Back to insights
Agent Governance9 min read

Shadow AI Inventory for Unsanctioned Agent Discovery

A shadow AI inventory classifies unsanctioned models, custom GPTs, and embedded SaaS agents, then routes keep, govern, or retire decisions. Discovery without an owner is just a longer list.

shadow AI inventoryunsanctioned AI discoveryAI asset inventoryAI acceptable useagent governance

Direct Answer

Inventory the unsanctioned path, then give each item a decision.

A shadow AI inventory is a discovery and classification workflow for models, custom agents, browser extensions, and newly enabled SaaS AI features that are already processing company records without a named owner or review. The agent should assemble an item packet: what it is, who uses it, what data it can see, and a keep, govern, or retire recommendation. It should not block accounts or delete workspaces on its own.

This is not the same job as a tool-permission inventory written before a planned launch. That document names what a future agent may touch. Shadow inventory finds the agents and copilots that are already running because a team pasted work into a consumer tool, built a custom GPT, or accepted a vendor's new 'AI assistant' checkbox.

Our bias is to treat discovery as a routing problem. CISA and G7 partners published minimum elements for an AI software bill of materials so organizations can see models, datasets, infrastructure, and security properties. That transparency standard is useful even when the 'system' is an unofficial workspace. A list of URLs without data class, owner, and decision is not an inventory.

Blind Spot

Acceptable-use policy without discovery leaves the real fleet unlisted.

Many companies published an AI use policy and stopped. Legal and marketing kept working. A paralegal built a custom GPT on live third-party paper. A campaign manager turned on an ad platform's generative assistant over customer lists. IT still believes the official copilot tenant is the only model path.

The old shadow-IT playbook looks for unsanctioned SaaS logins. That is necessary and incomplete. The new objects include consumer model accounts, browser extensions that send page text, low-code agents wired to a spreadsheet, and vendor AI features that appeared inside a contract you already signed.

A policy PDF is not visibility

If security cannot name the unofficial agents, the policy is a communication artifact, not a control.

A sanctioned tenant is not the fleet

Official Microsoft or Google copilots can coexist with consumer accounts and vendor-embedded models that never joined the tenant.

A one-time survey goes stale

New SaaS AI features appear inside existing products. The inventory needs a cadence, not a kickoff workshop.

Tool-permission inventory at https://solzero.com/blog/tool-permission-inventory-before-agent-launch is the launch control for a system you intend to ship. Shadow inventory is the discovery control for the systems nobody scheduled.

Item Packet

Legal and marketing need different questions on the same form.

Run the first inventory across in-house legal and marketing operations, two teams that often create unofficial agents for speed. The systems of record are the identity provider, the secure-web or CASB logs, the official copilot tenant, the SaaS admin consoles, the contract repository, and the AI-use register. The agent correlates signals into an item. A security and business owner pair decides the fate.

Object type

Consumer chat account, custom GPT or Gem, browser extension, low-code agent, vendor-embedded assistant, or shadow MCP server.

Owner and users

Who built it, who still has access, and whether it is personal, team, or widely shared.

Data classes observed or likely

Client contracts, customer lists, unpublished pricing, credentials, or public marketing copy. Likelihood is allowed. Invented certainty is not.

Model and destination

Where prompts go, whether a workspace is enterprise-managed, and any subprocessors the vendor already disclosed.

Business job it is doing

Clause triage, campaign copy, research. The sanctioned alternative, if one exists, belongs on the same line.

Recommended decision

Keep under a named owner, move to a sanctioned tool, govern in place with logging and no-training terms, or retire.

Discovery Sequence

Correlate signals. Do not start by threatening the users.

The first pass should make unofficial work visible without turning the exercise into a hunt. People adopted these tools because a sanctioned path was slow or missing. If the inventory only produces a ban, the next agent will be harder to see.

MCP catalogs at https://solzero.com/blog/mcp-tool-catalogs-for-agent-pilot-readiness cover capabilities you chose to expose. Shadow inventory should also look for unofficial MCP servers and API keys that never entered that catalog.

Read identity and egress first

OAuth grants, browser-extension installs, and DNS or proxy hits to consumer model endpoints are usually enough to start a packet.

Ask vendors what they enabled

Every major SaaS admin console now has an AI feature list. Treat a newly enabled assistant as a discovered item, not as the original product you reviewed years ago.

Interview the job, not the tool

Ask legal what clause work is leaving the matter system. Ask marketing what customer lists are being drafted against. The tool name comes second.

Offer a landing path

A keep-and-govern or move-to-sanctioned option should exist before retire. Discovery without a replacement recreates the same unofficial path next month.

Governance

Write the decision rules before the first block action.

NIST AI RMF GOVERN 6 asks for policies about third-party software, data, and supply-chain risk. Unofficial agents are third-party systems you did not mean to enroll. The inventory should feed that register the same way a purchased vendor does.

Access recertification at https://solzero.com/blog/access-recertification-agents-for-periodic-reviews is a later cousin for standing entitlements. Shadow inventory is earlier: it finds the unofficial entitlement so a recertification campaign has something to review.

Consumer tools on client or customer data

Default to retire or move. Do not leave privileged or personal data in an unmanaged account because the output was useful.

Vendor AI inside an existing contract

Route to the inbound AI vendor review. The feature may stay if training terms, region, and logging are acceptable.

Low-risk public-copy uses

Govern in place if the data class is already public and a named owner accepts the logging gap.

No automated lockout in version one

Blocking a workspace can destroy matter notes or campaign drafts. Contain by policy and owner first. Technical blocks come after the packet names the impact.

Scoreboard

Measure decided items and residual unofficial processing, not survey response rate.

The inventory is working when unofficial agents either gain an owner and controls or move to a sanctioned path. Useful measures include new items discovered per cycle, items with a named owner, items still processing restricted data after the decision date, time from discovery to decision, and sanctioned alternatives actually used after a move.

Do not treat a longer spreadsheet as maturity. An unclassified list of 200 browser extensions is still a blind spot.

The SolZero take is that shadow AI inventory is operating visibility for work that already left the building. If legal or marketing is already using unofficial agents and nobody can name them, start at https://solzero.com/#how-it-works.

Further reading