Shadow Agent
An unsanctioned AI agent — the sharp, dangerous end of shadow AI. Unlike a shadow chatbot that only answers questions, a shadow agent holds standing access (OAuth tokens, API keys, service accounts) and the authority to *take actions*: send email, update records, move data, run code, often unattended on a schedule or trigger. Shadow agents are more dangerous than shadow SaaS because they act rather than merely store: their credentials outlive the employee who built them (no offboarding), they inherit maximal scope by borrowing a human's token, and they turn a single Prompt Injection into an unattended exfiltration with no Human-in-the-Loop (HITL) gate. The most common shadow agent in 2026 is mundane — a Zapier- or n8n-style automation with an LLM step, a Custom GPT connected to company Workspace, or a coding agent pointed at prod with a personal access token.
Example
An engineer builds a coding agent that triages GitHub issues, authenticated with their personal access token scoped to the whole org. Six months later they switch teams; the agent keeps running on a credential nobody in security knows exists, with write access to every repo — an orphaned, over-privileged non-human identity waiting to be compromised.
Frequently asked questions
- How is a shadow agent different from just shadow AI?
- Shadow AI includes someone *asking* an AI a question. A shadow agent is someone giving an AI *standing access and authority to act*. The chat leaks what was pasted in; the agent executes an attacker's goal across every tool it can reach. The action capability is the whole difference.
- Why can't we just revoke shadow agents when we find them?
- You can and should scope down or revoke high-risk ones immediately — but revocation alone recreates the ban problem: the builder's need doesn't disappear, so they rebuild it hidden. Pair revocation with a fast sanction path so the safe version is easy to get.