By Jeff Harrell | Director of Product Marketing at Cequence. Original article can be found here: https://www.cequence.ai/blog/ai/ai-discovery/
Your company’s agentic AI footprint is bigger than you think
Ask a security team to count the AI agents running in their environment and you’ll get a reasonable answer: the sanctioned Copilot deployment, a Claude rollout, a handful of MCP servers the platform team stood up for Microsoft 365 and Atlassian. But when a global financial services organization with more than 2,000 employees ran its first agentic AI discovery report with Cequence AI Gateway, it found 740% more MCP servers, 800% more AI agents, and 600% more LLM providers than they expected. Every employee was using at least one agent. The security team hadn’t been careless; they gave the answer almost any of us would have given, and it was wrong by nearly an order of magnitude.
IBM’s Cost of a Data Breach 2026 put the average AI-enabled breach at $6 million and found that 43% of security incidents now involve shadow AI, roughly double the prior year. Among organizations breached through an AI application, 92% had failed to control access to it, and the most common entry point was a compromised API or plug-in.
The agentic insider threat
The security stack isn’t malfunctioning. A shadow agent authenticates with valid credentials, usually the credentials of the employee who deployed it. The WAF compares each request against its signatures and passes it. The API gateway verifies the token and forwards the call. Neither maintains state across a session, so a chain of individually legitimate tool calls that wanders outside the agent’s intended job registers as a series of unrelated, authorized events. Every existing check passes, and the aggregate behavior stays invisible.
An ungoverned agent is an insider with credentials, privileges, and network reach, operating at machine speed. And these insiders multiply quickly, because agent deployment is now near-instant: a marketing analyst can connect an agent to an MCP server without a ticket or review from the security team. The consequences accumulate quietly: expanded attack surface, credential sprawl, sensitive data moving through unintended channels, and an incomplete inventory that slows incident response at the moment when speed matters most.
AI discovery starts in the SIEM
Most approaches to finding shadow AI start by deploying something new: an endpoint agent, a browser extension, an inline proxy. Endpoint agents require an MDM rollout and miss unmanaged devices. Browser extensions miss everything that doesn’t run in a browser, which describes most agents. Inline proxies require rerouting traffic and then waiting for enough of it to accumulate to say anything useful. Each one puts a long, complicated project between the security team and the visibility they require, all while the shadow inventory continues to grow.
The AI discovery evidence already exists. Agent traffic, MCP sessions, and LLM API calls leave traces in the logs a SIEM collects. AI discovery built on that telemetry requires no new software, and is immediately able to produce actionable reports with historical data across whatever period the logs cover.
A discovery report also goes stale within weeks. The financial services numbers above were a snapshot of a footprint that changes constantly, so discovery must run regularly. And the inventory has to feed a central control to bring those newly discovered items under governance.
Frameworks and regulators require a maintained inventory
The Govern 1.6 section of the NIST AI Risk Management Framework calls for mechanisms to inventory AI systems, and ISO/IEC 42001 expects organizations to document the resources behind each AI system across its life cycle (Annex A.4.2). The OWASP agentic and MCP Top 10 lists name shadow MCP servers, rogue agents, identity and privilege abuse, and missing telemetry as canonical failure modes. The EU AI Act’s Article 50 transparency obligations apply today, and while the deployer duties in Articles 14, 26, and 49 were deferred to December 2027, each requires knowing which AI systems are in scope.
How Cequence AI Gateway approaches AI discovery
The AI Discovery capability in the Cequence AI Gateway works from an organization’s existing SIEM logs. Read-only SIEM access is the entire deployment: no endpoint agent, no browser extension, no inline proxy required. The first report covers whatever historical period you choose, and sensitive log data never leaves the SIEM; only the resulting reports are stored in AI Gateway. Reports refresh on a schedule, with 30 days of trend history, so the inventory reflects the AI footprint as it changes rather than a single point in time. It’s the same capability that produced the financial services findings above.
Discovery then feeds directly into governance. Discovered MCP servers can be added to the AI Gateway MCP Registry, with credentials brokered by the platform instead of the agent. Each discovered agent, once approved, gets bound to an Agent Persona: a plain-language job description compiled into enforceable policy. That is the Agentic Zero Trust model — judge an agent on its behavior and the actions it takes across its full session, constraining it the moment it attempts to stray from its job. Audit trails export in OTEL format back to the same SIEM the discovery data came from.
AI Gateway agentic AI discovery highlights:
- Maps your full agentic AI footprint: shadow MCP servers, agents, and LLMs
- Integrates with your SIEM: no agents, extensions, or proxies to deploy
- Actionable from the first report; the data is already in your SIEM
- Feeds directly into the AI Gateway registries and Agent Personas






