Unregistered Agent Operations
Accountability & GovernanceDescription
Agents instantiated, deployed, or operated outside formal governance processes. Creates unmanaged attack surface, accountability gaps, and policy blind spots. Shadow AI proliferates as teams bypass governance for productivity.
Department deploys an autonomous email agent without IT governance review; agent has no monitoring and operates outside data handling policies.
Researchers have demonstrated that LLM agents can be manipulated via prompt injection to exfiltrate environment variables, API keys, and secrets to attacker-controlled endpoints. The Samsung internal data leak via ChatGPT (employees pasting secrets into prompts) is a realized adjacent incident, but agent-driven automated exfiltration of credentials in a production deployment has not been publicly confirmed as a discrete incident.
Primary mitigations
- Centralised agent registry
- agent discovery scanning
- rogue agent detection
- policy enforcement at infrastructure level.
Detection signals
Unregistered Agent Detection Rate; unsanctioned agent instance count.