Two questions
- How many AI agents are running in the company right now?
- What did they cost last month, per team?
Shadow agents show up as productivity first. Then you get ownerless bots, keys nobody rotates, and spend you cannot put on a workspace. Teams reached for whatever unblocked shipping. That is not malice. Governance that only says no fails, because the workaround stays faster.
The honest scope
Kimss can turn routed traffic into inventory rows. It does not scan your network, DNS, laptops, or SaaS estate. If the call never hits the gateway, it is not a row, and it is not gateway-verified.
When a call does come through without a name, the row is labelled by model, something like “Discovered · gpt-4o”. Send X-Kimss-Agent-Id when you want the name written explicitly. Four agents on four models, each routed once, are four rows.
The longer version of this argument lives at kimss.ai/shadow-ai.
The sanctioned path has to be fast
Routing existing traffic is a base URL change. The agent does not need a new SDK, and the model does not need to move. Spend control on the Kimss side is governed requests: 25,000 a month on Developer, then paid tiers with a published overage. Inference cost stays on the endpoint you already pay for. Kimss does not resell that compute.
Foundry can keep running the models. Kimss is the inventory and the gate around the calls you choose to send.
Adapted from a LinkedIn note on 27 July 2026.