AI adoption is no longer something organizations can plan for at their own pace. It is already happening.
Employees are using browser-based AI services. Teams are experimenting with agents. Developers are connecting models to business systems. AI-enabled applications are appearing across corporate devices. Some of these activities are approved and well managed. Some of it is not.
The uncomfortable reality is that many organizations do not have a complete picture of the AI operating across their business. They may have policies, steering groups and approved platforms, but still be unable to answer some basic questions:
What AI do we actually have? Who owns it? What information can it access? Is anyone monitoring it? And what happens when an agent is created, tested and then abandoned?
You cannot govern what you cannot see.
That is why we are introducing a new set of AI discovery, governance and remediation services, starting with a focused Shadow AI Hunt.
Finding the AI Hiding in Plain Sight
The Shadow AI Hunt is a two-week assessment designed to uncover AI services, agents, applications and connections across an organization’s cloud platforms, endpoints, Microsoft 365 environment, Azure AI services and relevant on-premises systems.
This is not a lengthy transformation program. It is a focused discovery exercise.
We do not need to build new configurations, deploy controls or make changes to the customer environment during the assessment. The customer provides four hours of administrator time: three one-hour discovery sessions and a final one-hour walkthrough of the findings.
During the assessment, we look for AI that may otherwise be difficult to identify, including:
- Agents acquired through marketplaces
- Agents created using Copilot Studio, agent builders or development platforms
- AI-enabled desktop applications
- Browser-based use of external AI services
- Headless or background agents
- Model Context Protocol connections and servers
- Agents using SharePoint, OneDrive or uploaded files as grounding data
- Custom actions, connectors and links to business systems
Finding the technology is only the beginning.
A long inventory of agents and applications might look impressive, but it does not necessarily help anyone make a decision. The real value comes from understanding what the findings mean for the organisation.
We therefore look at ownership, creators, activity, data access, platform, capabilities and available controls. We identify agents that appear to have no accountable owner, agents that may no longer be required and capabilities that deserve closer attention.
What We Found in One Enterprise
A recent assessment with a large enterprise shows why these matters.
The discovery identified approximately 1,800 agents. Almost half did not have a named owner or a creator identity that could be reliably resolved. The assessment also found hundreds of AI-enabled endpoint installations, thousands of outbound connections and hundreds of agents that had been started but left in draft.
Some agents could access SharePoint or OneDrive. Others had capabilities such as code interpretation, image generation, uploaded files, custom actions or Graph connectors.
That does not mean every agent presented an immediate risk. Context matters.
An experimental agent with no access to business information should not necessarily be treated in the same way as an active agent connected to sensitive data and used in an important business process. But without visibility, organizations cannot make that distinction.
They are left guessing.
An Inventory Is Not Enough
Technology platforms can generate large volumes of telemetry. They can show that an agent exists, identify an application or highlight a connection. What they do not always explain is why the finding matters.
That requires interpretation.
For each relevant finding, we consider questions such as:
- Who should be accountable for this agent?
- Which department appears to be using it?
- What information can it access?
- Is it active, abandoned or still in development?
- Does it have capabilities that increase the potential risk?
- Is its purpose documented?
- Are logging and monitoring adequate?
- Has anyone considered transparency or impact assessment requirements?
- Where is information processed?
- Has the provider explained how customer data is handled?
This turns technical telemetry into something security, privacy, legal, compliance and business leaders can use.
The assessment can also compare the organization’s current position with relevant AI governance requirements and standards, including the EU AI Act and ISO 42001. Third-party providers can be reviewed against their published statements on matters such as certification, regulatory alignment, training data, data residency and customer-data handling.
If reliable information is unavailable, that absence is recorded as a gap. A vendor providing no clear answer about where information is processed should not automatically be treated as low risk simply because no problem has yet been reported.
From Findings to Action
The outcome is not another generic maturity score.
Customers receive a report explaining what was discovered, why the relevant findings matter and which actions should be prioritized. The report includes a practical remediation backlog linked to the risks and affected parts of the AI estate.
Recommendations will depend on what we find, but could include:
- Assigning owners to active agents
- Disabling abandoned or unclaimed agents
- Reviewing agents using personal OneDrive content
- Restricting unnecessary connectors and custom actions
- Identifying endpoint-based AI services and MCP servers
- Applying appropriate data loss prevention controls
- Introducing lifecycle and recertification requirements
- Improving logging and monitoring
- Adding AI disclosure and transparency language
- Reviewing third-party AI providers
- Providing targeted education for users, developers and administrators
The aim is not to fix everything at once. It is to help the organisation identify which measures will reduce the greatest concentration of risk and start there.
That is particularly important for organisations with limited resources. A realistic, prioritised plan is far more useful than a governance framework that looks impressive but never makes it into operation.
What Happens After the Assessment?
The assessment is the starting point. Once a customer understands what AI it has and where the most important risks sit, there are three practical ways forward.
Keep Watching
AI estates change quickly. A point-in-time inventory can become outdated as new agents are created, applications are installed and connections are added.
Our continuous monitoring service helps customers maintain visibility through recurring discovery, reporting and risk identification. It also keeps the remediation plan aligned with changes in the environment.
Start Remediating
Some customers will want help addressing the findings using the technology they already have.
This could involve establishing ownership, removing abandoned agents, introducing lifecycle processes, applying security controls, improving data protection, defining practical guardrails or providing targeted training.
The important point is that the work is driven by evidence. Instead of beginning with a large governance program, the customer can direct available resources towards the risks identified during the assessment.
Move Towards Agent 365 or Microsoft 365 E7
Customers looking to scale AI adoption may decide to evaluate Microsoft Agent 365 or upgrade to Microsoft 365 E7.
Microsoft 365 E7 brings together Microsoft 365 E5, Microsoft 365 Copilot, Microsoft Entra Suite and Microsoft Agent 365. It is intended to combine AI capabilities with the security, identity and governance services needed for wider enterprise adoption.
The assessment gives organizations a much better foundation for that decision. Rather than buying technology first and working out the requirements later, customers can use the findings to understand which controls they need, where they need them and what an upgrade would help them address
The First Step May Already Be Funded
Most organizations know they need better oversight of AI. What often stops them is the assumption that getting started will require a large budget, a new platform and significant internal effort.
That may not be the case.
Many organizations may be eligible for Microsoft funding that can cover the cost of the Shadow AI Hunt assessment. For qualifying customers, this can provide access to the discovery, risk report and prioritized remediation plan with only four hours of administrator involvement. Eligibility depends on Microsoft’s program criteria and must be confirmed before the engagement begins.
The assessment can then help the organization decide what comes next: continuous monitoring, targeted remediation, Agent 365, Microsoft 365 E7 or a combination of these.
AI is already inside most organizations. The question is no longer whether employees and teams are using it.
The question is whether anyone really knows what is there.