. https://www.nist.gov/news-events/news/2026/02/new-concept-paper-identity-and-authority-software-agents Accessed August 26, 2026. Relevance: NIST announcement explaining why AI-agent access to data, tools, and applications creates identification and authorization questions.

[2] CyberArk, “Why reducing AI risk starts with treating agents as identities,” February 17, 2026. https://www.cyberark.com/resources/blog/why-reducing-ai-risk-starts-with-treating-agents-as-identities Accessed August 26, 2026. Relevance: Vendor analysis used only for its identity-and-privilege framing of how agents are configured and operated.

[3] SailPoint, “Control your AI: SailPoint can discover, aggregate, and secure every AI agent across your enterprise,” March 9, 2026. https://www.sailpoint.com/blog/ai-agent-identity-security-governance Accessed August 26, 2026. Relevance: Vendor product perspective used for its description of agent discovery, ownership, access certification, least privilege, and lifecycle management.

[4] Netskope, “No ID, No Data For You,” June 22, 2026. https://www.netskope.com/blog/identify-manage-and-control-ai-agents-with-netskope-and-aembit Accessed August 26, 2026. Relevance: Vendor perspective used for its distinction between human and agent actors and its discussion of identity-based policy for agent access.

[5] Nudge Security, “Nudge Security Becomes the First AI Security Solution to Discover Shadow AI Agents Beyond APIs,” May 27, 2026. https://www.nudgesecurity.com/press/nudge-security-becomes-the-first-ai-security-solution-to-discover-shadow-ai-agents-beyond-apis Accessed August 26, 2026. Relevance: Vendor announcement used only to illustrate that agent discovery may require visibility beyond public platform APIs; no independent performance claim is inferred.