Stop Treating Embedded AI Agents Like Shadow AI
An embedded customer support agent issued an unapproved credit to a corporate client. Three days later, in an architecture review that advisor Richard Ewing described this week in CIO, the company’s leadership tried to trace that one transaction backward through production. Every monitoring dashboard was green. The network logs showed a clean, successful transaction. The cloud monitors showed standard processing time. The core financial system could not say what customer context triggered the credit, what calculation produced the amount, or which business policy authorized the spend. The software had worked. The company had lost control of a decision.
Nothing about that agent was hidden. It was in the procurement record, in the vendor’s inventory, and on every dashboard the company owned. The enterprise could see it perfectly. It could not understand it at all.
That distinction is the whole problem with AI agents in the enterprise, and the market has spent two years solving the wrong half of it.
Visibility Was Built for Shadow AI
Shadow AI demanded visibility. When employees pasted customer data into consumer chatbots and departments bought AI tools on corporate cards, the risk was that the enterprise could not see what was in use. The response was discovery: AI inventories, usage monitoring, and now agent control planes. ServiceNow’s AI Control Tower finds agents across 30 systems and can shut a rogue one down. Salesforce’s AIforce carries its permissions and governance out to agents in Slack and Claude. These are real visibility tools, and they work.
Visibility answers two questions: what agents exist, and what can they access. For shadow AI those were the questions that mattered, because an unapproved tool with unknown access is a visibility failure by definition. Find it, inventory it, control its access, and the shadow problem is largely solved.
Embedded Agents Arrive Fully Visible
Gartner forecasts that 40 percent of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5 percent in 2025. Every one of those agents passes the visibility test on arrival. It comes with the vendor’s security certification, a seat price, defined access roles, and a line in the contract. It is not shadow anything. It is the most sanctioned software in the building, and that is exactly why the existing toolset misses it.
What an embedded agent lacks is understanding, and understanding is a different set of questions. What was the agent authorized to decide, as distinct from what it was permitted to access? What business context did it act on? What did its action do in every other domain it touched? Ewing’s credit agent lived in the support application, but the money moved in the financial system, the margin hit landed in finance, and the policy it broke belonged to the business. Four domains, one decision, and no single owner. He describes the ownership vacuum precisely: the application team assumes security owns agent permissions, security assumes the process owner set the operating rules, and finance assumes the vendor built the platform to prevent violations. Everyone can see the agent. No one understands what it did.
No vendor can close that gap, because understanding requires context that ends at the vendor’s boundary. Salesforce can govern what its agents do inside Salesforce. It cannot say whether a credit those agents issued fell inside the risk appetite the board approved, because it does not hold the board’s appetite statement, the finance policy, or the ledger. A control plane sees the agent. It does not understand the decision.
Gartner has already priced the confusion. Its second forecast says 40 percent of enterprises will demote or decommission autonomous agents by 2027 because of governance gaps found only after production incidents, and it names the cause: failing to distinguish an agent’s ability to act from the scope of access it holds. Gartner does not use the words visibility and understanding, but that is the same split: what an agent can reach is a visibility question, and what it is allowed to decide is an understanding question. Read the two forecasts together and the sequence is plain. Agents are deployed on visibility alone in 2026 and pulled when the understanding gap surfaces in 2027.
IRM Was Defined to Deliver Both
When the Integrated Risk Management category was created at Gartner in 2016, it rested on one claim: risk technology has to give an enterprise both visibility of its risks and understanding of them, across the four objectives the IRM Navigator Model now organizes as Performance, Resilience, Assurance, and Compliance. Visibility without understanding is an inventory. Understanding without visibility is an audit of whatever happened to be found. Ten years on, the AI agent market has reproduced that split exactly. Control planes deliver visibility inside a platform boundary. Nobody delivers understanding across all of them.
Autonomous IRM is that original definition applied to agents: an independent function that sees every agent the enterprise runs, on every platform, and understands each consequential decision against the enterprise’s own standard rather than the vendor’s. Shadow AI needed the first half, and the market built it. Embedded agents need the second half, and the market has not. That is where the next front-runner in risk technology will be decided, and it is playing out in production right now, one green dashboard at a time.
Treating embedded agents differently from shadow AI means two things in practice. Require every agent platform to answer, for its own agents, what each one was authorized to decide and what business context it acted on, not only what it can access. Then assign the cross-platform answer, whether a decision was accurate, complete, and inside the risk appetite the board approved, to a function that sits outside all of the platforms, because none of them can see past its own boundary. The first requirement is a procurement change. The second is a seat nobody in the market holds yet.
Wheelhouse Advisors has mapped the four groups of vendors now competing for that seat, followed a single customer credit across three platforms to show what none of them can answer, and named the routes to the center. That analysis, Why the Race to Autonomous IRM Has No Front-Runner, is available exclusively on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge.
References
Ewing, Richard. “Your AI agent may have made the decision, but your company owns the risk.” CIO, September 21, 2026. https://www.cio.com/article/4223955/your-ai-agent-may-have-made-the-decision-but-your-company-owns-the-risk.html
Gartner. “Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026, Up from Less Than 5% in 2025.” Press release, August 26, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025
Gartner. “Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure.” Press release, May 26, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
Wheelhouse Advisors. “Why the Race to Autonomous IRM Has No Front-Runner.” The RTJ Bridge, September 23, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/why-the-race-to-autonomous-irm-has-no-front-runner