Council Post: Shadow Agents Are Coming: Why CIOs And CISOs Should Prepare
Drew Naukam is the CEO of Gorilla Logic, an AI-led digital software engineering firm specializing in building complex products & platforms.

getty
Shadow agents are everywhere.
I feel like I’m writing a 1960s-era Cold War story. I can envision dark alleys, trench coats, leather briefcases and other imagery from a John le Carré or other famous spy novel. The best spies, after all, are the ones you never see, operating in plain sight, answering to no one.
But alas, this article refers to a different set of agents: AI agent proliferation across the enterprise. And something that is quickly becoming a massive ungoverned risk for CIOs and CISOs.
The growth of large language models (LLMs) in organizations is staggering. Forbes recently reported that Anthropic’s Q2 2026 preliminary revenue surpassed $11.5 billion, more than 14 times the $787 million booked in Q2 2025, with roughly 80% of its revenue coming from API and enterprise business.
Businesses have insatiable demand for AI acceleration, and boards and CEOs are pushing aggressively for productivity improvements tied to these new capabilities. Business users are also adopting rapidly.
Most AI tool adoption follows a predictable path. Initially, AI replaced search engines with a more natural way of interacting, but real productivity comes at the workflow level, which is where the agent explosion becomes problematic.
Enter Desktop Agents
What started with tools like Claude Code, and then Claude Cowork, has quickly shifted to every frontier AI platform, like OpenAI’s Codex and now ChatGPT Work.
These tools are enabling non-technical levels across departments like finance and HR to design and execute multistep workflows that read, modify and access information to perform simple (and sometimes not-so-simple) tasks.
And therein lies the challenge that will keep IT and leadership awake at night.
Never before has so much power been available to non-technical teams. Agents are being created to run accounting functions, help executives manage their workloads, screen candidates in HR and analyze data in finance.
We quickly pivoted from the initial wave of conversational and reactive AI to silent desktop agents that act independently to complete multi-step tasks across critical enterprise systems.
A notable incident occurred in March when a Meta engineer used an internal AI agent to analyze a technical question. The story gained coverage because the agent posted its answer without the “human-in-the-loop” approval, and another Meta employee followed the advice.
The problem was, the advice was wrong and the resulting change made sensitive company and user-related data accessible to engineers who weren’t authorized to see. Meta classified the incident as Sev 1, its second-highest severity level. Meta has responded to the incident to say that “no user data was mishandled” and that “the security alert is an indication of how seriously it takes data protection.”
In general, many of these agents live on local machines or operate through a user’s existing permissions, outside the environments IT traditionally knows how to govern. They’re built quietly, by well-meaning employees solving real problems, which is exactly what makes them so hard to see.
Picture a finance analyst who builds an agent to pull data from three systems, reconcile it and email a summary every Monday. It works beautifully, until it doesn’t. And who’s responsible when it breaks if IT never knew it existed in the first place?
Similarly, when the analyst leaves, the agent often keeps running on their credentials. When a data source changes, no one’s watching. When something breaks, or worse, when something leaks, there’s no audit trail and no one accountable.
Multiply that by every department and every enthusiastic power user, and you have hundreds of these agents quietly operating across the enterprise.
Meta contained this one. But how many agents are creating vulnerabilities inside enterprises right now? And what happens when the next outcome isn’t as benign?
Why Critical Technology Requires Engineering Discipline
Don’t get me wrong. I am all for the productivity benefits these tools provide. They are game-changing. But just like we don’t want spies infiltrating our country, the industry needs a way to build agents in a governed, managed capacity.
This isn’t a reason to slow down; the gains are too real to ignore. But unmanaged proliferation is how you trade a productivity win today for a governance nightmare tomorrow.
If we’ve learned anything in the last decade, it is that you cannot shortcut enterprise security, governance, auditing and controls. A quick win will cost you more in the long-run.
CIOs and CISOs today should follow the same approach they have used for all critical technology implementations: enterprise AI requires engineering. Once an agent can access systems, move data or take action, it is no longer just another productivity tool. It is part of your technology environment, and it needs to be engineered that way. Telling an agent not to do something is not the same thing as preventing it from doing it.
The questions posed in this article aren’t new questions. Security, architecture, testing, governance and accountability have always mattered in enterprise technology. AI doesn’t make those disciplines obsolete. If anything, it makes them more important.
In the end, the organizations that come out ahead won’t be the ones that simply move the fastest. They’ll be the ones that manage to move fast while also keeping the lights on and the risks in check.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?