Your Newest Employee Is an AI Agent Nobody Hired


Somewhere in your business, there is a decent chance software is already reading files, updating records, or drafting messages on its own, connected by an employee, reviewed by no one, and logged nowhere. It was never interviewed, never onboarded, and never given a job description. This is the newest layer of workplace AI risk, and for most small and medium businesses it is completely invisible.
For the past two years, "AI at work" mostly meant chat: an employee asks, the AI answers, the employee decides what to do with it. That era had risks, mainly around what people paste into the chat box. But the model is changing underneath us. AI is moving from answering to acting, and the difference between those two words is the difference between a search engine and a coworker with keys.
An app receives your data. An agent reaches into your systems.
An AI agent is an AI that can do things: read your files, send email, create tickets, update records, run commands. It connects to your business systems through lightweight connectors, gets a goal in plain English, and then decides for itself which steps to take.
The part that surprises most owners is who sets these up. Not engineers. Anyone. A capable employee can connect an AI assistant to project tools, documentation, and code repositories in a few clicks, no IT ticket required. From that moment, the agent can read, create, update, and delete across all of those systems on the employee's behalf, from a single instruction like "clean up the backlog and update the status pages."
The employee supplies the goal. The agent chooses the steps. Every ticket created, page rewritten, or file changed happens without a human confirming each one. When a person submits a prompt, there is at least a moment where a control can intercept it. When an agent acts on its own, there is no human in the loop at all.
The plumbing nobody inventories
These connections run through connector services that link agents to real systems: email, file storage, project trackers, code repositories, databases, even cloud infrastructure. Some connectors are official and well built. Many are published by third parties and hobbyists, and employees pick whichever one works, the same way they once picked browser plugins.
In one analyzed environment, over a hundred such connectors were found linking AI agents into corporate systems. Each one is a door, opened by an employee, reviewed by nobody. Traditional IT tooling does not inventory this layer at all, which is why it has been called the new shadow IT. And a bad connector is not a neutral pipe: sitting between the agent and your systems, a malicious or vulnerable one can read the data passing through, alter requests, and steer the agent into actions the employee never intended.
Reads are questions. Writes are actions.
Not all agent activity carries the same weight, and the distinction is the single most useful lens an owner can learn.
When an agent reads, it is asking questions of your systems: risky mainly for what data it might carry out. When an agent creates, updates, or deletes, it is changing your business: modifying records, rewriting documentation, removing data. In one analyzed environment, agent activity broke down to hundreds of reads, over a hundred updates, and a couple dozen deletions. Software was autonomously modifying and removing corporate data, and nothing in the company's existing tooling recorded that it was happening.
That is the accountability gap in one image: real changes, in real systems, with no log of what was done, in what order, or why.
When two ordinary settings make one dangerous agent
The sharpest risk is not any single setting. It is a combination that arises innocently: an agent configured for high autonomy, allowed to act without asking, that is also connected to something sensitive.
Either alone is manageable. An autonomous agent confined to scratch work is fine. A supervised agent with production access is fine. But an agent that executes without confirmation and holds write access to cloud infrastructure can change configurations and delete resources with no human in the loop. That combination is a direct path to an incident, and it gets created by an employee toggling two settings that each seemed reasonable on their own.
A few other configuration patterns show up repeatedly when environments are scanned: agents routing traffic through AI model providers the business would never knowingly approve, connectors installed from unofficial sources with known flaws, and agents authenticating to important systems with static, long-lived credentials sitting on a laptop where a modern login flow was available. The pattern behind all of them: the tool is rarely the risk. The configuration is.
What oversight looks like (and why it is not a ban)
The answer is not banning agents any more than the answer to shadow AI was banning chat. The productivity is real, and this layer will only grow. The answer is treating agents the way you treat employees: know they exist, know what they can access, and keep a record of what they do.
Concretely, oversight of this layer means three things. An inventory: which agents exist on which devices, connected to which systems, under whose account. Visibility into actions: what each agent actually did, down to the specific operation. And permissions that match the job: an agent can be allowed to read from a system but blocked from creating or deleting in it, per system and per tool, the same least-privilege logic every business already applies to people. That last control is the one most companies do not know is possible, and it converts this whole topic from a black box into something manageable.
If the shadow AI conversation was about seeing which tools your team uses (we covered that here), the agent conversation is one level deeper: seeing what those tools are connected to, and what they are doing there.
The question to sit with
Would you know if an AI agent changed something in your systems yesterday?
For most small and medium businesses the honest answer today is no, and a year ago that answer was fine, because agents barely existed in normal companies. That grace period is ending as employees wire assistants into more of the business. Getting ahead of it does not require becoming an AI expert. It requires deciding that software acting inside your systems deserves at least the oversight you give a new hire.
Agent oversight, from the inventory to the per-tool permissions, is part of what our Managed AI Security service covers, starting with a free Shadow AI Discovery that includes the agents and connectors nobody inventoried. Prefer to talk it through first? We are happy to have that conversation.
cAIberOps is a managed security service provider based in McLean, Virginia. We secure the AI your team already uses, nationwide, and protect small and medium businesses with managed email security and managed endpoint protection.
Comments