The agent nobody sanctioned has no owner, no off switch, and whatever access its creator happened to hold. The controls that work make the approved path the faster one.
Standing an agent up is quick; getting one sanctioned is not. That gap is the whole of shadow AI. It works, which is why it spreads. Nobody recorded an owner, so there is no one to answer for it and no one to switch it off. And it inherits whatever access its author already held, so the blast radius is a by-product of one person's IAM history.
The work started where the demand does, not with a policy: business teams wanting to ship small internal apps without waiting on an engineering backlog, and an escalation asking, at enterprise level, to see which agents were deployed and who signed them off.
A prohibition removes neither the backlog that created the demand nor the ease of routing around it. It removes the part of the demand you could see. The answer that worked was a path, not a rule.
Our own pre-production review of a regulated enterprise's internal developer platform found every app handing the identity that creates a release the same role that approves that release into production. That was a deliberate pilot-stage setting, carrying the platform's own pilot-only annotation — and precisely what a review before production exists to find. The gate was real; the separation was missing. Approval separation is named first in the hardening phase that engagement has already scoped in public.
Two sibling failures both pass a checklist. A deployment step named for a vulnerability scan did no scanning — it pushed the image, the scanning permission sitting unused — and with no enforced code-ownership file, a merged pull request alone authorised security-sensitive infrastructure change. A control that sits in the repository but never executes is worse than no control, because a reviewer ticks it off.
Offline tests ran on every pull request long before anyone marked that job required on the merge path that authorises a change. A gate governs what it is required for and nothing else.
This control travels best between organisations, and is also the one most often present in configuration and absent in fact. Three named roles carry it: the person who decides what a business term means, the person who signs off a production promotion, and the engineering peer reviewer. Decision rights sit apart from operational ones, the split survived handover, and a four-step escalation chain ends at the promotion approver, not a group mailbox.
Approval evidence attaches to the artefact, not to a conversation. A staging promotion waited on sign-off from a named client-side approver, and the deployment record and gate evidence rode on a pull request that itself needed approval to merge. Every evaluation run behind a promotion is archived and dated, because that is what an auditor reads.
Two cheap primitives. A hold — no production deploys until it is lifted, by name — costs one line and has an owner by construction: somebody must lift it. The second is timing. Access a client-side IT group held during the build came off before merge, and whatever stayed did so because a named owner signed for it. Wait until an engagement ends and you have granted standing access for its whole duration; take it away as the change lands and removal is part of the change.
Promoting an agent or a model version to production takes at least thirty counted scenarios at ninety-five per cent or better; anything under that bar does not go. One production run of the gate came back 54 of 54. The threshold is the half worth carrying; a score alone is a number nobody outside the run can interpret.
Prevention is an economics argument: the unsanctioned path wins when it is quicker. On the platform, the sanctioned path was a self-service portal in which pushing to git triggers a build and then a deploy sitting behind an identity-aware proxy, production gated on a human approval; six pilot apps went out over three pipeline templates built for reuse; zero manual console access from day one. In a search rollout it was one sanctioned surface over ten connectors that respect each source system's access controls, for more than 1,400 people.
None of it inspects whether the thing promoted is correct. An agent that is confidently wrong can be promoted with every approval in place, and it clears each control above. Two gaps were handed over as gaps. The evaluation gate had no wiring into the deployment pipeline, so whether it ran came down to someone remembering — logged openly as a risk with somebody's name against it: on a status report, a control people follow and a control the system enforces look identical. And the per-phase sign-off rested on one named person, flagged in writing, with a backup approver requested.
Nothing here is retroactive. A compliance boundary covers what was born inside it; move a project in afterwards and it is watched from that day on, never covered retrospectively. And a hold holds only until somebody lifts it.
Get in touch
Tell us what system the answer lives in and who needs it. We'll reply with a view on whether it's a two-week assessment, a five-week pilot, or something else.