Ask a CISO how many AI tools are running inside their organization right now, and you might get a confident number. New research suggests that number is wrong—and not by a little.
According to research Malwarebytes' ThreatDown conducted, 74% of organizations were running more AI tools than they expected. Companies that predicted five or fewer tools in their environment instead found, in 30% of cases, 16 or more already active. Workforce adoption told the same story: organizations estimated roughly a third of employees were using AI tools day to day; the actual median was 58%.
That's not a rounding error in an inventory spreadsheet. It's a governance system that doesn't know what it's governing—and the tools slipping through that blind spot are no longer passive chatbots. Increasingly, they're agents: software with standing permissions to read files, execute code, and reach into other systems through protocols like MCP (Model Context Protocol). SecureWorld asked security leaders what that shift means for practitioners trying to close the gap.
From shadow IT to shadow agents
The numbers land differently depending on who's reading them, but the underlying anxiety is consistent. "The fact that 74% of organizations found more AI tools than they expected, and that actual workforce use was a median 58% versus an expected 33%, underscores the shadow AI reality that many organizations and CISOs are struggling with right now," said Diana Kelley, CISO at Noma Security, a unified AI security and governance platform.
Kelley's read is that the gap gets more dangerous as AI use shifts from something people do to something agents do on their own. "That governance gap becomes more serious as AI continues to shift from people-driven use to agent-driven action that can access sensitive data, run code, and connect to other tools and services," she said. Security teams, in her view, need visibility into three things at once: what's running, what it can touch, and what it's actually doing at runtime. "You can't govern what you can't see, and with agentic AI, unknown access can quickly become enterprise harm."
The checkpoint that disappeared
Part of what makes shadow AI harder to contain than shadow IT is that it skips a step organizations used to be able to count on. Randolph Barr, CISO at Cequence Security, an API security and bot management provider, said the 74% figure doesn't surprise him, as most organizations are still building basic AI governance while leadership pushes for faster adoption. Every department wants to experiment, he said, and none of them think to loop in IT or security first.
"It used to be that rolling out an application required engineering or IT, and that requirement was a built-in checkpoint," Barr said. "AI erased it. Now, anyone with a browser can wire up an agent over lunch."
Barr's prescription starts with the oldest rule in the field: you can't protect what you can't see. But he's wary of governance that only shows up after the fact. "If governance feels like a roadblock, people will just route around it, and you're back where you started," he said. The controls that matter for agents, in his view, sit at the infrastructure layer: tying every action to a real identity instead of a borrowed login, scoping agents to least privilege, continuously discovering which tools and MCP connections are actually live, and enforcing runtime behavior with a full audit trail so a hijacked or off-script agent can be contained and reconstructed after the fact.
A second dataset says the same thing
ThreatDown isn't the only vendor finding this. Pathlock's own 2026 AI Governance Gap Report, based on a May 2026 survey of 286 IT, compliance, and security decision-makers, found that 51% of organizations aren't confident they know all the AI agents operating in their systems—a strikingly similar shape to ThreatDown's numbers, from a different vendor surveying a different population.
"These findings mirror what we are seeing in our own research," said Chris Radkowski, GRC expert at Pathlock, an identity and access security provider. The overlap points to something practitioners already suspect: AI adoption is accelerating faster than governance can keep up. Radkowski's emphasis is on treating agents as identities rather than tools—maintaining an inventory of agents and their permissions, enforcing least privilege by task, and continuously monitoring activity. "Organizations also require transaction-level visibility, so they can answer not only 'What is this agent allowed to do?' but 'What is it actually doing?' across connected systems," he said.
The takeaway for security teams
Nobody is arguing for blocking AI adoption outright; that ship has sailed, and trying to stop it tends to just push usage further into the shadows. The consistent advice instead is to build governance that assumes agentic behavior from day one: real-time discovery of what's actually running rather than what's on an approved list, identity-based access scoped to specific tasks, and runtime monitoring that can catch an agent acting outside its intended lane before it becomes an incident.
The two surveys agree on the scale of the blind spot. What happens inside it is still mostly unmonitored, and that's the part security teams are being urged to fix.

