Acme Corp · all environments · prepared for the CISO and audit committee

AI agent inventory and exposure

Read-only discovery across production, edge, and managed endpoints.

FINDINGS SUMMARY · PERIOD ENDING 28 AUG 2026
Agents discovered11
Attested — origin and work provable7
Unattested — cannot prove anything3
Failed verification — record altered after creation1
Attestation coverage63.6%
Total agent token spend$25,140 / mo
Spent by agents with no established owner$8,920 / mo
ANNUALIZED, UNOWNED$107,040
$107,040 a year is being spent by AI agents that no one in the organization owns. Four agents have no approver, no stated business purpose, and no accountable team. They hold live credentials to customer data, payroll, and external storage.Material finding · recommend action this quarter

Material findings

ClassAgentExposureSpend / mo
No ownerunknown-llm-worker
prod-us-east / vm-114:8080
Outbound calls to an external model endpoint. Purpose unknown. Egress not attributable to any approved workload. Running 9d.$4,310
No owner(unidentified)
prod-eu-west / cron-runner-02
Scheduled export writing to external object storage. No approver of record. Running 16d. EU data residency implications.$2,240
Shadowsales-copilot-poc
shadow / laptop-jdoe / localhost
Credential-holding script on an unmanaged endpoint with a live CRM API key. Not seen in 9h. Off-boarding risk.$880
TamperedSupport Triage (patched)
prod-eu-west / ns-cx / pod-13
Presented a creation record whose governance policy was modified after creation. Record fails verification. Holds customer PII read access.$1,490
StaleSecurity Log Analyst
prod-us-east / ns-sec / pod-4
Attested, but last attestation 7.5h old against a 15-minute policy. Operating at reduced authority; incident-response coverage degraded.$3,120

Recommended actions

Terminate the two unowned production agents

No approver exists; no business process depends on them. Effect: $78,600 annualized spend stopped, two external egress paths closed.

Revoke the CRM credential on the unmanaged endpoint

Remove the shadow script. Effect: $10,560 annualized, one off-boarding exposure closed.

Quarantine the tampered agent

Pending investigation of who modified its governance policy and when. Effect: PII access suspended; chain-of-custody evidence preserved.

Restore attestation cadence for the security agent

Effect: incident-response coverage restored to full authority.

Require an owner and stated purpose for every agent

Standing control, with unowned agents refused at deployment. Effect: this finding does not recur.

Method and limits

  • Classification. An agent’s own claim about itself was not treated as evidence. Attested means a signature chains to a verified creation record using a key unavailable to the platform executing the agent.
  • Consumption figures are attributed from provider billing and metering-proxy records produced independently of the agents themselves, not from agent self-report.
  • Scope. Production Kubernetes, edge gateways, managed VMs, and enrolled endpoints. Unmanaged networks and offline systems were not in scope.
  • Absence of a finding is not assurance that no agent exists. This is an inventory and exposure assessment, not a security certification or a legal opinion.
  • Discovery ran read-only inside the environment. No inventory data was transmitted externally.
Programs & participation
NVIDIA InceptionMember
NIST Zero DraftsSubmissions filed
NIST AI 300-1Public comment
NIST NCCoEPost-Quantum Cryptography
Community of Interest
DOE Genesis MissionConsortium participant
Congressional Internet CaucusAdvisory Group — former member

Participation in an open public process is not endorsement. No agency, standards body, consortium or company listed here endorses Atom Works™, its products or its claims.