Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news
ai

Shadow AI agents are multiplying. Here's how to find and secure them.

Shadow AI agents are proliferating across enterprise stacks—built in Salesforce Agentforce, Microsoft Copilot Studio, Cursor, Zapier, Retool, and dozens of other platforms—often without IT or security visibility or approval. The core problem is structural: agents differ fundamentally from shadow AI chatbots because they hold persistent permissions, connect directly to corporate systems, and execute actions autonomously. When an unmanaged agent fails, the damage isn't confined to a chat window; it's a live system that's been altered. The risk metrics are stark: 48% of cybersecurity professionals rank agentic AI as the most dangerous attack vector of 2026, yet only 21% of IT leaders report mature governance programmes. This gap between exposure and readiness defines the current state of CX and operations teams, where agents are being deployed faster than security can inventory them.

Discovery remains the foundational challenge because most agent detection methods rely on vendor APIs, leaving substantial blind spots where employees build agents on platforms without public integrations. Browser-based discovery—observing agent creation in real time through extensions—captures activity on low-friction tools like Cursor automations, Retool, and Zapier agents, which paradoxically tend to carry the broadest access and least oversight. For CX teams already running Agentforce or similar platforms, the question becomes whether your current governance approach accounts for agents built outside your primary stack, where ops teams and product managers are likely automating workflows without formal approval. Once agents are inventoried, the governance layer must balance speed with control: assigning ownership, setting approval statuses, and nudging creators to justify access or fix risky configurations—all without forcing the workforce to seek permission before building.

The implication for support and CX operations is that agent sprawl is no longer a future scenario but an active operational reality. Teams must shift from preventing agent adoption to maintaining visibility and control over what's already running, which requires discovery methods that span both API-exposed platforms and the shadow tools where real adoption is happening. The governance burden falls on CX leaders to establish who owns each agent, what systems it can access, and whether its permissions remain justified—particularly as team members leave or agent purposes drift over time. Without this framework, the efficiency gains from agentic automation will be offset by security incidents, compliance violations, and the operational chaos of managing undocumented systems touching customer data and core workflows.