What’s Hiding in the Shadows?

Three shadows, three different problems

Shadow IT

Shadow IT means using technology without the approval or knowledge of those in charge. This could be an unauthorized SaaS app, a personal cloud storage account, or a department tool that skipped security review. The usual questions follow: Where is the data? Who can access it? Is it secure and compliant?

Shadow AI

Shadow AI is the same idea, but with AI tools, models, and services. In a contact centre, this might look like someone pasting a customer interaction into their personal AI account to summarize it, uploading a spreadsheet for analysis, or using an outside tool to draft customer replies.

Usually, the tool itself isn’t the problem. The real issue is that no one knows what data left the company, where it went, or what happened to it.

And it isn’t rare. In a June 2026 PagerDuty survey of 1,250 office professionals at large companies, 66% said they had used AI tools at work even though they believed company policy did not permit it. OneTrust’s 2026 AI-Ready Governance Report found that only 48% of organizations had clear visibility into both approved and unapproved AI use, and one-third had seen employees turn to unauthorized AI because the approved route was too slow.

Shadow Agents

Shadow Agents are AI agents working inside or alongside the organization without proper oversight or approval, especially those that can access systems or take actions.

A Shadow AI tool might summarize a customer call, while a Shadow Agent could update the CRM, open a case, reschedule an appointment, send a message to the customer, or hand the task to another agent.

This changes the question. It’s no longer just about what the AI can see, but what it is allowed to do.

When AI builds agents, the stakes go up

A new trend is emerging: AI is now used to help create other AI agents. Today’s frameworks can gather context, use tools, write code, and set up working agents much faster than traditional projects.

This is real progress, but it also means the number of agents and tool connections in an organization can grow faster than any architecture review board can manage.

Setting up an agent is just the start. Agents are tested, adjusted, and changed over time, and each change can affect what they know, what tools they can use, and what they can do. Discovery isn’t a one-time task. You need to keep track of which agents exist, who owns them, and what authority they have right now.

Why this is a CCaaS architecture problem

I’ve worked with Genesys and contact centre systems for about twelve years. While the technology has changed a lot, one thing stays the same: the contact centre touches a huge amount of enterprise data and processes. Today’s CCaaS platforms bring it all together, and AI reasons increasingly, orchestrates, and acts.

Genesys shows where this is heading. At Xperience 2026 in September, it launched an AI Control Plane focused on centralized discovery, identity, policy, and observability, along with Navigator, Orchestrator, and Contextual Intelligence. (Navigator and Orchestrator are scheduled for general availability between late 2026 and spring 2027.) The goal is to coordinate AI, people, and systems while keeping decisions within clear business boundaries.

Its Agentic Virtual Agent follows the same idea: defined controls, built-in guardrails, explainable decisions, and auditable outcomes. That is what makes governed autonomy different from simply handing over control to AI.

Genesys isn’t alone. Microsoft made Agent 365 generally available in May 2026 as a control plane to observe, govern, and secure agents, including those that were never registered. The point isn’t about any single vendor. Once a CX platform becomes the layer where work is orchestrated and executed, AI governance becomes core to the architecture.

You can’t govern what you can’t see

This is the biggest change Shadow Agents bring.

Cloud Security Alliance research from April 2026 found that 82% of enterprises had discovered at least one previously unknown AI agent in the past year. In a separate CSA survey, 54% reported between one and 100 unsanctioned agents, and just 15% said three-quarters or more of their agents had a clear owner.

Unknown agents don’t only come from employees experimenting, either. Gartner has found that 61% of senior cybersecurity professionals have seen AI agent automation appear in enterprise software they had already approved. In a contact centre, that could be an agentic feature switched on in a platform you have run for years.

That makes discovery and observability foundational. You must know what AI is running, what it is connected to, which identity it uses, what data and tools it can access, and what actions it can carry out. And when an agent takes an action, you need enough telemetry to reconstruct what happened.

You can’t govern an agent you don’t know about, and you can’t control authority you didn’t realize you gave.

From data governance to authority governance

Most AI governance talks have focused on data: what the model can see, where the data goes, whether the provider keeps it, and which laws apply. These questions still matter. But now, agents add a new question: authority.

For every AI agent involved in a customer journey, I’d want clear answers to these:

Identity: What is this agent, and who owns it?

Discovery: How did we find it, and are we sure we have found them all?

Data: What customer and enterprise information can it access or infer?

Authority: What can it do, and on whose behalf?

Boundaries: What is it explicitly not allowed to do?

Authentication: How thoroughly must the customer be verified before the agent acts?

Human approval: Which decisions need a person to sign off?

Observability: Can we reconstruct its prompts, tool calls, decisions, and actions?

Lifecycle: Who can change its instructions, permissions, models, or tools, and who can retire it?

What this means for platform selection

For years, people have evaluated CCaaS based on channels, routing, workforce engagement, reporting, integrations, reliability, and cost. All these still matter.

But as AI handles more of the customer journey, buyers need to ask tougher questions. Can the platform spot which AI is involved in customer journeys? Can agents have their own identity and permissions? Can you limit which tools they use? Can you apply policy before an action happens? Can the platform require human approval? And can you audit agent actions across different systems?

The focus moves from asking “Does the platform have AI?” to “Can it govern the AI acting for us?” That’s a much harder test.

Blocking AI isn’t the answer

The natural reaction is to tighten all the controls. I don’t think that works.

Shadow IT taught us that people find ways around technology and rules that slow them down, and Shadow AI is proving this again, only faster. If an employee can solve a problem in ten minutes with an outside AI tool, while the approved way takes months, it’s no surprise they take the shortcut.

That doesn’t mean customer data should be put at risk. But the fact that these workarounds happen shows how the organization really works, and more policies or training alone won’t fix it. What works is clear policy, approved tools people want to use, technical controls, and real visibility.

This is where CCaaS platforms have an opportunity. A platform that lets business teams experiment and automate while still maintaining discovery, identity, permissions, policy, observability, and human oversight becomes more than a communications tool. It becomes part of how the organization governs AI.

The next shadow is even harder to spot

Shadow IT was about unmanaged applications. Shadow AI brought unmanaged data and intelligence. Shadow Agents add something new: unmanaged authority.

For customer experience leaders, the issue isn’t just whether employees use unauthorized AI. It’s whether any agent, anywhere in or connected to the customer journey, can act in ways the organization doesn’t fully understand.

As CCaaS platforms move from just routing interactions to orchestrating outcomes, governance should shift from controlling access to understanding actions.

So, what authority have we really given AI to act for our customers and our organization? And do we know every agent that holds it?

Next
Next

Data Residency Is Not Data Sovereignty