TL;DR: Governance for AI agents fails when enterprises cannot inventory what exists, because manual registration misses shadow AI and leaves tool access, data flow, and ownership unmapped, according to Trust3. Continuous discovery across cloud audit logs, platform connectors, and SDK intercept is the prerequisite for runtime policy and observability.
NHIMG editorial — based on content published by Trust3: Solving the Enterprise AI Agent Inventory Problem
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: How should security teams discover shadow AI agents in the enterprise?
A: Use endpoint artefacts first.
Q: Why do AI agents create a governance problem for IAM teams?
A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.
Q: What do security teams get wrong about AI agent authentication?
A: They often confuse prompt-level identity propagation with enterprise authentication.
Practitioner guidance
- Build discovery from evidence, not forms Use cloud audit logs, platform APIs, and SDK-level instrumentation to discover agents that were never formally registered.
- Record agent identity and tool reach together For every agent, capture the service account or API key, the connected tools and MCP servers, and the data systems it can read or write.
- Flag ownerless agents as governance exceptions Make declared ownership a mandatory field for deployment approval and a daily control check for existing agents.
What's in the full article
Trust3's full article covers the operational detail this post intentionally leaves for the source:
- A practical discovery model that combines cloud audit logs, platform connectors, and SDK-level interception for agent inventory.
- A field-by-field description of what a complete AI agent registry needs to capture for governance and review.
- Examples of how to scope shadow AI across enterprise infrastructure, developer environments, and organisational credentials.
- The next part of the series on behavioural observability, including how runtime monitoring should build on discovery.
👉 Read Trust3's analysis of solving the enterprise AI agent inventory problem →
AI agent discovery is the governance gap teams keep missing?
Explore further
Discovery is the first real control in AI agent governance: policy without inventory is administrative theatre. Agents proliferate through many teams, many platforms, and many credentials, so the control problem is not lack of rules but lack of visibility. If the estate is unknown, ownership, review, and enforcement are all downstream of a gap that already exists.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Another finding from the same research shows only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared with nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who should own AI agent access reviews and lifecycle decisions?
A: Ownership should sit with the business application team and the identity function together, because the workflow owner understands the task and the identity team understands privilege, audit, and offboarding. Without that split accountability, access reviews become generic checklists that miss the real operational risk.
👉 Read our full editorial: Enterprise AI agent inventory is the first governance control