Direct answer
What is a shadow agent and how should an enterprise govern it?
#A shadow agent is an AI agent or agentic workflow created or operated outside the organization’s approved inventory, ownership, security, evaluation, or governance process. Govern it by discovering the identity and dependencies, containing risky access, assigning an owner, classifying the workflow, evaluating actual behavior, and migrating useful work into a sanctioned path or retiring it.
- Do not begin with a blanket assumption that every unsanctioned workflow is malicious.
- Prioritize credentials, sensitive data, external communication, and irreversible side effects.
- Provide a faster approved path so teams do not recreate the problem.
Source basis: reviewed synthesis of the strategy corpus. Report-derived claims remain subject to the verification boundary in the source library.