Executive Summary
AI agents increasingly operate as software actors with enterprise access. Microsoft's 2026 Agent ID documentation treats agent identity as a distinct management and governance problem. [1] Its Windows 365 for Agents architecture further separates the human requester from the agent user identity and links activity to audit records. [2] Current identity-security vendors are simultaneously expanding discovery and lifecycle approaches for agentic identities. [3] [4] [5] CyberTech Intelligence finds that the most defensible control thesis is not that every shadow agent is dangerous. It is that unmanaged authority becomes difficult to govern when the organization cannot connect agent, owner, identity, permission, tool, data, behavior, and lifecycle evidence.
Research Methodology and Source Selection
This report is a secondary-research synthesis and CyberTech Intelligence operating-model analysis. Eight public sources were selected for agent identity management, delegated access, lifecycle governance, enterprise agent discovery, workforce accountability, OAuth-linked surfaces, public-sector AI risk-management direction, and the NIST AI Risk Management Framework. Microsoft and NIST sources are used for platform or framework guidance within their stated scope. Vendor research and product material are used only for the publisher's own observations, survey results, or control approach.
Evidence Universe and Sample Assumptions
No source is used to infer that a specific company has deployed a shadow AI agent, has overprivileged identities, is exposed through OAuth, has experienced an incident, needs a product, has budget, or is likely to buy. Vendor-sponsored research is bounded to its sample and methodology. Product announcements describe the publisher's own capabilities. Framework guidance supports operating questions and control design, not account-level prevalence.
Evidence Grading
Table 1. Evidence Grading and Permitted Use
|
Grade |
Source Standard |
Permitted Use |
|
A - Authoritative |
Government publication, standards body, or official public framework. |
Risk-management, lifecycle, identity, governance, and policy context within the stated scope. |
|
B - Primary platform guidance |
Official product or platform documentation describing identity, access, lifecycle, or security architecture. |
Description of that platform's control model; not universal proof of best fit. |
|
C - Primary vendor research / analysis |
Official survey, research report, product announcement, or technical analysis with stated publisher context. |
Scoped observations and control ideas; not market-wide prevalence or account-level probability. |
|
D - CyberTech Intelligence synthesis |
Analytical framework created from cited evidence and operating requirements. |
Decision support, metrics, maturity, readiness, and governance design; not an external proof point. |
Research Limitations
"AI agent" is not one uniform technical object. Agents may use different orchestration models, credential paths, delegation patterns, SaaS integrations, local execution environments, and control planes. "Shadow AI" can also refer to unapproved AI applications, embedded AI features, local agents, cloud agents, or unsanctioned integrations. This report therefore avoids universal prevalence claims and focuses on control questions that remain useful across implementations.
Key Terminology Distinctions
- Shadow AI tool: an AI application or feature used outside the expected review or approval path.
- Shadow AI agent: a software actor or agentic workflow operating outside the expected management path and capable of taking actions or calling tools.
- Agent identity: the digital identity or account construct used to authenticate and authorize the software actor where a platform provides one.
- Delegated access: authority exercised by the agent on behalf of a human, application, or service through an approved mechanism.
- Authority drift: a practical condition in which the agent's effective permissions, tools, or data reach expand beyond the originally reviewed task.
These terms are analytical aids, not universal standards. The report uses them to keep discovery, identity, authorization, and runtime behavior separate enough for evidence-based decisions.
Research Framework
Findings use the CyberTech Intelligence Shadow AI Agent Control Framework™: Discover, Assign Ownership, Identify, Map Authority, Right-Size, Approve, Observe, and Retire. The framework tests whether a workforce agent can move from unknown or unmanaged use to an explainable, auditable, and reviewable identity-control state.
Executive Findings
- AI agents require explicit identity and access thinking because they can act across enterprise systems rather than only generate content. [1] [2]
- Shadow AI is first a visibility and ownership problem; risk cannot be assessed reliably when the actor and purpose are unknown. [3]
- Separating the human requester from the software actor can improve attribution, delegated-access reasoning, and lifecycle control where the platform supports it. [2]
- Agent-governance programs increasingly emphasize ownership, discovery, access context, and lifecycle management, but vendor approaches should not be treated as universal standards. [3] [4] [5]
- OAuth grants, browser extensions, tokens, service accounts, and other credentials can create identity-linked access outside a single central inventory. [6]
- Public-sector AI risk-management work emphasizes governance, accountability, resilience, and lifecycle risk decisions rather than one-time approval. [7] [8]
- Identity risk can exist even when credentials are technically valid if the agent has more authority, persistence, or autonomy than the current task requires.
- Research Desk observation: control failures concentrate at handoffs - discovery to ownership, ownership to authorization, authorization to runtime, and runtime to offboarding.
1. AI Agents Introduce Distinct Identity and Authorization Questions
Microsoft's Agent ID documentation organizes AI-agent security around management, governance, protection, access, and lifecycle. [1] This supports a key distinction: the agent is not merely the model. It is an operating actor that needs identity context when it connects to enterprise resources. The research implication is to separate model safety from the identity and authority of the workflow that uses the model.
2. Visibility Should Precede Risk Classification
SailPoint's 2026 Agentic Fabric announcement centers discovery and unified visibility as a foundation for governing agentic identities. [3] That is a vendor solution position, but the operating logic is broader: risk scoring without a reliable inventory can miss agents that appear through browsers, endpoints, embedded SaaS functions, cloud platforms, and developer tooling. Discovery evidence should therefore be retained as part of the identity record.
3. Human Sponsorship Preserves Business Accountability
Agent access exists because a person or team authorized a business purpose. The governance model should preserve that link. Vendor identity frameworks from SailPoint and Saviynt both emphasize extending governance to AI or non-human identities. [3] [5] CyberTech Intelligence treats the human sponsor as the business decision-maker for purpose, continued need, and major authority changes, while a technical owner manages configuration and response.
4. Separate the Human Request from the Software Action Where Possible
Microsoft's Windows 365 for Agents architecture describes distinct human and agent identities and an audit path that can trace a request from the initiating user through agent execution. [2] The implementation is Microsoft-specific, but the design principle is useful: delegated automation is easier to govern when the organization can distinguish the human who asked from the software identity that acted.
5. Access Surfaces Extend Beyond a Single Directory
Nudge Security's July 2026 announcement focuses on hidden OAuth grants and browser extensions as identity-linked surfaces that can be difficult to govern centrally. [6] As a product announcement, it does not establish market prevalence. It does show why a complete agent inventory may require evidence from browser, SaaS, identity, endpoint, cloud, and application layers rather than relying on one directory or API.
6. Identity Risk Can Exist Without Invalid Credentials
An agent can use a legitimate token and still exercise more authority than the current task requires. The risk question is therefore broader than authentication. It includes permission scope, credential duration, connected tools, data reach, autonomy, approval, and behavior. The control objective is not to make every action manual. It is to make authority intentional and reviewable.
7. Lifecycle Risk Management Is More Useful Than One-Time Approval
Treasury's 2026 public-private AI initiative and NIST's AI RMF both emphasize practical risk management across the AI lifecycle. [7] [8] For workforce agents, lifecycle thinking means reviewing identity and authority when the agent is created, when the workflow changes, when a sponsor changes role, when new tools are connected, when risk signals appear, and when the business purpose ends.
8. Research Desk Observation: Risk Concentrates at Handoffs
Most organizations already have some of the required controls, but they sit in different teams. Endpoint may discover the process; SaaS management may see the app; identity may see a grant; cloud may see a role; engineering may know the workflow; the business may know the purpose. Risk concentrates where those facts fail to transfer. Require evidence at each handoff so an assumption is not mistaken for an approved identity or an active business need.
Board-Level Evidence and Decision Metrics
- Percentage of priority agents with a named sponsor, technical owner, and documented purpose.
- Percentage of agents with an explicit identity or credential path and mapped resource access.
- Percentage of high-impact actions protected by human approval, deterministic policy, or explicit prohibition.
- Number and age of unknown-owner agents, stale credentials, broad OAuth scopes, orphaned service accounts, and unreviewed connectors.
- Time from discovery to decision: approve, constrain, migrate, redesign, or retire.
- Percentage of agent identities reviewed after a material workflow, owner, platform, or permission change.
- Percentage of decommissioned agents whose credentials, grants, integrations, and data access were removed successfully.
- Trend in repeat exceptions by business function, platform, identity type, and access pattern.
Twelve-Month Implementation Roadmap
0-90 days: establish discovery sources, agent records, sponsor requirements, identity classification, and first-pass authority mapping. 3-6 months: right-size high-risk permissions, formalize approval gates, connect logging and exception workflows, and test credential revocation. 6-9 months: automate lifecycle triggers where practical, expand visibility across browser, SaaS, endpoint, cloud, and developer paths, and measure authority drift. 9-12 months: scale only control patterns that remain explainable, operationally supportable, and measurable across business functions.
Strategic Takeaway: Make the Software Actor Auditable
The workforce edge now includes people and the software actors they delegate work to. The durable control advantage is not a larger blocklist. It is an auditable chain from business purpose to sponsor, agent identity, permission, tool, data, action, monitoring, and retirement. That chain allows security teams to support productive automation without turning every experiment into either a blind spot or a blanket prohibition.
Shadow AI Agent to Governed Identity Path
Figure 1. From Unknown Agent to Measured Control
|
Stage |
Operating Meaning |
|
1. Discover |
Confirm the agent or agentic workflow and preserve the evidence source. |
|
2. Assign Ownership |
Name a human sponsor and technical owner; record purpose and expected duration. |
|
3. Identify |
Document agent identity, delegated user context, account, token, grant, key, role, or certificate. |
|
4. Map Authority |
Map systems, data, tools, APIs, connectors, and high-impact actions. |
|
5. Right-Size |
Reduce functionality, access, and persistence to the current task. |
|
6. Govern Runtime |
Add approval, policy, logging, monitoring, alerting, and exception handling. |
|
7. Review and Retire |
Reassess after changes and remove access when purpose or ownership ends. |
Governance and Decision Rights
Figure 2. Shadow AI Agent Governance Framework
|
Decision Stage |
Accountable Owner |
Required Evidence |
Exit Criteria |
|
Discovery |
Security / IT |
Agent evidence, platform, workflow, first/last seen, initial identity clue. |
Agent record exists. |
|
Ownership |
Business Sponsor / Technical Owner |
Purpose, accountable person, team, duration, expected outcome. |
Ownership accepted. |
|
Authorization |
Identity / Security |
Identity type, credentials, scopes, resources, data, tools, high-impact actions. |
Authority is intentional. |
|
Runtime |
Platform / Application Owner |
Approval gates, policy, logs, alerts, exceptions, response path. |
Material actions are governable. |
|
Lifecycle |
Identity Governance / Risk |
Review evidence, drift, sponsor status, expiry, incidents, decommission path. |
Continue, constrain, redesign, or retire. |
CyberTech Intelligence Shadow AI Agent Control Framework™
Figure 3. Eight-Layer Architecture
|
Layer |
Name |
Operating Requirement |
|
01 |
Discover |
Find material agents across workforce and technology paths. |
|
02 |
Assign Ownership |
Tie each material agent to a human sponsor and technical owner. |
|
03 |
Identify |
Document the agent identity, human delegation, and credential path. |
|
04 |
Map Authority |
Map data, tools, APIs, systems, and high-impact actions. |
|
05 |
Right-Size |
Limit permissions, functionality, and persistence to the task. |
|
06 |
Approve |
Require human or deterministic control for material actions. |
|
07 |
Observe |
Monitor activity, investigate exceptions, and review authority drift. |
|
08 |
Retire |
Revoke and decommission access when purpose, ownership, or risk changes. |
Shadow AI Agent Readiness Score™
Table 2. CyberTech Intelligence Shadow AI Agent Readiness Score™
|
Domain |
Executive Assessment Question |
Ready-State Evidence |
|
Discovery |
Can material agents be found across expected workforce and technology paths? |
Repeatable discovery sources and current inventory. |
|
Ownership |
Does each material agent have a sponsor and technical owner? |
Named owner, sponsor, purpose, and review date. |
|
Identity |
Is the authentication and delegation path explicit? |
Identity/account/grant/token/key/role and issuer. |
|
Permission Scope |
Does access match the current task? |
Resources, scopes, entitlements, and rationale. |
|
Tool and Data Reach |
Are tools, APIs, MCP servers, applications, and data stores mapped? |
Connection map and data classification. |
|
High-Impact Actions |
Are destructive, privileged, external, or financial actions controlled? |
Approval, deterministic policy, or explicit prohibition. |
|
Credential Lifecycle |
Can credentials expire, rotate, and be revoked? |
Expiry, rotation, revoke test, and exception path. |
|
Monitoring |
Can material activity be observed and investigated? |
Logs, alerts, audit records, and incident workflow. |
|
Drift Review |
Are changes to access and connections reviewed? |
Change evidence, scheduled review, and exception aging. |
|
Offboarding |
Can the agent and its integrations be retired cleanly? |
Disable/decommission process and verified removal. |
|
Measurement |
Are control outcomes measured before scale? |
Coverage, remediation, review, exception, and retirement metrics. |
How to Calculate the Score
Rate each domain from 0 to 4: 0 = absent; 1 = informal; 2 = documented; 3 = implemented and tested; 4 = measured and continuously improved. The maximum is 44 points. Divide the total by 44 and multiply by 100. Suggested bands are Critical (0-24%), Developing (25-49%), Defined (50-69%), Managed (70-84%), and Adaptive (85-100%). This is an internal readiness aid, not a certification, breach forecast, financial forecast, or product-performance statement.
Shadow AI Agent Governance Maturity Model
Figure 4. CyberTech Intelligence Shadow AI Agent Governance Maturity Model
|
Maturity |
Operating Pattern |
Leadership Priority |
|
Reactive |
Discovery is ad hoc and agent access is reviewed only after an issue or user question. |
Create a repeatable inventory and ownership rule. |
|
Defined |
Priority agents have documented owners, identities, authority, and lifecycle expectations. |
Standardize review, approval, and retirement. |
|
Connected |
Business, identity, endpoint, SaaS, cloud, application, and data evidence feed one control workflow. |
Close handoff gaps and automate review triggers. |
|
Measured |
Coverage, exceptions, authority drift, approval controls, and offboarding outcomes are measured. |
Prioritize recurring gaps by business impact. |
|
Adaptive |
Controls change as data sensitivity, workflow authority, and observed behavior change. |
Expand autonomy only when evidence supports the decision. |
Use the Shadow AI Agent Readiness Assessment
Benchmark one business function across discovery, ownership, identity, permission scope, tool and data reach, approval controls, monitoring, drift review, and offboarding. Use the gaps to prioritize the next control decision and executive conversation.
About CyberTech Intelligence
CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.
Research and Citation Governance
This report uses public sources current through August 26, 2026. Government and NIST material is used for risk-management, lifecycle, and policy context. Platform documentation describes the publisher's own architecture. Vendor research and product material are used only for the publisher's stated observations, samples, or capabilities. CyberTech Intelligence does not infer that a named organization has a shadow AI agent, compromised identity, active incident, buying intent, budget, or need for a specific product. Framework, maturity, and scorecard content are CyberTech Intelligence synthesis tools and are not certification or prediction.
References
[1] Microsoft Learn, “Microsoft Entra Agent ID documentation,” Current documentation, 2026. https://learn.microsoft.com/en-us/entra/agent-id/ Accessed August 26, 2026. Relevance: Microsoft documentation index for managing, governing, and protecting AI agent identities across access, lifecycle, and security controls.
[2] Microsoft Learn, “Identity and security in Windows 365 for Agents,” Updated June 2, 2026. https://learn.microsoft.com/en-us/windows-365/agents/identity-security Accessed August 26, 2026. Relevance: Microsoft architecture guidance describing separate agent identity, delegated human context, session-scoped access, and auditability for agent workloads.
[3] SailPoint, “Introducing the SailPoint Agentic Fabric: Securing the new era of enterprise AI,” May 11, 2026. https://www.sailpoint.com/blog/introducing-sailpoint-agentic-fabric-securing-enterprise-ai Accessed August 26, 2026. Relevance: Vendor perspective used for its discovery, identity context, governance, and response model for agentic identities.
[4] BeyondTrust, “AI Agents and Identity Security: How Enterprises Are Rewriting the Rules,” March 2026. https://assets.beyondtrust.com/assets/documents/Ebook-BeyondTrust-AI-Agent-Identity-March-26.pdf Accessed August 26, 2026. Relevance: Vendor-sponsored research used only for its reported enterprise observations about agent projects, identity processes, and governance priorities.
[5] Saviynt, “2026 Identity Security Trends,” 2026. https://saviynt.com/hubfs/2026%20Identity%20Security%20Trends%20-%20Saviynt.pdf?hsLang=en Accessed August 26, 2026. Relevance: Vendor trend report used only for its stated expectations about AI identities, access, lifecycle, and governance challenges.
[6] Nudge Security, “Nudge Security Unveils AI Agents to Mitigate Escalating Risks from Hidden OAuth Grants and Browser Extensions,” July 15, 2026. https://www.nudgesecurity.com/press/nudge-security-unveils-ai-agents-to-mitigate-escalating-risks-from-hidden-oauth-grants-and-browser-extensions Accessed August 26, 2026. Relevance: Vendor announcement used only to illustrate OAuth grants and browser extensions as identity-linked surfaces that can sit outside centralized review.
[7] U.S. Department of the Treasury, “Treasury Announces Public-Private Initiative to Strengthen Cybersecurity and Risk Management for AI,” February 18, 2026. https://home.treasury.gov/news/press-releases/sb0395 Accessed August 26, 2026. Relevance: Government release used for the current policy emphasis on secure, resilient AI adoption and practical risk-management resources.
[8] National Institute of Standards and Technology, “AI Risk Management Framework,” Updated 2026. https://www.nist.gov/itl/ai-risk-management-framework Accessed August 26, 2026. Relevance: NIST risk-management framework used for Govern, Map, Measure, and Manage lifecycle logic and current 2026 profile-development context.