AI Models & Platforms

The Next Shadow IT Problem Will Be Shadow Agents

mm
Add Unite.AI to your preferred sources on Google

Shadow IT used to mean an employee signing up for a SaaS tool without asking, or a department running its own subscription until IT found out the hard way. We got that under control with better visibility, procurement discipline, and cloud governance.

Agents are going to reset that problem, and they’ll move faster than SaaS or cloud ever did, because this time the unauthorized system doesn’t just sit there. It acts.

Autonomy Sprawl

Finance builds its own agents. So do HR, sales, procurement, and customer service. Employees spin up personal agents. Vendors quietly embed agents into the products we already pay for.

Multiply that across a large organization and the CIO isn’t tracking twenty agents anymore. It’s hundreds or thousands of software entities, each with some ability to touch systems and take action. IBM has predicted large enterprises will be running more than 1,600 AI agents by the end of this year. Gartner has warned that agents create infrastructure, identities and access privileges faster than governance processes can track them.

CIOs’ priority for 2027 will be taking an actual inventory. Who built each agent, what it does, what systems it touches, what permissions it has, and who owns it. Without that, there’s no governance program; just an assumption that someone else is watching.

Human-in-the-Loop Doesn’t Scale

“Keep a human in the loop” was a reasonable answer when there were a handful of agents. It stops being one, once an enterprise is running thousands of agents executing an enormous volume of actions. There aren’t enough people or hours for that.

The fix is risk-based autonomy, not blanket oversight. An agent updating an internal record doesn’t need the scrutiny a financial transaction does. What should determine the level of human involvement: the dollar value of the action, how sensitive the data is, the agent’s confidence level, regulatory exposure, and whether the agent is acting outside its expected parameters.

Gartner has outlined a similar model, including checkpoints ranging from pre-execution approval to mid-task intervention to post-execution review and periodic sampling. The target isn’t a human in the loop everywhere. It’s a human at the right point in the loop.

Agents Managing Agents

Right now, most organizations are still in the phase of one human directing one agent. Next comes multi-agent systems: specialized agents that talk to each other, hand off tasks, and run entire workflows without a person in the middle.

A procurement agent flags a need, checks with a finance agent on budget, and triggers a purchasing agent to execute; no human touches any of it. McKinsey calls this emerging architecture an “agentic mesh.” Deloitte found only 15% of organizations have scaled cross-functional multi-agent adoption, and just 5% say their business processes are highly prepared for it.

The risk changes shape here. It’s no longer “did one agent make a mistake.” It’s how far that mistake propagates through a network of agents and systems before anyone notices. CIOs will need to govern not just individual agents but the relationships and dependencies between them.

Agent Economics Aren’t SaaS Economics

Agents don’t answer a prompt once and stop. They run continuously, call models repeatedly, hit APIs, consume cloud resources, and trigger other agents. That’s a different cost profile than adding a SaaS seat, and it lacks predictability.

A workflow that looks cheap in a pilot can get expensive fast once hundreds of agents are running it in production continuously. IBM projects AI spending will rise from just under 15% of IT budgets in 2025 to nearly 25% by 2027, and found that 85% of technology leaders still lack full visibility into real-time AI spending.

Know the cost of an agent per task, per workflow, per business outcome. Not just the price of the underlying model.

From Managing Technology to Managing Autonomy

For decades, my job as a CTO has basically been managing systems that people use. That’s changing. Now I’m managing systems that act on people’s behalf, and that’s a different kind of job entirely.

So, when I think about who’s going to come out ahead in 2027, it’s not the CIO with the most agents deployed. It’s the one who can actually tell you which agents they’ve got, what those agents are allowed to do, who’s on the hook for them, what they cost, and the ROI of the investment. 

We spent 2026 figuring out how to get AI into production. 2027 will be about figuring out what to do once it’s out there acting on its own, and how to govern it in a way that enhances security and compliance without sacrificing efficiency.

Jeremy Ung is the chief technology officer of BlackLine. He oversees the company's global technology direction with an emphasis on enhancing its solutions for the office of the CFO through connected data and AI-powered platforms that will accelerate the company’s ability to scale and continuously deliver customer value.