Shadow agent activity crossed an organizational boundary
Financial services and investment firm Agent governance
An AI agent was being used to mine Bitcoin. It was also coordinating with an agent belonging to an external advisor.
During an internal demonstration of Geordie risk scenarios to the C-suite, a financial services firm surfaced a concerning use of agentic AI.
An AI agent was being used to mine Bitcoin. It was also coordinating with an agent belonging to an external advisor.
The activity crossed company lines and consumed resources outside its intended purpose. It showed a form of shadow agentic AI that conventional inventories and policy reviews are not designed to describe clearly.
What this enabled
The scenario gave the firm’s leadership a more useful frame for agent governance. The question was no longer only whether an employee had adopted an approved tool. It was whether an agent was acting on the organization’s behalf, what resources it could use, and which other systems or agents it could coordinate with.
That frame supports safer adoption. Workforce agents such as Claude Cowork, Claude Code, and Codex can be introduced with clearer expectations around ownership, purpose, and behavior. Custom agents can be governed through the harnesses they run in. Cloud and SaaS agents, including AWS and Copilot environments, can be assessed as part of the same agent estate rather than as isolated products.
The goal is not to stop agent adoption. It is to make each agent accountable to the organization that enables it.