The signal. Microsoft’s Agent 365 launch (opens in a new tab) is extending agent discovery to 18 agent types, including developer tools like Claude Code and GitHub Copilot CLI, because organizations increasingly cannot see what’s already running inside them. The reporting around it is stark: in IBM’s 2025 breach study (opens in a new tab), roughly one in five organizations had already suffered a breach involving shadow AI, and 63% of breached organizations had no AI governance policy at all.

What changed. “Shadow AI” is the AI-era version of shadow IT: capable agents, adopted bottom-up by employees who just want to get work done, running outside any sanctioned process. What’s new is the capability. Shadow IT was a rogue spreadsheet. Shadow AI is a system that can take actions, send messages, move data, call APIs, on your behalf, without your knowledge.

Why it matters. The reflex response is a blanket ban: lock it all down, forbid the tools, mandate approval for everything. This reliably fails. It doesn’t stop the behavior; it drives it further underground, and it forfeits the upside to competitors who governed instead of banned. Prohibition converts your most motivated adopters into your least visible risk.

Strategic implication. The alternative is proportional governance: visibility first, then controls sized to risk. Know what’s running. Make the sanctioned path easier than the shadow path. Apply graded control: a password-reset agent and an agent that can change financial limits do not belong under the same rule. The goal is not zero shadow AI; it’s zero invisible shadow AI.

What to take into the room: ask a blunt question: “what agents are running in our organization right now, and who approved them?” If the room goes quiet, your governance problem is a visibility problem first. Solve that before you reach for the lockdown.