How to improve visibility across the enterprise AI ecosystem
Rapid adoption of AI tools and agents has created activity that traditional security systems may not see. Continuous inventory, behavioural detection, and least-privilege access are three core responses.
AI adoption has moved faster than governance and security controls in many organisations. The result is a visibility gap: IT may know that a software subscription exists but not what data employees send to generative AI tools, which AI capability was later added to an approved service, or which systems an autonomous agent can reach.
A sponsored AI News article, citing Cisco’s 2025 Cybersecurity Readiness Index, says 60 percent of organisations do not know the specific requests employees make to generative AI tools. The figure and the article’s recommendations should be read in the context of sponsored content, but the underlying issue is material: security policy is difficult to enforce when data flows and agent activity cannot be observed.
Three important forms of shadow AI
The first is an unapproved stand-alone tool, such as an employee placing a document or dataset into a public chatbot to complete a task more quickly. The second is an AI feature embedded in software that was already approved, but added after the original security review. The third is an autonomous agent that does more than answer questions: it takes action inside connected systems and can propagate mistakes or compromise at machine speed if access is poorly scoped.
Why traditional tooling can fall short
Conventional asset-discovery and monitoring products were designed to find known software in expected locations. They do not necessarily classify model usage, data exchanges with chatbots, or the behaviour of an agent operating inside an application. Buying more conventional tooling without changing discovery and monitoring practices therefore may not close this architectural gap.
Three practical actions for security teams
1. Continuous discovery and inventory: A one-time audit is insufficient. Organisations need a living record of tools, embedded capabilities, models, agents, owners, and access levels, with changes tracked continuously.
2. Layered behavioural detection: Monitoring should supplement known attack signatures with an understanding of normal user, device, and agent behaviour, then investigate meaningful deviations. The article presents Darktrace as a commercial example of this approach; that reference is also part of the sponsored content and is not a substitute for independent product assessment.
3. Zero-trust access: Each agent should have only the data and tool permissions required for its defined task. Least privilege, environment separation, action logging, and human approval for sensitive operations can reduce the blast radius of an error or compromise.
The central conclusion is that visibility is a prerequisite for control. An organisation cannot reliably manage AI risk if it does not know which models and agents are active, what data is moving, and what actions are being executed.

Source: AI News