TL;DR: AI agent discovery closes the gap between what security teams think exists and what is actually running across cloud, SaaS, and development environments, according to Unosecur. Continuous discovery matters because agents appear outside normal provisioning, inherit access from connected platforms, and can become shadow identities before anyone reviews them.
At a glance
What this is: This is an analysis of continuous AI agent discovery and its key finding that manual inventories miss active agent identities created outside standard workflows.
Why it matters: It matters because IAM, IGA, and security teams need one governed view of agents, service accounts, and human identities before untracked access turns into unmanaged risk.
By the numbers:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems.
👉 Read Unosecur's analysis of AI agent discovery and complete inventory visibility
Context
AI agent discovery is the process of finding agent identities, the credentials they use, and the systems they touch across cloud, SaaS, and development environments. The identity governance problem is that many agents are created outside normal provisioning, so they never enter the inventory that security teams rely on for review and control.
The primary gap is visibility, not intent. A team can build an agent to solve a workflow problem quickly, but if it bypasses the provisioning path, it becomes a shadow identity with active access and no clear ownership. That is why discovery has become a control issue for NHI governance, not just an asset inventory exercise.
Key questions
Q: How should security teams govern AI agents that were never formally provisioned?
A: Security teams should govern them through runtime discovery, ownership mapping, and behavioural controls rather than relying only on directory records. If an agent appears in production traffic but not in identity systems, it still needs a documented owner, a known purpose, and an enforced access boundary. Without those, the organisation cannot prove accountability or lifecycle control.
Q: Why do shadow agents create a bigger risk than ordinary automation?
A: Shadow agents create more risk because their authority can expand quietly as teams adapt them to new tasks. Ordinary automation usually has a narrower, more fixed control path. Shadow agents can cross systems, accumulate permissions, and continue acting without a clear owner, which makes accountability and containment much harder.
Q: What should an agent inventory include beyond a name and status?
A: A useful inventory should show the agent’s model, the tools it can invoke, and the knowledge base or data source that feeds its context. Those fields explain real capability far better than a label. Two agents with the same status can carry very different risk if one can read data and the other can act on production systems.
Q: Should AI agents be reviewed separately from human and service accounts?
A: No. Review them in the same identity context so you can compare privilege, ownership, and lifecycle state across all identity types. Separate views encourage blind spots and make it harder to see when an agent has more reach than the human or service account it sits beside. Unified review is the practical control.
Technical breakdown
Why manual agent inventory fails
Manual inventory breaks because AI agents do not behave like human accounts or traditional service accounts. They are often created inside SaaS tools, cloud projects, or developer experiments, then inherit access from the platforms they connect to. That means the identity record is fragmented from the start. Security teams that depend on periodic audits or self-registration only see what users remember to report, which is usually incomplete. Continuous discovery changes the detection model from scheduled enumeration to runtime observation across cloud, SaaS, and development surfaces. The important shift is not just counting agents, but finding them before they accumulate ungoverned access.
Practical implication: replace periodic agent surveys with continuous discovery across every environment where agents can be created.
Why unified identity context matters
An agent inventory has limited value if it sits in isolation. The useful question is not only whether an agent exists, but how its access compares with the human users, service accounts, and other non-human identities around it. A single unified view makes that comparison possible. It also reduces false confidence, because an agent that looks benign on its own may be over-privileged when the connected system, workload, and data source are considered together. In identity terms, context is the control surface. The inventory needs to show relationships, not just objects.
Practical implication: correlate agent identities with adjacent human and machine identities before approving or retaining access.
What an agent identity card must include
A useful discovery layer has to show the model, tools, and knowledge base behind each agent, not just a label and status. Those elements define effective capability. Two agents can appear identical, yet one may only read internal knowledge while another can invoke tools that write to production systems. That difference is why discovery must reach behind the identity into the execution context. For NHI governance, the real control question is whether the discovered agent can do something material without review, not whether it has a neat entry in a dashboard.
Practical implication: require every discovered agent to be tied to its model, toolchain, and data context before it is accepted into inventory.
Threat narrative
Attacker objective: The objective is to operate an active, credentialed agent without governance visibility so access can persist and expand unnoticed.
- Entry occurs when an AI agent is created inside a SaaS platform, cloud project, or developer workflow outside the normal provisioning queue.
- Escalation occurs when the agent inherits credentials and tool access from the environment it was connected to, rather than from a deliberately reviewed grant.
- Impact occurs when the agent remains active but invisible, creating shadow AI exposure that can outlive the team that created it.
Breaches seen in the wild
- Moltbook AI agent keys breach — Moltbook breach exposed 1.5M AI agent keys.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI agent discovery is now a governance function, not an inventory feature. Discovery matters because agents are being created outside human-style provisioning paths, which means traditional registration and review processes never see them. If the identity programme cannot find an agent at runtime, it cannot govern its access lifecycle, ownership, or retirement. The practitioner conclusion is straightforward: discovery must be treated as a control boundary in the identity model.
Complete visibility requires linking discovery to lifecycle governance. Finding an agent is not enough if the record does not also support review, recertification, and offboarding. The article correctly shows that model, tool, and knowledge-base context determine what the agent can actually do, which means lifecycle decisions have to be made on behaviour and exposure, not just on the existence of an entry. The practitioner conclusion is that agent inventory without lifecycle linkage becomes stale almost immediately.
Shadow AI is an NHI problem before it becomes an AI problem. The underlying issue is unmanaged non-human identity sprawl, because the agent is credentialed, connected, and active long before security notices it. That puts this topic squarely in the same governance class as service account sprawl and unmanaged API access. The practitioner conclusion is that NHI controls must extend into SaaS, cloud, and developer environments where agents are created informally.
Runtime context is the missing control plane for agent identity. A name and status field do not tell you whether an agent can write to production, query sensitive knowledge, or invoke multiple tools in one session. The article points to a deeper control need: identity governance has to evaluate what an agent can reach at the moment of execution. The practitioner conclusion is that context-aware discovery is the only inventory worth relying on for agent risk decisions.
From our research:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to The 2026 Infrastructure Identity Survey.
- Another finding from the same survey shows that 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- That gap makes lifecycle and context governance more urgent, as shown in NHI Lifecycle Management Guide, which connects provisioning, rotation, and offboarding to identity control.
What this signals
Complete discovery is becoming the front door to agent governance. Teams that cannot enumerate agents continuously will also struggle to enforce review, least privilege, and retirement at the right moment. The operational question is no longer whether AI agents exist, but whether the identity programme can see them soon enough to govern them.
Shadow AI should be treated as unmanaged NHI sprawl. That framing changes the programme response, because the remediation path sits in identity hygiene, ownership, and lifecycle control rather than in a separate AI-specific silo. When agent identity is folded back into IAM and NHI governance, the control model becomes much clearer.
With 70% of organisations granting AI systems more access than a human employee in the same role, per The 2026 Infrastructure Identity Survey, the real programme risk is privilege drift hiding inside apparently normal automation.
For practitioners
- Implement continuous agent discovery across all creation surfaces Monitor cloud providers, SaaS applications, and development environments continuously so newly created agents are surfaced during the session they appear, not at quarter-end review.
- Unify agent records with human and machine identity inventories Correlate discovered agents with service accounts, human users, and machine identities in a single identity view so access decisions can be judged in context.
- Require model, tool, and knowledge-base mapping for every agent Do not accept an agent into inventory until the underlying model, callable tools, and context sources are recorded and tied to an owner.
- Bind discovery to offboarding and retirement workflows Use the same inventory to drive review, recertification, and decommissioning so agents do not persist after the workflow or business use case has ended.
Key takeaways
- AI agent discovery closes a real governance gap because agents are often created outside normal provisioning and never enter the inventory.
- Visibility must include context, not just existence, because model, tool, and data access determine what an agent can actually do.
- Identity teams should fold agent discovery into the same lifecycle and review controls used for other non-human identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Discovery and inventory are central to unmanaged non-human identity risk. |
| Recommendation: Inventory all agent identities continuously and tie each one to owner, context, and lifecycle state. | ||
| NIST CSF 2.0 | PR.AC-1 | Identity inventory and access control both depend on knowing what identities exist. |
| Recommendation: Map agent discovery into identity inventory and access governance under Protect. | ||
| NIST Zero Trust (SP 800-207) | Zero trust requires explicit, current identity context before access decisions. | |
| Recommendation: Treat discovered agents as continuously verified identities rather than trusted background automation. | ||
Key terms
- AI Agent Service Discovery: The process an AI agent uses to find available tools, services, or endpoints that can help it complete a task. In enterprise settings, discovery should be governed so the agent only sees authorized capabilities, not the full environment.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Unified Identity Visibility: Unified identity visibility is the ability to map human and non-human access across data and AI environments in one view. It connects identities, entitlements, and activity so teams can see who or what is touching sensitive data. This visibility is the foundation for least privilege, monitoring, and governance.
- AI Agent Lifecycle Governance: The set of controls that assigns, constrains, monitors, and retires autonomous agents across their full operating life. It extends IAM practice to software that can act on its own, making ownership, scope, auditability, and revocation mandatory rather than optional.
What's in the full article
Unosecur's full blog post covers the operational detail this post intentionally leaves for the source:
- Continuous discovery workflow across cloud, SaaS, and development environments
- Unified identity dashboard behaviour for agents, human users, and service accounts
- Model, tool, and knowledge-base mapping logic for each discovered agent
- Lifecycle linkage from discovery through retirement and decommissioning
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on September 5, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org