Executive Leadership
Shadow AI Agents: What a CEO Does About the Automation Nobody Approved
Somewhere in your company there is an agent that reads the CRM every night and emails a sales team its follow-up list before 7 a.m. Nobody approved it. It may be the best automation you own.
Most of what gets written about shadow AI pictures one employee pasting a customer contract into a public chatbot. That happens, and it is a real data problem. It is also the 2023 version of the problem.
The 2026 version runs on a schedule.
The people in your company who are good at their jobs have figured out that an agent can do the tedious part of those jobs while they sleep. A marketing manager wires a personal API key into a workflow tool and has it rewrite every product page for search. A finance analyst connects a spreadsheet to a model and lets it reconcile vendor invoices on Thursday nights. None of it went through IT, and some of it is quietly excellent.
I know the type because I am one. My own fleet started as automation I built for myself, for work I was tired of doing by hand, long before any of it had a register or an owner field. Most of the governance habits I write about on this site were learned by cleaning up after it.
Why the ban will lose
The reflex at most companies is a memo. Approved tools only, personal accounts forbidden. It feels decisive.
It drives the agents underground, where they keep running on the same personal keys, now with an owner who has every reason to never mention them. You trade a visible risk for an invisible one and lose the work too. When I was CMO at Mozilla, the whole product was an argument that people should control their own tools, and I came away convinced that you cannot win a fight against your own employees’ ingenuity by decree. You can only make the sanctioned path less annoying than the shadow one.
What makes an agent different from a chatbot tab
A chatbot session ends when the tab closes. An agent holds credentials and wakes up on a timer, and its output lands somewhere other people or systems read, which gives it most of what makes an employee departure dangerous with none of the offboarding.
When the marketing manager leaves for a competitor, their personal API key leaves with them and the agent stops. Or worse, it keeps working, billing a card nobody at the company controls and writing to a folder the company still depends on. I described this failure from the inside in retiring an AI agent. Shadow agents are the same failure with no register to check against.
Run an amnesty, and mean it
The fastest way to find shadow agents is to ask, under terms that make answering safe. I would announce it from the CEO, in writing, with a date.
- Thirty days, no penalties. Anyone who declares an agent, workflow, or scheduled model call they built gets thanks and zero discipline, even if it touched data it should not have. The thirty days matter more than anything else on this list, because an amnesty without an end date is just a suggestion box.
- A form short enough to fill out in five minutes. What it does, what it can read, whose key it runs on, who uses its output.
- Every declared agent goes on the fleet register with its builder as owner, moved to a company-paid key within the quarter.
- After the deadline, discovery means shutdown. The agent gets turned off, and its owner can bring it back through the normal path once it is registered.
Security will want to scan network logs and expense reports for model vendors at the same time. Let them. Expense reports are worth the afternoon, because a small monthly charge from a model vendor filed under “software” is often the only paper trail an agent leaves. The scan finds keys. Only the amnesty tells you what an agent is for and who would notice if it stopped.
Read the list as a roadmap
Here is the part none of the shadow AI guides I read for this piece get to. They treat the inventory as a list of risks to close. I treat it as the most honest product research a CEO will ever receive, because every shadow agent is a requirement that an employee cared about enough to build a working prototype on their own time and their own card.
Sort the declarations by what they do instead of by what they touch, and patterns show up fast. If four people in different departments each built something that summarizes customer calls, that is one missing internal service with four working prototypes of it. The best of the four should probably become the official version, with its builder in charge.
I would bring that sorted list to the executive team as a planning input, right next to the budget. It shows where the company’s sanctioned tools are slowest, which is exactly where the next round of shadow agents will come from if nobody fixes it.
The builders
The people who built shadow agents are your future fleet owners, and the worst outcome of this entire exercise is that they learn to stop telling you things.
Where the line actually sits
Amnesty does not mean anything goes. Two rules hold during the thirty days and after them. Customer data never runs through a personal account, full stop, and an agent found doing it gets paused on discovery while the amnesty protects the person who built it. Separately, no shadow agent gets authority to commit the company to anything (sending contracts or issuing refunds) until it has been placed on the delegation of authority matrix like every other agent.
Everything else is negotiable. I expect most declared agents to be low risk and high value, and for those the right response is a company key and a calendar reminder.
What the board should see
Directors should hear about this once, as one comparison. How many agents the amnesty and the scans found, against how many were on the register before they started. The gap between those two numbers is the clearest measure I know of how far a company’s AI governance has drifted from its actual operations, and it belongs alongside the accountability and concentration questions in what boards should ask about AI.
I sit on the board of ACT | The App Association, and the questions I find most useful in that room are the ones management can answer with a count. This one qualifies. A technology board advisor should be asking it now, while the gap is still small enough to close in a quarter.
The CEO’s part is the announcement. Write it yourself, sign it, put the deadline in the first line, and say plainly that the agents people built are wanted. Then on day thirty-one, actually turn off the first undeclared agent anyone finds, because the next amnesty will only be believed if this one ended on the date it said it would.
This article is part of the Executive Leadership cluster, focused on board governance and the operating discipline required to run AI systems responsibly at the executive level.