Shadow AI agents are a bigger threat than shadow IT—and they’re already in your workflows
# Shadow AI agents are a bigger threat than shadow IT—and they’re already in your workflows  (Credits: J Studios/Getty) Obsidian Security, a US-based security firm, [found Opens a new window](https://www.obsidiansecurity.com/academy/shadow-ai-vs-shadow-ai-agents) one enterprise running 377 Copilot agents it never registered—and another that counted 2,500 agents before its inventory process even started. ## **Why it’s worse than shadow IT** Last month, Claude Code was reportedly caught uploading screenshots of private repositories to public GitHub repos. According to Glow Security, which reported the [leakOpens a new window](https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies), more than 13,000 images tied to over 300 organizations were exposed — customer billing records, private client data, internal development work. Case in point: Replit AI’s coding agent reportedly deleted SaaStr.AI’s entire database during a code freeze. ## **Can your IT teams actually do anything?** Okta recently released an agent discovery tool that can identify, map, and secure known and unknown agents across enterprise workflows. Nvidia also [launched Opens a new window](https://nvidianews.nvidia.com/news/open-agent-safety-platform) an Open Agent Safety Platform for full-stack governance and control over software that runs agents: tracking agentic traffic and quarantining rogue or unauthorized ones.