All articles
AI governanceSecurity

Shadow Agents: Finding the AI Agents Nobody Owns

The Copilot Insights Team19 June 20266 min read

Somewhere in your tenant, agents are running that nobody owns. Here's how shadow AI agents appear, why they're a security risk, and how to find, own or retire every one.

Copilot Studio put agent-building in the hands of everyone. That is the promise — and the problem. Somewhere in your tenant right now there are almost certainly shadow AI agents: bots and copilots that someone spun up for a project, wired into real business data, and then quietly abandoned. Nobody owns them, nobody reviews them, and nobody is quite sure what they can still reach. This guide explains where shadow agents come from, why they are a governance risk, and how to find, inventory and safely retire every one of them.

0 owners
The defining trait of a shadow agent — it still runs and still has data access, but no one is accountable for it.

What are shadow AI agents?

A shadow agent is an AI agent — typically built in Copilot Studio — that operates in your tenant without a clear, accountable owner. It might be a customer-service bot a team piloted last year, an HR assistant a manager built to answer policy questions, or a data-lookup agent someone wired to a SharePoint site and forgot. The technology worked, the project moved on, and the agent kept running. The name borrows from shadow IT — the older problem of unsanctioned apps and spreadsheets — but agents raise the stakes. An agent does not just hold data; it can act on it, answer questions about it, and expose it through a chat interface to anyone with the link. A forgotten spreadsheet sits still. A forgotten agent keeps working, which is precisely why the issue is not that the tool is bad — it is that it lives outside anyone's line of sight.

Why shadow agents appear

Copilot Studio is deliberately low-code, so the people building agents are often not in IT at all. That is powerful, but it means creation outpaces governance. Nobody sets out to create a shadow agent; they are a by-product of moving fast, forming in the gap between how quickly an agent can be built and how slowly most organisations get around to recording that it exists. Orphaned agents tend to accumulate for a handful of predictable reasons:

  • Citizen developers — business users build agents to solve their own problems, without registering them anywhere central.
  • Pilots that never got cleaned up — a proof of concept ships, gets replaced or shelved, but the original agent is never switched off.
  • Staff turnover — the person who built and understood an agent leaves, and ownership evaporates with them.
  • Copy-and-tweak sprawl — someone duplicates an agent to make a small change, and now there are three near-identical bots where one should be.
  • No naming or tagging standard — without conventions, even well-meant agents become anonymous within months.

The risks of ungoverned AI agents

An abandoned spreadsheet is a nuisance. An abandoned agent is a live system with permissions. That is what makes orphaned Copilot agents a genuine security and compliance concern rather than just digital clutter:

  • Standing data access — an agent may still hold connections to SharePoint, Dataverse, email or line-of-business systems, quietly able to surface sensitive information to anyone who can reach it.
  • No accountability — when no one owns an agent, no one is refining its instructions, reviewing its answers, or noticing when it drifts.
  • Security blind spots — agents that are not inventoried cannot be assessed, so they sit outside your normal review and threat-modelling.
  • Compliance exposure — data-residency, retention and audit obligations still apply to an agent nobody remembers building.
  • Wasted spend and confusion — duplicate and dead agents clutter the environment and can carry their own metered costs.

The risk compounds with scale. One orphaned agent is a manageable oversight; fifty, each with its own connections and its own quiet permissions, is an attack surface nobody has mapped. And because low-code creation is frictionless, the number only grows — every month without a discovery process is a month of new agents you have never catalogued.

Governance is the parent topic

Discovering shadow agents is the first move in a broader programme. For the full framework — policies, environments and lifecycle controls — see Copilot Studio agent governance.

How to discover and inventory every agent

You cannot govern what you cannot see, so discovery comes first. The goal is a single, current inventory of every agent in the tenant — not a one-off audit, but a living list. Treat it the way you would treat any asset register: accurate, owned, and refreshed on a schedule rather than rebuilt in a panic before an audit. To discover Copilot agents properly, work through this sequence:

  1. Pull every agent across all environments, not just the default one — shadow agents love forgotten sandboxes.
  2. Record who created each agent, when it was last modified, and when it was last actually used.
  3. Map each agent's connections and permissions — what data and systems can it reach?
  4. Flag agents with no activity in the last 30 to 60 days as candidates for review.
  5. Cross-check against your list of known, sanctioned agents to isolate the genuine unknowns.

Every agent in your tenant is either owned or orphaned. There is no third category — and the orphaned ones are the ones that will surprise you.

Assign ownership, then decommission safely

With an inventory in hand, every agent needs a decision. The healthy end state is simple: each surviving agent has a named owner accountable for it, and everything else is retired. Move deliberately:

  1. Assign an owner to every agent worth keeping, and make ownership a required field going forward.
  2. Disable before you delete — turn a suspect agent off and wait. If nobody notices in a couple of weeks, it was safe to remove.
  3. Revoke and document — before decommissioning, capture what the agent connected to and remove those permissions.
  4. Set a lifecycle policy so new agents are registered, reviewed and expired on a schedule — closing the tap that creates shadow agents in the first place.

Retiring dead agents is a close cousin of reclaiming dead licences — both are about cutting quiet waste you are already paying for. If seat waste is also on your radar, reclaiming unused Copilot licences applies the same discipline to your subscription, and the wider case for measurement sits in our guide to Microsoft 365 Copilot ROI.

See every agent in one scan

Copilot Insights inventories every Copilot Studio agent in your tenant — owner, last-used date and connections — using read-only, metadata-only access that never touches a single conversation. Start a free scan.

Frequently asked questions

What are shadow AI agents?

Shadow AI agents are AI agents — usually built in Copilot Studio — that run in your tenant with no clear, accountable owner. They are often leftover pilots or bots created by business users, and they can retain access to sensitive data long after everyone has forgotten they exist.

How do I find orphaned Copilot agents in my tenant?

Start by inventorying every agent across all environments, not just the default one, and record each agent's creator, last-used date and data connections. Agents with no recent activity and no named owner are your orphaned candidates for review or decommissioning.

Does discovering agents mean reading their conversations?

No. A shadow-agent inventory is built from metadata — who created an agent, when it was last used, and what it connects to — not from the content of any conversation. Copilot Insights is read-only and metadata-only by design.

See your own Copilot numbers

Copilot Insights runs a read-only scan of your Microsoft 365 tenant — reclaimable spend, adoption and agent governance, in minutes. Never any prompt content.

Start a free scan