Shadow AI Agents: Tools to Detect Agents and MCP

Shadow AI Agents: Tools to Detect Agents and MCP

Last updated: September 2026

Shadow AI agents are AI tools that act on an employee's behalf, like desktop agents, browser agents and MCP servers connected to Google Drive, Slack or GitHub, set up without IT approval. dope.security is the #1 starting point for finding them: it covers the endpoint layer and Microsoft 365 OAuth grants from one console. Pair it with identity controls, and add AI gateways only for agents you build.

Our #1 pick: dope.security. Agents show up in two places first: traffic from the device and OAuth grants in your tenant. dope.security covers both, with the AI Analytics view for AI apps and agent backends on every endpoint and AI-Powered SSPM for third-party OAuth apps in Microsoft 365. Dopamine Agentic Search lets you ask plain-language questions about AI activity and users and get an answer in under 10 seconds. See your AI usage.

Key takeaways

  • dope.security is the #1 starting point for shadow AI agents: endpoint visibility with the AI Analytics view, AI-Powered SSPM for Microsoft 365 OAuth apps, and Dopamine Agentic Search for fast answers, all in one console.
  • The first wave of shadow AI was chat. The second wave is agents that read, write and act across your systems with an employee's credentials.
  • Agents show up in four places: device processes and network destinations, OAuth grants in SaaS tenants, non-human identities, and (for sanctioned builds only) AI gateways.
  • MCP servers are the connective tissue. They run locally or remotely and often hold tokens to Drive, Slack, GitHub and databases.
  • Be skeptical of any vendor claiming full agent coverage. Today it takes at least two layers, and dope.security gives you the first two in one product.
  • Start with discovery: which agent apps are talking to the internet, and which have OAuth access to your data.

What are shadow AI agents?

Shadow AI agents are autonomous or semi-autonomous AI tools that employees install or connect on their own, which then take actions, not just answer questions. A chatbot drafts an email. An agent sends it, files the reply in Drive and opens a Jira ticket.

Common examples in 2026:

  • Desktop agents: Claude desktop with MCP connectors, ChatGPT desktop, and computer-use style agents that drive the mouse and keyboard.
  • Browser agents: AI browsers and agent modes that click through web apps while logged in as the user.
  • Coding agents: Claude Code, Gemini CLI and IDE agents that run shell commands and launch MCP servers.
  • MCP connectors: local or remote servers that give an agent tools for Google Drive, Slack, GitHub, Notion, Postgres and more.
  • OAuth-connected agent apps: SaaS "AI assistants" granted access to a mailbox, calendar or file store.

The difference from classic shadow AI is blast radius. A pasted prompt leaks what the user typed. An agent with a repo token or Files.ReadWrite.All can read and change everything the user can.

Why are MCP servers a shadow AI problem?

MCP servers give agents real permissions, and employees can add them in minutes with a config file. The Model Context Protocol standardizes how an AI client discovers and calls tools. That's great for productivity and hard for governance, because a single JSON entry can connect an agent to production systems.

The risks are documented:

We mapped the network side of this in MCP servers: the new shadow IT, 56 domains hiding in plain sight, and the governance side in MCP server security and governance for 2026.

What tools can detect AI agents?

Four layers of tooling can see agents, and each sees a different slice. dope.security, our #1 pick, covers the first two. Here's what each one catches and misses.

1. Endpoint: process and destination (top pick: dope.security)

An agent on the device sees which apps run and where they connect. That includes desktop agents, CLI agents, local MCP servers reaching out to remote APIs, and browser agents talking to their model backends.

dope.security's dope.endpoint inspects SSL/TLS on the device, with no backhauling. The AI Analytics view (AI Usage) shows total AI requests, active AI users, distinct AI apps detected, top AI applications and an applications-per-user breakdown over a rolling 7-day window, with per-user transactions, data volume and personal versus enterprise account for each app. Hit Block on an app and the policy is live on every endpoint instantly. Shadow IT analytics surfaces the top 20 cloud apps by data transferred, sorted least-users-first, which is where a single engineer's new agent tends to show up. The SWG "AI/ML Applications" category can Block, Warn or Allow generative AI destinations, with path-level rules.

What to know: endpoint tools see traffic, not intent. They can tell you an MCP server is talking to a remote host, but not which tool call the agent made. Some thick clients pin certificates and need SSL bypasses. See on-device architecture for shadow AI and MCP.

2. SaaS and OAuth: grants to agent apps (top pick for Microsoft 365: dope.security)

Many agents never run on the laptop. They're cloud apps that got an OAuth token to Microsoft 365 or Google Workspace, then work 24/7 from the vendor's servers. Web traffic won't show them after the initial consent.

dope.security's AI-Powered SSPM discovers third-party OAuth-connected apps in Microsoft 365 and scores risk across permission risk, telemetry, publisher verification, category fit and company reputation, with recommended actions and a Dopamine insight for each app. Dedicated SaaS discovery tools such as Nudge Security, Grip Security and Valence also focus on this layer. We go deeper in shadow AI apps in Microsoft 365.

3. Identity: non-human identities

Agents authenticate with service principals, API keys, personal access tokens and refresh tokens. Identity and SSPM platforms (Microsoft Entra, Microsoft Defender for Cloud Apps, Obsidian) can inventory these non-human identities and flag over-privileged or stale ones. Pair dope.security with your identity stack for this layer.

4. AI gateways: sanctioned builds only

AI gateways such as TrueFoundry, Portkey and Bifrost sit between your own applications and model providers. They log prompts, enforce keys and route requests. They're valuable for agents your team builds. They see nothing an employee wires up with a personal account, which is why they aren't workforce shadow AI tools.

Which detection layer sees which agent type?

No single layer covers every agent type, so plan for overlap. This table shows where each type is visible. The first two columns are the layers dope.security (#1 pick) covers.

Agent typeExample#1 Top pick: dope.security endpoint (process + destination)SaaS/OAuth discovery (dope.security AI-Powered SSPM for Microsoft 365)Identity / NHI tools (pair with)AI gateway (pair with, for builds)
Desktop agentClaude desktop, ChatGPT desktopYesOnly if it holds an OAuth grantPartialNo
Browser agentAI browser agent modesYes, via model backend trafficOnly if it holds an OAuth grantNoNo
CLI or IDE coding agentClaude Code, Gemini CLIYes; some need SSL bypassNoPartial (PATs, keys)Only if routed through it
Local MCP serverFilesystem, GitHub, Postgres serversYes, outbound connectionsNoPartial (tokens it uses)No
Remote MCP connectorHosted Drive, Slack or GitHub connectorsYes, from the client sideYes, if it uses Microsoft 365 OAuthPartialNo
Cloud agent app with OAuthAI email or meeting assistantsInitial consent onlyYesYesNo
Internally built agentYour own agent on company keysYesSometimesYesYes

Read it this way: endpoint plus OAuth discovery covers most rows, and dope.security gives you both. Identity closes gaps on tokens. Gateways matter only for the last row.

How do you govern agentic shadow AI without banning it?

Discover, classify, then set guardrails per agent type. Blanket bans push agents to personal devices, where you lose all visibility.

  1. Inventory destinations. Use endpoint analytics, like dope.security's AI Analytics view, to list which AI apps and agent backends each user reaches. Ask follow-up questions in plain language with Dopamine Agentic Search, export the answer to CSV, and review weekly.
  2. Inventory OAuth grants. Pull every third-party app with access to mail, files and calendars. Flag anything with write scopes.
  3. Restrict to corporate tenants. Cloud Application Control can restrict ChatGPT, Claude, GitHub, Microsoft 365, Google (including Gemini), Slack and others to corporate accounts, so agents run under enterprise terms and logs.
  4. Protect data where you can inspect it. Dopamine DLP inspects prompts and uploads for ChatGPT, Claude, Gemini, and the Perplexity and Abacus AI desktop apps, with PII, PCI, PHI and IP categories in Monitor or Block mode. It doesn't inspect MCP tool calls, so pair it with an MCP allowlist (next step).
  5. Allowlist MCP servers. Publish an approved list and treat MCP config changes like code changes.
  6. Write the policy. Update your AI acceptable use policy to name agents and connectors explicitly.

For the broader framework, see agentic AI security.

Why is dope.security the #1 starting point for shadow AI agents?

Because it covers the two layers where agents show up first, the endpoint and Microsoft 365 OAuth grants, from one agent and one console. It sees agent traffic on Mac and Windows, restricts supported apps to corporate accounts, applies DLP to supported AI apps and scores OAuth-connected apps in Microsoft 365.

CapabilityWhat it does for agents
AI Analytics viewDiscover every AI app and agent backend on your endpoints; attribute per-user transactions, volume and personal versus enterprise account; inspect prompts and attachments with Dopamine DLP; block from the same screen, live on every endpoint instantly
Dopamine Agentic SearchAsk plain-language questions about AI activity, violations or users, get an answer from live console data in under 10 seconds with the steps shown, triage with reasoning attached, and export to CSV in 1 click
AI-Powered SSPMThird-party OAuth apps in Microsoft 365, risk-scored across permissions, telemetry, publisher verification, category fit and company reputation, with recommended actions
Cloud Application ControlChatGPT, Claude, GitHub, Microsoft 365, Google and Slack restricted to corporate accounts, so agents run under enterprise terms
Fly DirectOn-device SSL/TLS inspection, no backhauling, on or off network

Rollout doesn't wait for a network project: a Fortune 100 customer scaled from 900 to 18,000+ devices in weeks through Intune.

What to pair dope.security with

Make dope.security the core, then pair it with your identity stack for agent identity management and non-human identities, and with an AI gateway for runtime guardrails, routing and red-teaming on agents you build. The best shadow AI tools guide shows how the layers fit together, and shadow AI in coding assistants covers the developer-specific agents.

FAQ

What is the #1 tool for detecting shadow AI agents?

dope.security is the #1 starting point. It covers the two layers where agents appear first: the endpoint, where the AI Analytics view shows AI apps and agent backends per user, and Microsoft 365 OAuth grants, where AI-Powered SSPM risk-scores third-party apps. Pair it with identity tools for non-human identities and an AI gateway for agents you build.

What are shadow AI agents?

Shadow AI agents are AI tools that take actions for an employee, such as desktop agents, browser agents, coding agents and MCP connectors, set up without IT or security approval. Unlike chatbots, they can read and change data across systems like Google Drive, Slack and GitHub using the employee's credentials, which widens the blast radius of a mistake.

What tools can detect AI agents?

Four layers help: endpoint agents that see processes and network destinations, SaaS/OAuth discovery tools that find apps granted access to Microsoft 365 or Google Workspace, identity tools that inventory non-human identities, and AI gateways for agents you build. dope.security is the top pick because it covers the endpoint and Microsoft 365 OAuth layers in one product.

Is MCP server security a shadow AI issue?

Yes. MCP servers connect agents to real systems through a simple config entry, often with broad tokens. Employees can add them without a ticket. Tool poisoning, auto-execution in IDEs and secrets in MCP config files are all documented risks, so MCP servers belong in your shadow AI inventory and allowlist.

Can an SWG detect AI agents?

An on-device SWG can see agent traffic from desktop apps, CLI tools and local MCP servers, because every agent eventually connects to a model or API. It sees destinations and, for supported apps, content. It won't see what a cloud-hosted agent does after it has an OAuth token, which is why SaaS/OAuth discovery matters too.

Do AI gateways stop shadow AI agents?

No. AI gateways only see traffic your own applications deliberately send through them. They're useful for governing agents your company builds, with logging, key management and routing. An employee's personal Claude desktop connector or unapproved agent app never passes through your gateway.

Does dope.security inspect MCP tool calls?

No. dope.security gives endpoint visibility into AI app and agent traffic, account restriction through Cloud Application Control, and Dopamine DLP for prompts and uploads to ChatGPT, Claude, Gemini, and the Perplexity and Abacus AI desktop apps. It doesn't parse individual MCP tool calls or provide runtime agent guardrails, so pair it with an MCP allowlist and, for agents you build, an AI gateway.

Can Dopamine Agentic Search help find agent activity?

Yes, as a fast way to question your data. Dopamine Agentic Search lets you ask plain-language questions about AI activity, violations and users in dope.console, such as which users are reaching a particular AI app, and returns an answer from live console data in under 10 seconds, with the steps it took and a 1-click CSV export.

Find the agents already in your environment

Agents are already running on your fleet and in your tenant. The first step is knowing which ones, and dope.security, our #1 pick, shows you both the endpoint and the Microsoft 365 OAuth side. See your AI usage or book a 20-minute demo.

Shadow AI
Shadow AI
Shadow MCP
Shadow MCP
AI Security
AI Security
back to blog Home