TL;DR: Shadow AI is moving into enterprises through SaaS updates and user-accessible agent features, while agents inherit human permissions and can act at machine speed, according to ArmorCode. The governance gap is not model capability but identity context, ownership, and review of what AI can touch and do.
NHIMG editorial — based on content published by ArmorCode: The Mythos AI Threat Isn’t the AI. It’s the People Behind It
By the numbers:
- One enterprise security team recently discovered 150 distinct Copilot agents operating in their environment within a single week.
- One enterprise security team discovered 150 distinct Copilot agents operating in their environment within a single week.
- One enterprise security team recently discovered 150 distinct Copilot agents operating in their environment within a single week.
Questions worth separating out
Q: How should security teams manage permissions for AI agents?
A: Security teams should regularly assess and update the permissions granted to AI agents to ensure they align with their intended scope.
Q: Why do shadow AI tools create identity governance risk?
A: Shadow AI is risky because users often reach those tools through identities, browser sessions, or tokens that were never assessed for data handling or access scope.
Q: What breaks when AI SOC agents do not have enough context?
A: They become brittle, overconfident, and inconsistent because they can only act on the visible event, not the organisational reasoning behind it.
Practitioner guidance
- Map every AI-enabled workflow to a named owner Create an inventory of SaaS features, agents, and API-based automations that can act in production.
- Treat embedded AI as a governed non-human identity Apply lifecycle controls to agents that can read, write, or orchestrate tasks.
- Rebuild access review around behavioural scope Do not rely on user identity alone.
What's in the full article
ArmorCode's full blog covers the operational detail this post intentionally leaves for the source:
- The article’s AI Exposure Management framing for continuously ingesting signals from identity, cloud, EDR, firewall, and SASE tooling.
- The launch context for Anya Agents, including the Remediation Agent, Zero-Day Exposure Hunting Agent, Finding Overview Agent, and Risk Analyzer Agent.
- ArmorCode's description of how its Context Risk Graph connects findings, assets, software supply chain, threat intelligence, and documentation.
- The article's own readiness-assessment framing for organisations deciding whether their AI governance model is mature enough for agentic workflows.
👉 Read ArmorCode's analysis of the Mythos AI threat and Shadow AI governance →
Shadow AI and inherited trust: what IAM teams are missing?
Explore further
Shadow AI is becoming an NHI governance problem, not just an AI governance problem. Once an AI feature can act, query, or modify systems, it behaves like a non-human identity with lifecycle and ownership requirements. That shifts the control question from model safety to access governance, inventory, and offboarding discipline. Practitioners should treat every agent as a governed identity surface, not a convenience feature.
A question worth separating out:
Q: Who is accountable when an embedded AI feature causes unauthorised access?
A: Accountability should sit with the business owner of the workflow, the application owner, and the security control owner who approved the access path. If no one can explain why the AI feature was enabled, who reviewed it, and what it can touch, governance has already failed.
👉 Read our full editorial: Shadow AI governance is failing when agents inherit trust