TL;DR: API-led agent inventory misses active AI agents running outside sanctioned channels, leaving security teams with incomplete ownership, risk scoring, and enforcement data, according to Obsidian Security. The governance problem is not just visibility, but the assumption that configuration data reflects runtime behaviour across AI agents, SaaS features, and shadow deployments.
NHIMG editorial — based on content published by Obsidian Security: The AI Agents Your Security Tools Can’t See
By the numbers:
- Across Obsidian's customer base, agent counts grew from under 500 in late 2024 to nearly 95,000 by February 2026.
- 38% of agents carried medium, high, or critical risk factors from the moment they deployed.
Questions worth separating out
Q: How should security teams discover AI agents that are not in IAM inventories?
A: Use multiple discovery paths at once: declared agent registries, repository scanning, plugin and app store monitoring, network analysis, and identity analytics.
Q: Why do AI agents create a bigger governance problem than ordinary endpoint tools?
A: Because an AI agent can execute many file reads, API calls, and transfers in one session without a human approving each step.
Q: What do security teams get wrong about AI governance inventories?
A: They often inventory only the AI they built themselves and miss embedded AI inside vendor platforms and other shadow AI.
Practitioner guidance
- Correlate API discovery with runtime visibility Use API inventory for baseline coverage, then add browser or session-level telemetry to identify agents that appear only after they start acting inside SaaS tools and personal accounts.
- Review embedded AI features in approved SaaS apps Inventory AI capabilities already turned on inside collaboration, CRM, and productivity platforms, because those features can create identity risk without a new OAuth grant or connection event.
- Map ownership to live agent activity Require a named business and technical owner for every active agent, then reconcile that ownership against observed usage, connector scope, and data access patterns.
What's in the full article
Obsidian Security's full blog post covers the operational detail this post intentionally leaves for the source:
- How browser-level visibility identifies AI activity inside SaaS sessions that API inventories do not surface
- What kinds of embedded AI features in tools like collaboration and productivity platforms create hidden identity risk
- How Obsidian distinguishes configured agents from active agents in customer environments
- Why the company argues that incomplete inventory undermines entitlement mapping, runtime enforcement, and risk scoring
👉 Read Obsidian Security's analysis of AI agent visibility gaps and shadow risk →
AI agent inventory gaps: what security teams still cannot see?
Explore further
API inventory is not identity governance for AI agents. API-driven discovery can identify configured agents, but it cannot prove what is active, embedded, or operating through trusted SaaS features. That means the control problem is not just a missing tool, but a broken assumption that administrative records represent runtime identity. The implication is that governance for AI agents must begin with behavioural truth, not configuration completeness.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: How should organisations govern AI agent risk once discovery is in place?
A: Treat discovery as the first control, then attach ownership, access scope, behavioural monitoring, and review cadences to each active agent. Governance should be based on who can act, what they can reach, and whether the action still matches the business purpose. That is the point where policy becomes enforceable.
👉 Read our full editorial: AI agent visibility gaps leave enterprise governance blind to shadow risk