Shadow AI spreads quietly
Any team with a credit card can spin up an AI agent. Any developer with an API key can deploy an MCP server, and any engineer can install a coding agent on a laptop. The result is AI running in production and on laptops that no central team knows about.
API-only scanners catch what is registered. They miss the agent a contractor deployed last Tuesday, the model proxy running on a personal AWS account, the MCP server someone stood up in a dev namespace and forgot to tear down. By the time these show up in an audit, the risk has been live for a while.
Coding agents add a new version of the problem. Is anyone running Claude or Codex on a personal account? What did last month's token bill buy? Without visibility on each host, neither question has a good answer.