Opens in a new tab
vmblog logo 2024 wht (updated)

Shadow AI Is Here: Securing the Endpoint Against Unsanctioned Agents

Share: 

shadow ai is here

By Brad LaPorte, CMO, Morphisec

Many security teams are treating AI agents the way they once treated cloud adoption — they recognize something new is happening on the horizon, agreed to monitor developments, but, at the end of the day, don’t treat it with the urgency it demands. 

A new report from the Cloud Security Alliance and Zenity makes the case clearly: security leaders can no longer ignore what’s happening. Right now, AI agents are deeply embedded in enterprise operations and causing significant harm. According to the research, 43 percent of organizations report that more than half of their employees use AI agents, and 47 percent have experienced an AI agent-related security incident in the past 12 months. 

With data like this, it’s fair to declare that the era of experimental AI is over, and the security tools most organizations are relying on are severely overmatched.

The Shadow AI Problem Is Not a Policy Problem

When employees began adopting cloud services without IT approval a decade ago, the industry’s response was to implement policies such as acceptable use guidelines, software inventories, and procurement controls. And, for a while, that approach worked well enough.

But shadow AI is an entirely different problem. The scale and speed of adoption have far outpaced the governance frameworks organizations might put in place. This accelerated use is driven by employees who are not waiting for approval before deploying AI agents that can browse the web, write and execute code, access internal systems, and take autonomous actions on their behalf. By the time security teams catch wind of what’s happening, it’s too late, their defenses are outmatched, and the exposure has already materialized.

The traditional perimeter defenses and static access controls being used by many are outmatched for a reason. They were designed for threats that came from outside the network, and their identities were human. AI agents are already within the business perimeter, acting with user-level permissions and behaving in ways that are difficult to predict, even for the people who deployed them. When those agents are compromised, manipulated via prompt injection, or simply misconfigured, the results are delivered directly to the endpoint, and most organizations have no visibility into what happens next.

Why Detection Is Not Enough

When facing a new threat category, the instinctual response is to improve detection. This manifests as increased monitoring, increased logging, and behavioral analytics. This can be a sound approach for many types of threats. But for AI agents, it simply isn’t enough.

Detection depends on knowing what normal looks like. But with AI agents, normal is a moving target. Agents make autonomous decisions, interact with systems in novel sequences, and adapt their behavior based on context. Establishing a reliable behavioral baseline for an agent designed to learn and adapt is a significant challenge even under the best conditions. And what about the unsanctioned agents? Security teams often don’t become aware of these until something goes wrong, making damage control effectively impossible.

Speed further compounds matters. AI agents can move through systems and execute actions in seconds. By the time a detection system identifies anomalous behavior, alerts a human analyst, and initiates a response, it’s too late. Detection is a necessary step, but it cannot serve as the primary line of defense against threats operating at machine speed.

A Different Approach: Prevent the Exploit, Not Just the Agent

Begin by accepting that regaining control isn’t possible. Unsanctioned agents will continue to be deployed, and legitimate agents will continue to be compromised. The behavior of any given agent at any given moment cannot be fully predicted or governed.

The more useful question is what happens when an AI agent attempts to deliver a payload or execute malicious code on an endpoint. Can the organization prevent that from succeeding regardless of how it arrived?

This is when the conversation shifts from controlling the agent to neutralizing the exploit. This represents a fundamentally different threat model, one that accepts the reality of Shadow AI rather than trying to legislate it away. Instead of monitoring agent behavior, the focus shifts to the endpoint itself — built so that a compromised agent arrives and finds nothing to work with.

The Window Is Already Open

If the endpoint is where AI agent risk ultimately lands, that’s where teams need to focus. The starting point is the access layer and specifically, what privileges an agent holds and how those privileges are enforced.

Most organizations grant agents standing, always-on permissions inherited from the human who deployed them. As a result, every new agent becomes a persistent, over-privileged path into production. That’s not a configuration problem. It’s an architectural one.

Closing it requires three things simultaneously: agents treated as first-class identities with distinct credentials and audit trails; permissions created at the moment of need and destroyed when the task ends; and authorization evaluated at runtime — who’s asking, on whose behalf, and for what scope — before any action executes

Organizations that get this right don’t just reduce their exposure to Shadow AI. They build an environment where the endpoint offers compromised or manipulated agents nothing to work with.

The era of watching and waiting is over. The question now is whether the endpoint is ready for what’s already inside the perimeter.

##

ABOUT THE AUTHOR

Brad LaPorte, Chief Marketing Officer at Morphisec and former Gartner Analyst

brad laporte

Brad LaPorte is a seasoned cybersecurity expert and former military officer specializing in cybersecurity and military intelligence for the United States military and allied forces. With a distinguished career at Gartner as a top-rated research analyst, Brad was instrumental in establishing key industry categories such as Attack Surface Management (ASM), Extended Detection & Response (XDR), Digital Risk Protection (DRP), and the foundational elements of Continuous Threat Exposure Management (CTEM). His forward-thinking approach led to the inception of Secureworks’ MDR service and the EDR product Red Cloak—industry firsts. At IBM, he spearheaded the creation of the Endpoint Security Portfolio, as well as MDR, Vulnerability Management, Threat Intelligence, and Managed SIEM offerings, further solidifying his reputation as a visionary in cybersecurity solutions years ahead of its time.