Shadow agents

Count the agents. Then count the rows.

Ask your platform team two questions. If the answers are “not sure” and “a handful of invoices,” you do not have a strategy gap. You have an inventory gap.

A job can ship for weeks and still be invisible to the people who own risk.
On this page Two questions The honest scope The sanctioned path has to be fast

Two questions

  1. How many AI agents are running in the company right now?
  2. What did they cost last month, per team?

Shadow agents show up as productivity first. Then you get ownerless bots, keys nobody rotates, and spend you cannot put on a workspace. Teams reached for whatever unblocked shipping. That is not malice. Governance that only says no fails, because the workaround stays faster.

The honest scope

Kimss can turn routed traffic into inventory rows. It does not scan your network, DNS, laptops, or SaaS estate. If the call never hits the gateway, it is not a row, and it is not gateway-verified.

When a call does come through without a name, the row is labelled by model, something like “Discovered · gpt-4o”. Send X-Kimss-Agent-Id when you want the name written explicitly. Four agents on four models, each routed once, are four rows.

The longer version of this argument lives at kimss.ai/shadow-ai.

The sanctioned path has to be fast

Routing existing traffic is a base URL change. The agent does not need a new SDK, and the model does not need to move. Spend control on the Kimss side is governed requests: 25,000 a month on Developer, then paid tiers with a published overage. Inference cost stays on the endpoint you already pay for. Kimss does not resell that compute.

Foundry can keep running the models. Kimss is the inventory and the gate around the calls you choose to send.

Adapted from a LinkedIn note on 27 July 2026.

Read the shadow-agent page

Two numbers. No install required to ask the question.