The Shadow AI Economy: From Shadow IT to Shadow Agency
PAC Horizons, 50. Year anniversary PAC Analysts
From Vulnerability Management to Attack-Path Governance
On 1 October 2026, Eckhart Mehler had the pleasure of joining the PAC Horizons event in Frankfurt as a guest speaker for a fireside chat on “The Shadow AI Economy: The Rise of AI-Driven Shadow IT and Tokenisation.”
The conversation was moderated by Spencer Izard, Research Director at PAC, and explored a challenge that is rapidly moving beyond the familiar territory of employees using unsanctioned AI tools.
As generative AI evolves into agentic AI, the nature of Shadow IT is changing with it. AI systems are no longer limited to generating or processing information. Agents can be given identities, tokens and access to enterprise tools, allowing them to interact with data, invoke APIs and increasingly perform actions on behalf of users and organizations.
This raises a different set of questions for CISOs: How do we discover AI capabilities that are emerging across the enterprise? How do we govern machine identities and delegated authority? What happens when employees can create their own agents? And how can organizations provide a secure environment for AI innovation without creating so much friction that users simply move into the shadows?
During the discussion, Eckhart Mehler argued that we may therefore need to think beyond Shadow IT and even Shadow AI. What is emerging could be described as Shadow Agency: digital actors exercising authority inside the enterprise without sufficient visibility, governance or accountability.
The following is an edited transcript of my conversation with Spencer Izard, covering Shadow AI, agentic systems, tokenisation, AI governance, Safe Harbour approaches and what I call the principle of Least Agency.
The Shadow AI Economy
An Edited Conversation on Shadow AI, Agents and Digital Agency
What happens when Shadow IT evolves from employees using unauthorized applications into autonomous AI agents acting inside enterprise systems? In this conversation, the discussion moves beyond public chatbots and data leakage toward a more fundamental security question: Who — or what — is allowed to act on behalf of an organization?
Spencer Izard: Where is Shadow AI surfacing most aggressively across your organization today, and what operational challenges are forcing cross-departmental action?
Eckhart Mehler: I think we first need to broaden our understanding of Shadow AI. It is no longer primarily about employees opening a public chatbot and entering corporate information.
AI functionality is appearing almost everywhere: in SaaS applications, development environments, browsers, low-code platforms and increasingly through agents, connectors and APIs.
That creates a fundamental visibility problem for the CISO.
We may have a reasonably good inventory of our traditional applications. But do we know all the AI capabilities embedded in those applications? Do we know which agents have been created? Which external models they use? Which enterprise data they can access? Which APIs they can call? Which identities and tokens they use?
That is why, for me, Shadow AI is first and foremost a discovery and governance problem.
You cannot govern an AI estate that you cannot see.
And there is another important point: we should not automatically interpret Shadow AI as malicious or irresponsible employee behavior. In many cases, it is exactly the opposite. People are trying to solve a business problem, improve productivity or experiment with a technology that is developing incredibly quickly.
The difficulty is that innovation can now move faster than traditional governance processes can even detect it.
Spencer Izard: How is the Shadow AI risk landscape changing as employees move from simple text prompts to autonomous, multi-step agents operating directly inside daily workflows?
Eckhart Mehler: This is where I believe we are seeing a fundamental change in cybersecurity.
With generative AI, our security discussion initially focused heavily on information. What data goes into the model? Is confidential information being disclosed? Where is the data processed? What does the model return?
Those are still important questions.
But agentic AI introduces another dimension: authority.
An agent may have an identity. It may hold an OAuth token. It may invoke an API, search SharePoint, access a database, send an email, interact with a business application or call another agent.
So the security question changes from:
“What can the AI know?”
to:
“What is the AI allowed to do?”
That is a profound change.
Traditional Shadow IT gave us unmanaged applications. Shadow AI gave us unmanaged models and data flows. Agentic AI can give us unmanaged actors.
I therefore think we are moving toward something that could be called Shadow Agency.
Spencer Izard: What do you mean by “Shadow Agency”?
Eckhart Mehler: Agency in this context means the ability and authority to act.
Think about the difference between an AI system that summarizes an email and an AI system that reads the email, decides that an action is required, accesses another system, changes a record and sends a response.
The second system is not merely processing information. It is exercising delegated authority.
That means we increasingly have to think about a chain such as:
Identity → Authority → Decision → Action → Accountability.
And this becomes particularly interesting when we introduce tool protocols, connectors and architectures such as MCP.
The model itself may not have direct access to anything important. But connect it to tools, enterprise APIs and identities and suddenly it can act across multiple systems.
The model gets a lot of attention.
The tool layer gets the authority.
Spencer Izard: Addressing Shadow AI requires cooperation across business, IT, security and legal teams. How do you make that governance enabling rather than restrictive?
Eckhart Mehler: The first thing I would avoid is making the CISO the owner of AI.
Security cannot own the business purpose of an AI system.
The business has to own the use case and ultimately the outcome and associated business risk. IT will own and operate much of the underlying technology. Privacy and Legal have their respective responsibilities. Security defines and assures security boundaries. Internal Audit may provide independent assurance.
So I don’t think we need centralized ownership of everything.
What we need is clear accountability and common guardrails.
A useful principle is:
Central guardrails, decentralized innovation.
And I would add another very simple requirement: every relevant AI use case needs an owner, and every autonomous agent needs an accountable owner.
Spencer Izard: But doesn’t that kind of governance inevitably slow innovation?
Eckhart Mehler: Bad governance does.
Good governance can actually accelerate innovation because developers and business teams know the boundaries before they start.
The worst situation is when somebody develops something innovative for three months and Security, Privacy or Compliance appears shortly before production and says: “You cannot deploy this.”
Security needs to become involved early enough that we can define a safe space in which experimentation can happen quickly.
That changes the role of the CISO from being a gatekeeper at the end of the process to helping establish the boundaries at the beginning.
Spencer Izard: That brings us to the idea of a “Safe Harbour.” How can organizations make employees choose sanctioned AI rather than unauthorized alternatives?
Eckhart Mehler: The secure solution has to be attractive.
If accessing the approved enterprise AI environment requires several weeks, multiple approvals and complicated processes while somebody can start using a public AI service in thirty seconds, we should not be surprised when Shadow AI appears.
A Safe Harbour cannot simply mean: “Here is the list of tools you are allowed to use.”
It should provide usable AI capabilities, approved models, appropriate access to enterprise data and a clear path for experimentation.
The principle should be:
The secure path must become the path of least resistance.
But agentic AI adds another requirement.
Once employees can build agents themselves, Safe Harbour also needs identity management, authorization, logging, monitoring and software governance.
I am very much in favor of democratizing AI development. Low-code and no-code environments can unlock enormous creativity across an organization.
But there is an important distinction:
Democratizing AI development must not mean democratizing production access.
Being able to create an agent does not automatically mean that agent should be allowed to access sensitive information, execute transactions or communicate externally.
Spencer Izard: So is traditional Least Privilege still sufficient?
Eckhart Mehler: I don’t think it is sufficient by itself.
Least Privilege remains absolutely essential. An agent should only receive the permissions required for its task.
But agentic AI introduces another dimension: autonomy.
Imagine an agent technically has permission to create a payment instruction. That does not necessarily mean we want it to autonomously decide when to create one.
So I think we need to complement Least Privilege with what I call Least Agency.
An agent should receive not only the minimum permissions necessary, but also the minimum degree of autonomous action necessary to accomplish its task.
Those are different controls.
Privilege asks:
“What are you permitted to access?”
Agency asks:
“What are you permitted to initiate or decide autonomously?”
This distinction will become increasingly important as agents become embedded in business processes.
Spencer Izard: As your organization continues to adapt to Shadow AI, what is your primary focus right now? And what advice would you give other CISOs?
Eckhart Mehler: My primary focus is understanding and governing agency.
For decades, identity and access management has taught us to ask questions such as:
Who are you?
Which system may you access?
Which information may you see?
Agentic AI adds another question:
What are you — or the agent acting on your behalf — allowed to do?
Before writing another twenty-page AI policy, I would therefore recommend starting with discovery.
Find your AI applications.
Find your agents.
Find your connectors and MCP servers.
Find your machine identities.
Find your API keys and delegated tokens.
Then, for each relevant system or agent, ask three very simple questions:
What can it read?
What can it do?
Where can it send information?
I think of that as:
READ → ACT → EGRESS.
That simple model can reveal risks that are easy to miss when we look at permissions individually.
An agent might legitimately be allowed to read a document repository. It might legitimately have access to an email capability. And external communication might also be legitimate.
But combine those capabilities and you have created an entirely different risk.
Agentic risk often emerges not from one dangerous permission, but from the composition of individually legitimate permissions.
Spencer Izard: If you had to leave the audience with one thought about the Shadow AI economy, what would it be?
Eckhart Mehler: I would say that we should stop thinking about Shadow AI purely as another generation of Shadow IT.
The deeper issue is delegated digital agency.
We are beginning to create digital actors that operate somewhere between traditional software and traditional users. They can receive identities, hold credentials, consume information, select tools and execute actions.
Our governance models were not designed with that type of actor in mind.
So the next generation of enterprise security will not only be about controlling access.
It will increasingly be about controlling delegated agency.
The organizations that succeed will probably not be those that try to eliminate Shadow AI entirely. They will be those that make governed AI easier, faster and more useful than Shadow AI.
And for CISOs, that leads to a fairly simple principle:
Every agent should be discoverable, identifiable, attributable, constrained, observable and revocable.
Ultimately, the question for cybersecurity is changing.
It is no longer only:
“Who has access?”
Increasingly, it is:
“Who — and what — is allowed to act?”
Spencer Izard:
Eckhart, I think that is a very fitting point to end our conversation. We have moved from Shadow IT and Shadow AI to a much broader question of identity, authority and accountability in an increasingly agentic enterprise.
Thank you very much for sharing your perspective and experience with us today.
Eckhart Mehler:
Thank you, Spencer. I really enjoyed the conversation and the opportunity to explore these questions with you.
And thank you to PAC for inviting me to be part of PAC Horizons. I think discussions like this are particularly valuable right now because none of us has all the answers yet. The technology is developing extremely quickly, and security, governance and business need to learn together.
Thank you also to everyone here in Frankfurt for listening and for the discussions around the session.
Spencer Izard:
Thank you, Eckhart. It has been a pleasure having you with us.
Eckhart Mehler:
Thank you, Spencer — and thank you again to PAC for having me.
Publication Note & Disclaimer
This article provides security and governance analysis, not legal advice. Regulatory obligations must be assessed against the facts, jurisdictions, data types, and roles of the organizations involved.
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion