
On September 1, 2026, at its Fal.Con conference in Las Vegas, CrowdStrike introduced Falcon Guardian, an endpoint tool built to inventory, control, and shut down unauthorized AI agents. The same day, a six-month-old startup called AIR Security emerged from stealth with $50 million to build an inline firewall for agents, vetting every skill, plugin, and MCP server before it’s allowed near enterprise data. Two well-capitalized companies, one Las Vegas conference floor, one problem: enterprises have agents running that IT never approved, and nobody can say with confidence what those agents can touch.
The scale nobody sized correctly
“Shadow IT” used to mean a marketing team expensing an unapproved SaaS subscription. Shadow agents are a different order of risk. An agent can read files, call APIs, and take action with the permissions of whoever built it, and it can do all of that without a human approving each step. Two independent surveys published this year put numbers on how far ahead of governance that risk has run.
Shadow agents, by the numbers
Figures are vendor- and industry-sponsored survey data, cited here as directional evidence of the trend, not an independent OnClik audit.
AIR’s own research illustrates why detection is now urgent rather than aspirational: a test skill it built passed the security scanners available to it and reached more than 26,000 agents before being pulled. That is the shape of the exposure. It doesn’t require a sophisticated attacker, just an agent with a plugin nobody reviewed.
Two companies, two ways of hunting the same problem
Falcon Guardian and AIR take different routes to the same conclusion: agents that already exist ungoverned need to be found, watched, and, where necessary, stopped.
Two different routes to the same problem
“AI hasn’t changed the attack, it has changed its speed.” — George Kurtz, CEO, CrowdStrike
Detection is progress. It isn’t the fix.
Both launches start from the same assumption: the agents already exist, so the job is to find them and contain the damage. That’s a genuinely useful layer, and enterprises without any agent visibility today should welcome it. But it treats a symptom. Neither product asks why an employee could stand up an autonomous agent with real system access in the first place, without a security review, a change ticket, or anyone in IT knowing it happened.
That’s the part worth sitting with at the CXO level. A firewall for agents is necessary precisely because most enterprises built their automation the way they built shadow IT: piecemeal, tool by tool, agent by agent, with governance added after the fact because no single platform owned the decision of who gets to build what. Bolting detection onto that sprawl is progress. It is not the same as never having the sprawl.
The alternative is governance that lives inside the automation layer itself, not a separate product watching it from the outside. When every agent is provisioned, permissioned, and audited inside one platform, there’s no shadow layer to go hunting for, because there was never a path for an ungoverned agent to exist in the first place. That’s the difference between policing agent sprawl and never creating it.
Questions worth asking before your board asks them
Enterprises that get ahead of this won’t be the ones with the best agent-hunting tools. They’ll be the ones that never had a shadow layer to hunt, because governance was built into how agents get created in the first place.


