Shadow AI Crisis: CrowdStrike Unveils Falcon Guardian for Agent Security

- CrowdStrike introduced Falcon Guardian to provide runtime visibility and security for autonomous AI agents.
- A Fortune 500 company discovered 18,000 active AI agents despite having approved only 300.
- The tool addresses the gap where traditional identity and governance tools fail to track non-human AI identities.
- Security focus has shifted from prompt-level governance to endpoint execution to stop real-time data exfiltration.
The corporate landscape is currently witnessing a silent explosion of autonomous software. While executives discuss AI strategy in boardrooms, employees across all levels are deploying AI agents to automate their workflows, often bypassing IT oversight entirely. This phenomenon, known as shadow AI, has reached a critical mass where traditional security perimeters are no longer sufficient.
During the Fal.Con 2026 keynote, CrowdStrike President Michael Sentonas revealed a staggering case study that illustrates the scale of this invisibility. A Fortune 500 customer activated an agent discovery tool and immediately found 18,000 AI agents active on its endpoints. The company had officially approved only 300. This massive discrepancy highlights a dangerous blind spot: the gap between corporate policy and actual employee behavior.
The shift from execution to agency
For decades, software operated on a deterministic model; it performed exactly what it was programmed to do. However, the rise of agentic AI has changed the fundamental nature of computing. As Sentonas noted, software has moved from simple execution to agency, meaning it can now reason, plan, and decide how to accomplish a goal autonomously.
This autonomy introduces a new layer of risk. AI agents often operate with the full permissions of the users they serve, allowing them to access sensitive enterprise systems and execute tasks at machine speed. When these agents are deployed as shadow AI—driven by employees fearing layoffs or seeking efficiency through vibe coding and API integrations—they operate outside the view of security teams. Tools like Falcon Guardian are designed to close this gap by focusing on where the action actually happens: the endpoint.
Why the endpoint is the critical control point
Many organizations have attempted to secure AI by focusing on the prompt layer or through high-level governance. While these measures are useful for policy, they cannot stop an agent that is already in motion. CrowdStrike CEO George Kurtz argues that the only way to solve the agent problem is at the endpoint and within cloud workloads, because that is where agents execute their tasks and connect to user identities.
The logic is straightforward: an AI agent may reason at the AI layer, but it interacts with files, credentials, networks, and applications through the operating system. By integrating AI agent activity with endpoint telemetry, security teams can establish a direct causal chain from the initial prompt to the actual runtime behavior. This allows for the detection of malicious actions that would be indistinguishable from legitimate user activity if viewed in isolation.
Combatting the proliferation of non-human identities
The scale of the identity crisis in the agentic enterprise is immense. Research from Software Analyst Cyber Research (SACR) and Stanford Graduate School of Business indicates that enterprises now run approximately 144 non-human identities for every single human user. When ephemeral instances and shadow agents are included, the number of active identities per team can reach into the thousands.
Traditional identity and access management (IAM) systems were built for humans and deterministic machine identities. They are not equipped to handle the fluid, decision-making nature of AI agents. This has led to a scenario where only 18% of enterprises isolate their highest-risk AI agents, and a mere 8% combine that isolation with active enforcement. The result is a sprawling ecosystem of agents—including tools like Claude Code, Cursor, OpenAI Codex, and Kiro—that can potentially move laterally through a network without triggering traditional alarms.
Runtime protection against autonomous threats
To address these vulnerabilities, Falcon Guardian introduces several key capabilities aimed at runtime enforcement:
- AI Agent Discovery: A live inventory of known and shadow agents across Windows and macOS, identifying who deployed them and their current security status.
- AI Gateway: A centralized control point for monitoring and managing enterprise AI traffic.
- Causal Chain Visibility: The ability to link a prompt to a specific system action, allowing security teams to understand the blast radius of a potential threat.
- Runtime Blocking: The capacity to stop malicious exfiltration in real-time, such as preventing an agent from sending AWS credentials to an external server.
In a controlled demonstration, CrowdStrike showed how a Claude Code agent could be manipulated via a GitHub issue thread to load a malicious skill and exfiltrate credentials. While the agent followed the instructions, the Falcon sensor blocked the exfiltration attempt and identified 12 other agents that had utilized the same compromised skill.
The economics of shadow AI adoption
The drive toward shadow AI is not merely a technical trend but a cultural one. A flourishing underground economy of apps and skills is emerging, fueled by employees taking crash courses in Python and API integration to remain competitive in an AI-driven job market. This creates a paradox where the very tools intended to increase productivity also create systemic vulnerabilities.
CrowdStrike has integrated the discovery capabilities of Guardian into its Falcon Flex consumption-based licensing model. This allows existing customers to activate the module without a lengthy procurement cycle, acknowledging that the speed of AI deployment requires a security response that is equally rapid. The goal is to provide runtime visibility on the agent, ensuring that as software gains more agency, it does not lose its accountability.
Global implications for US and UK enterprises
For businesses operating in the USA and UK, the rise of autonomous agents complicates an already dense regulatory environment. In the US, where the focus remains heavily on risk management and sector-specific guidelines, the discovery of thousands of unauthorized agents could be viewed as a failure of internal controls during audits or insurance renewals. The ability to prove that AI agents are monitored at runtime will likely become a requirement for cyber insurance eligibility.
In the UK, where the approach to AI regulation has historically been more pro-innovation and less prescriptive than the EU's AI Act, the burden of safety falls largely on the enterprise. However, the sheer volume of non-human identities creates a massive surface area for data breaches. For UK firms, the priority is shifting toward the three essential questions posed by industry blueprints: Where are the agents? What can they connect to? And what can they actually do?
Across both markets, the transition from deterministic software to agentic AI means that governance is no longer enough. Companies must move toward a model of continuous runtime monitoring to ensure that the efficiency gained from AI agents does not come at the cost of total system compromise.
FAQ
What is the difference between AI governance and runtime security?
Governance focuses on policies and rules about how AI should be used, while runtime security monitors and blocks actual actions as they happen on the system to prevent breaches.
What are shadow AI agents?
These are AI tools or autonomous agents deployed by employees within a company without the knowledge or approval of the IT and security departments.
Why is the endpoint considered the best place to secure AI agents?
Because AI agents must eventually interact with the operating system to access files, networks, and credentials, making the endpoint the only place with complete visibility of their execution.
Which AI agents were specifically mentioned as being discovered in the Fortune 500 case?
The discovery included agents such as Claude Code, OpenAI Codex, Cursor, and Kiro.
Sources: Venturebeat, Crowdstrike (2) ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email






