Skip to content
Wingback Security

You cannot govern AI you have not inventoried

Wingback Security · 7 min read

Security programs keep buying AI guardrails for agents they have never listed.

The Cloud Security Alliance’s The Invisible Enterprise: Shadow AI and the Ungoverned Frontier frames the problem as asset blindness. CSA’s AI Safety Initiative describes assistants in browsers, AI-native SaaS bought by business units, models pulled into pipelines without review, and agentic workflows wired to corporate data, all running without registration, risk scoring, or monitoring.

The paper’s numbers are concrete. Reco’s telemetry, cited by CSA, puts 91% of AI tools outside IT control, with organizations averaging hundreds of shadow AI apps per thousand employees. IBM’s 2025 Cost of a Data Breach findings (also cited there) report higher average cost and longer dwell time for shadow AI incidents. The regulatory deadline is fixed too: the EU AI Act’s high-risk obligations, including inventory and risk classification as prerequisites, land on August 2, 2026.

This Field note focuses on that inventory gap. Tool-description poisoning and coding-agent credential inheritance on laptops matter; they belong in other posts. The question here is simpler: do you even know which agents, models, and AI integrations you are already running?

What “shadow AI” actually covers in 2026

CSA’s definition is deliberately broad: any AI system, model, tool, API, agent, or integration that runs without formal registration, risk assessment, policy governance, or security monitoring.

In practice, security leaders usually discover four overlapping layers:

  1. Consumer assistants and browser paths: ChatGPT, Gemini, Claude, Copilot, and vertical tools used for work tasks, often with sensitive paste behavior.
  2. Business-unit AI SaaS: legal review, HR screening, CRM copilots, and analytics assistants procured outside central security review.
  3. Developer-sourced AI infrastructure: open-weight models, SDKs, experimental inference endpoints, and MCP connectors that migrate from laptop to pipeline.
  4. Agentic systems: workflows that do more than answer questions. They call tools, query stores, send messages, and accumulate permissions over time.

The fourth category is where a missing inventory becomes autonomous risk. An ungoverned agent is a non-human actor with reach into identity, data, and production systems, and often no assigned owner in the CMDB. An unlisted SaaS app is a different problem; an ungoverned agent can act on its own.

CSA is direct about the dependency: no governance capability is meaningful without knowing what assets it governs. NIST AI RMF’s Map function and ISO/IEC 42001 make the same point. You cannot measure or manage what you never mapped.

Why traditional asset management misses the AI estate

A VM shows up in a cloud console. A SaaS app often appears in SSO or OAuth grant logs. An AI path can leave almost none of those breadcrumbs.

Direct API keys in application code, personal browser sessions, browser extensions, fine-tuned derivatives on shared GPU pools, RAG indexes nobody registered, and agents spun up inside a vendor console all evade inventories built for IP addresses and installed packages. CSA notes that some shadow AI tools show median usage durations over 400 days without formal approval. Usage that long means operational dependencies with roots, not weekend experiments.

That is why a quarterly “AI tool survey” fails. The estate changes weekly. Developers adopt a new coding agent. A product team enables a SaaS agent builder. A research group points a workflow at a vector store. If discovery is a one-time event, your inventory is already stale when the slide deck finishes.

A useful AI inventory has to answer questions traditional CMDB rows never asked:

  • What identity does this agent or model path use?
  • What tools and data can it reach?
  • How much autonomy does it have without a human in the loop?
  • Who owns it when something goes wrong?
  • Did its configuration, connectors, or permissions drift since last review?

CSA’s Capabilities-Based Risk Assessment (CBRA) framing (criticality, autonomy, permission scope, and potential impact) is a practical way to turn that inventory into triage rather than a vanity dashboard.

Inventory is also a compliance control, not only a security nicety

Security teams sometimes treat discovery as “phase zero” and never leave phase zero. Regulators are closing that window.

Under the EU AI Act timeline CSA summarizes, organizations need a living picture of AI systems before risk tiering, conformity work, and documentation can be honest. NIST AI RMF and ISO/IEC 42001 likewise treat inventory and context-of-use mapping as the base layer. If your only AI list is a procurement spreadsheet of three approved vendors, you are not ready for an auditor who asks which agents touch customer data this quarter.

Runtime defense still needs inventory underneath it. You cannot put least-privilege tool scope, session kill switches, or red-team coverage on agents that do not appear in any system of record.

What good AI Surface Intelligence looks like

Buyers evaluating Agent Detection & Response should treat discovery as a continuous product capability rather than a professional-services spreadsheet.

Cover more than one place AI runs. Endpoints (coding agents, local MCP, browser assistants), cloud and SaaS agent platforms, and the inference paths inside your own products each hide a different slice of shadow AI. Covering one channel alone leaves the rest invisible.

Prefer what is running over what was registered. Approved catalogs matter. Live collectors that watch cloud accounts, code, workstations, and runtime calls catch the AI your business actually depends on.

Score so teams can act. A calibrated risk score that combines exposure, configuration, ownership gaps, and change history lets teams fix the worst first without inventing a weekly triage ritual.

Bind every asset to an owner and a blast-radius story. “Unknown agent, broad tool access, no owner” belongs on the P1 list.

Keep the inventory live. Continuous reconciliation beats annual AI audits the same way continuous vulnerability management beat annual pen-test PDFs.

Those requirements line up with how modern ADR platforms are judged: discover the surface, defend in flight, red-team what matters, and keep evidence for governance frameworks buyers already cite.

How Wingback helps

Wingback’s public platform story starts with AI Surface Intelligence: continuous discovery of agents, models, MCP servers, and inference paths across the places enterprises actually run AI (cloud and SaaS, engineering workstations, and the software you ship), then risk scoring and routing findings to owners. That is the inventory layer CSA says is missing.

In practical terms, for the shadow-AI blindness problem:

  • Map the estate that is actually running, including shadow and sanctioned paths, rather than waiting for voluntary registration alone.
  • Score assets so security and engineering can prioritize exposure, ownership gaps, and risky configurations without inventing a new severity language every week.
  • Connect discovery to defense. Inventory is useful when it feeds runtime Agent Detection & Response (watching tool use and sessions, and stopping unsafe actions while they are still running) instead of living in a separate spreadsheet.
  • Support the governance conversation with evidence that maps to frameworks security and compliance teams already use, including NIST AI RMF-style mapping and EU AI Act readiness pressure around knowing what you operate.

An AI risk review board, an approved-tool catalog, and least-privilege design still matter. Wingback makes the invisible estate visible enough that those controls can attach to real agents and real owners.

If your team is staring at CSA-style inventory gaps and needs a living map of agents, models, and MCP paths across endpoints, cloud, and product inference, request a demo. For product detail, see AI Surface Intelligence and platform capabilities.

What to do this week

  1. Pick one discovery channel you do not currently cover (cloud AI services, SaaS agent builders, code/MCP usage, or endpoint assistants) and instrument it.
  2. Require an owner, purpose, and data/tool scope for every agent above a low autonomy threshold; treat “no owner” as a security finding.
  3. Reconcile your approved AI catalog against live usage; the delta is your shadow-AI backlog.
  4. Score agents with autonomy and permission scope in the formula, not only “is this model approved.”
  5. Tie inventory tickets to runtime controls: once an agent is known, decide what it may call, what it may exfiltrate, and who gets paged when policy fails.

Sources and further reading

Talk with Wingback

A prompt filter does not fix an estate you have not listed. The work starts with inventory and ownership; autonomy risk arrives the moment an unlisted agent can act. If you want help turning an invisible AI estate into a governed one (discover first, then enforce), request a demo.