TL;DR: As agentic AI spreads into browsers, IDE plugins, and local desktop assistants, fragmented discovery is leaving visibility gaps that make shadow AI harder to govern, according to Lasso Security. Unified inventory matters, but context, runtime insight, and risk scoring determine whether teams can actually govern what they find.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Consolidate AI Agents Discovery with the Lasso & CrowdStrike Falcon Integration”.
Key questions
Q: What breaks when AI discovery is limited to browser sessions?
A: You miss shadow AI, local copilots, IDE extensions, and many agentic interactions.
Q: Why does AI visibility not automatically solve governance risk?
A: Visibility only shows that a tool exists.
Q: How do security teams know whether an AI agent is operating safely?
A: Security teams know an AI agent is operating safely when its permissions, invoked tools, and accessed data remain consistent with the approved use case over time.
Practitioner guidance
- Consolidate discovery sources Pull browser telemetry, endpoint signals and developer tooling data into one inventory so AI agents are visible across web and desktop use cases.
- Classify AI tools by behavior Separate generative and agentic AI from ordinary software by evaluating permissions, data handling and how the tool behaves at runtime.
- Add runtime risk scoring Score discovered tools using live usage patterns, sensitive-data exposure and anomalous behaviour rather than relying on installation status alone.
Bottom line: Fragmented discovery leaves AI agents outside a single governance view, especially when browser, desktop and developer tools are monitored separately.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI discovery without endpoint context is not discovery in governance terms. A partial inventory can create the illusion of control while leaving desktop agents, IDE plugins, and browser copilots outside the same review surface. That is a visibility failure, but it is also an identity governance failure because the organisation cannot reliably assign ownership, permissions, or policy to tools it cannot consolidate.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What is the difference between visibility and discovery in AI governance?
A: Visibility shows activity, while discovery identifies and consolidates the actual AI tools in use. A browser log or endpoint alert may show that something is happening, but discovery connects that signal to a known tool, its context, and its governance status. Teams need both, but only discovery supports inventory-driven control.
👉 Read our full editorial: AI agent discovery still leaves a governance gap on endpoints
Unified AI discovery is now a governance requirement, not a convenience feature. The article shows that browser agents, desktop assistants and IDE plugins can no longer be treated as separate visibility problems. When the estate is split across channels, governance becomes inconsistent by design. Practitioners should treat unified inventory as the baseline for any AI control programme.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should security teams govern local AI agents that run on developer endpoints?
A: Treat them as NHIs with identity, access, and lifecycle ownership. Inventory each agent, define which user context it inherits, limit its reachable systems, and require approval for commands that modify code, secrets, or network state. If the agent can execute in the same context as the developer, it needs the same level of governance as other privileged machine identities.
👉 Read our full editorial: AI agent discovery still leaves a governance gap on endpoints