Shadow AI Inventory for Unsanctioned Agent Discovery
A shadow AI inventory classifies unsanctioned models, custom GPTs, and embedded SaaS agents, then routes keep, govern, or retire decisions. Discovery without an owner is just a longer list.
Direct Answer
Inventory the unsanctioned path, then give each item a decision.
A shadow AI inventory is a discovery and classification workflow for models, custom agents, browser extensions, and newly enabled SaaS AI features that are already processing company records without a named owner or review. The agent should assemble an item packet: what it is, who uses it, what data it can see, and a keep, govern, or retire recommendation. It should not block accounts or delete workspaces on its own.
This is not the same job as a tool-permission inventory written before a planned launch. That document names what a future agent may touch. Shadow inventory finds the agents and copilots that are already running because a team pasted work into a consumer tool, built a custom GPT, or accepted a vendor's new 'AI assistant' checkbox.
Our bias is to treat discovery as a routing problem. CISA and G7 partners published minimum elements for an AI software bill of materials so organizations can see models, datasets, infrastructure, and security properties. That transparency standard is useful even when the 'system' is an unofficial workspace. A list of URLs without data class, owner, and decision is not an inventory.
Blind Spot
Acceptable-use policy without discovery leaves the real fleet unlisted.
Many companies published an AI use policy and stopped. Legal and marketing kept working. A paralegal built a custom GPT on live third-party paper. A campaign manager turned on an ad platform's generative assistant over customer lists. IT still believes the official copilot tenant is the only model path.
The old shadow-IT playbook looks for unsanctioned SaaS logins. That is necessary and incomplete. The new objects include consumer model accounts, browser extensions that send page text, low-code agents wired to a spreadsheet, and vendor AI features that appeared inside a contract you already signed.
A policy PDF is not visibility
If security cannot name the unofficial agents, the policy is a communication artifact, not a control.
A sanctioned tenant is not the fleet
Official Microsoft or Google copilots can coexist with consumer accounts and vendor-embedded models that never joined the tenant.
A one-time survey goes stale
New SaaS AI features appear inside existing products. The inventory needs a cadence, not a kickoff workshop.
Item Packet
Legal and marketing need different questions on the same form.
Run the first inventory across in-house legal and marketing operations, two teams that often create unofficial agents for speed. The systems of record are the identity provider, the secure-web or CASB logs, the official copilot tenant, the SaaS admin consoles, the contract repository, and the AI-use register. The agent correlates signals into an item. A security and business owner pair decides the fate.
Object type
Consumer chat account, custom GPT or Gem, browser extension, low-code agent, vendor-embedded assistant, or shadow MCP server.
Owner and users
Who built it, who still has access, and whether it is personal, team, or widely shared.
Data classes observed or likely
Client contracts, customer lists, unpublished pricing, credentials, or public marketing copy. Likelihood is allowed. Invented certainty is not.
Model and destination
Where prompts go, whether a workspace is enterprise-managed, and any subprocessors the vendor already disclosed.
Business job it is doing
Clause triage, campaign copy, research. The sanctioned alternative, if one exists, belongs on the same line.
Recommended decision
Keep under a named owner, move to a sanctioned tool, govern in place with logging and no-training terms, or retire.
Discovery Sequence
Correlate signals. Do not start by threatening the users.
The first pass should make unofficial work visible without turning the exercise into a hunt. People adopted these tools because a sanctioned path was slow or missing. If the inventory only produces a ban, the next agent will be harder to see.
MCP catalogs at https://solzero.com/blog/mcp-tool-catalogs-for-agent-pilot-readiness cover capabilities you chose to expose. Shadow inventory should also look for unofficial MCP servers and API keys that never entered that catalog.
Read identity and egress first
OAuth grants, browser-extension installs, and DNS or proxy hits to consumer model endpoints are usually enough to start a packet.
Ask vendors what they enabled
Every major SaaS admin console now has an AI feature list. Treat a newly enabled assistant as a discovered item, not as the original product you reviewed years ago.
Interview the job, not the tool
Ask legal what clause work is leaving the matter system. Ask marketing what customer lists are being drafted against. The tool name comes second.
Offer a landing path
A keep-and-govern or move-to-sanctioned option should exist before retire. Discovery without a replacement recreates the same unofficial path next month.
Governance
Write the decision rules before the first block action.
NIST AI RMF GOVERN 6 asks for policies about third-party software, data, and supply-chain risk. Unofficial agents are third-party systems you did not mean to enroll. The inventory should feed that register the same way a purchased vendor does.
Access recertification at https://solzero.com/blog/access-recertification-agents-for-periodic-reviews is a later cousin for standing entitlements. Shadow inventory is earlier: it finds the unofficial entitlement so a recertification campaign has something to review.
Consumer tools on client or customer data
Default to retire or move. Do not leave privileged or personal data in an unmanaged account because the output was useful.
Vendor AI inside an existing contract
Route to the inbound AI vendor review. The feature may stay if training terms, region, and logging are acceptable.
Low-risk public-copy uses
Govern in place if the data class is already public and a named owner accepts the logging gap.
No automated lockout in version one
Blocking a workspace can destroy matter notes or campaign drafts. Contain by policy and owner first. Technical blocks come after the packet names the impact.
Scoreboard
Measure decided items and residual unofficial processing, not survey response rate.
The inventory is working when unofficial agents either gain an owner and controls or move to a sanctioned path. Useful measures include new items discovered per cycle, items with a named owner, items still processing restricted data after the decision date, time from discovery to decision, and sanctioned alternatives actually used after a move.
Do not treat a longer spreadsheet as maturity. An unclassified list of 200 browser extensions is still a blind spot.
The SolZero take is that shadow AI inventory is operating visibility for work that already left the building. If legal or marketing is already using unofficial agents and nobody can name them, start at https://solzero.com/#how-it-works.
Further reading