The Agent Workforce Is Already Here
Enterprises are rapidly assembling a new digital workforce of autonomous AI agents. Unlike conventional applications, these agents can plan tasks, invoke tools, access data, collaborate with other agents, and write to business systems. They are one part software workload and another part human-like, acting with delegated authority but often without clear ownership and accountability.
OutSystems’ 2026 State of AI Development report found that 96% of surveyed organizations were using AI agents in some capacity, while 94% were concerned that AI sprawl was increasing complexity, technical debt, and security risk. Yet many organizations still cannot answer basic questions: What agents exist? Who owns them? What identities and permissions do they use? Which systems and data can they reach? What actions have they performed? Agent security and governance must therefore begin with continuous discovery.
AI Agents Create a Different Visibility Problem
Most business system inventories were designed to support relatively stable categories such as employees, applications, service accounts, cloud resources, and devices. AI agents do not fit neatly into any of these categories. Classifying an agent as human or non-human does not tell you enough on its own. The question that matters is what the agent can do, under whose authority, and with what potential impact. Three terms get used interchangeably in this discussion, and the difference matters. Discovery establishes that an agent exists and who owns it. Visibility describes the identity, permissions, and connections it holds. Observability tracks what it actually does once running.
Shadow AI Is Being Driven by Shadow Agents
Shadow AI has moved beyond employees using unauthorized chatbots. Developers, business units, automation teams, and individuals build agents through SaaS applications, low-code platforms, agent development environments, and other productivity tools. These agents may be useful, but they can be deployed without review by IT, security, privacy, or governance teams. Prohibiting them outright may simply push their use further underground.
The visibility gaps are significant. Organizations may not know an agent’s owner or purpose, which applications it connects to, whether its OAuth or API access is excessive, what sensitive data it can reach, or whether an orphaned agent retains valid credentials. They may also miss behavioral changes after deployment. This lack of knowledge about agent existence, ownership, access, and activity is becoming the central shadow AI challenge.
Why Traditional Asset and User Inventories Are Not Enough
CMDBs, IAM systems, directories, SaaS applications, and cloud asset inventories provide useful pieces of the agent picture, but rarely the complete view. A meaningful inventory must connect each agent to its creator, owner, purpose, service accounts, OAuth grants, API tokens, secrets, applications, APIs, MCP servers, tools, data sources, parent agents, sub-agents, delegation relationships, and runtime activity.
The Salesloft Drift compromise of August 2025 showed what that gap costs. Attackers stole the OAuth tokens that Drift’s AI chat agent used to reach customers’ Salesforce environments, then queried records as the trusted application without a password or an MFA prompt. Google put the number of affected organizations at more than 700. Drift was a sanctioned integration in every one of them, and the exposure sat in permissions and connections that no conventional asset or user inventory tracked.
The inventory also cannot be a static register. Agents can be created, modified, duplicated, or decommissioned much faster than traditional applications or human users. A quarterly assessment will be outdated before it is completed. Governance therefore requires a continuously updated graph of agents, identities, permissions, connections, and actions.
What Continuous Agent Discovery Must Provide
Effective agent discovery should provide five essential capabilities:
- Broad coverage. Discovery should include sanctioned and unsanctioned agents, developer-built agents, embedded SaaS agents, personal agents, and agents created within automation tools.
- Identity context. Organizations must understand what identity an agent uses, whose authority it inherits, and whether its permissions are appropriate for its purpose.
- Relationship mapping. Discovery should show how agents connect to human users, sub-agents, applications, tools, APIs, credentials, and data.
- Runtime correlation. The inventory must connect each agent to what it does, rather than merely showing where it was registered or how it was configured.
- Lifecycle monitoring. Security teams should identify newly created, modified, inactive, abandoned, and unusually behaving agents.

From Discovery to Governance
Agent discovery is not the final objective. It is the foundation for observability, behavioral monitoring, policy enforcement, threat detection, audit evidence, and remediation. Once organizations know what agents exist, they can assign owners, validate purpose, review permissions and connections, identify excessive or stale access, apply risk-based policies, monitor behavior, generate evidence, and terminate unsafe agents.
Agent discovery and observability systems should then feed IAM, SaaS security, SIEM, data security, AI governance, and incident-response processes rather than becoming another isolated system. Emerging AI Agent Visibility and Observability Platforms (AI-VOP) extend discovery and observability into runtime telemetry, interaction mapping, behavioral analytics, explainability, policy enforcement, containment, and remediation.
Visibility Precedes Observability
Organizations cannot secure, govern, or audit agents they do not know exist. Continuous discovery should become an immediate AI security and governance priority rather than hoping for AI adoption to become centralized or standardized. The organizations best positioned to benefit from agentic AI will not impose the strictest prohibitions. They will continuously discover agents, understand their authority and behavior, and apply appropriate controls without hindering innovation.
This is why KuppingerCole Analysts is launching new research focused on AI-VOPs and the emerging market and vendors providing them. As agents become more autonomous and more deeply connected to enterprise systems, visibility must precede observability and control. Two related pieces are available to KuppingerCole subscribers: Agent Visibility and Observability Platforms (AVOP), a Leadership Brief, and Navigating the Agentic AI Security Landscape, an Advisory Note.