- 70% of organizations have employees using generative AI tools without official sanction.
- 3,000+ publicly accessible links found in a single enterprise tenant with 40,000 users.
- 13 governance signals used to assess AI readiness in Orchestry's scoring system.
Experts would likely conclude that while democratizing AI tools empowers employees, it introduces significant security and compliance risks that require proactive governance solutions.
Taming the Digital Ghosts: A New Defense Against Shadow AI in Microsoft 365
VANCOUVER, BC – September 01, 2026 – In the rush to embrace artificial intelligence, a new class of digital ghost has begun to haunt the enterprise: shadow AI. These are the AI-powered agents and automations built by employees, often with the best intentions, using powerful, low-code tools like Microsoft’s Power Platform. They exist in the digital blind spots of an organization, operating without IT approval, oversight, or governance. Now, a new solution aims to bring them into the light.
Vancouver-based Orchestry today announced AI & Agents, a feature for its Microsoft 365 governance platform designed specifically to give IT and security teams a unified command center to discover, assess, and control these rogue agents. The launch comes as organizations grapple with the dual-edged sword of AI democratization—while it empowers employees to innovate, it also creates significant, often invisible, security and compliance risks.
The Unseen Risk: Shadow AI in the Enterprise Cloud
The problem of 'shadow AI' is not a future hypothetical; it's a present-day reality. Recent industry surveys reveal a startling picture: in as many as 70% of organizations, employees are using generative AI tools without official sanction, and a majority of IT leaders are deeply concerned about the associated security risks. This isn't just about employees pasting sensitive data into public chatbots. Within the walls of the corporate cloud, the risk is more insidious.
Microsoft 365, with its integrated Power Platform, has given millions of employees the ability to build their own apps, automations, and AI agents in minutes. An employee in marketing can build an agent to summarize customer feedback; a logistics coordinator can create one to track shipments. The challenge is that these agents inherit the data access permissions of their creators. If an employee has access to poorly secured data, so does their homemade AI.
This is where the long-standing problem of data oversharing collides with the new reality of AI. In a striking example of this exposure, Orchestry found that in a single enterprise tenant with roughly 40,000 users, over 3,000 links were shared with “anyone,” making the underlying documents publicly accessible. Every single AI agent built on that tenant could potentially read, process, and surface that information. The risk is no longer just a misconfigured link; it's a misconfigured link being actively mined by an unmonitored AI.
A Unified Command Center for AI Governance
Orchestry's response is to treat the problem holistically. The company argues that simply providing a list of AI agents—something it notes Microsoft will soon offer for free—is insufficient. The real risk lies at the intersection of the agent, the platform it runs on, and the data it can access.
"The list was never the hard part," said Michal Pisarek, founder and CEO of Orchestry, in the announcement. "What decides whether an agent is dangerous is the content it reads and the platform it runs on, and no inventory retrofits a decade of permissions decisions. We have governed that layer since before agents existed, and pointing it at AI was the obvious next step."
The new AI & Agents feature is designed as a single pane of glass, eliminating the need for administrators to jump between the Power Platform, SharePoint, and Microsoft Purview admin centers. From one dashboard, an IT team can see every agent on their tenant, view a dynamically calculated risk score, and drill down into the specific findings that generated it. These findings could include the agent’s connection to sensitive data, its reliance on risky platform connectors, or its ability to share information externally.
Crucially, the platform provides direct, actionable controls. An administrator can disable or delete a high-risk agent across all sources from the same interface, with all actions logged for audit purposes. This creates a clear, defensible trail of governance. The platform also introduces a scoped administrative role, allowing security teams to manage agent-specific risks without needing the 'keys to the kingdom'—full tenant admin permissions.
From Reactive Cleanup to Proactive Readiness
Beyond simply hunting down existing shadow AI, Orchestry is positioning its solution as a tool for strategic AI readiness. The platform includes a scoring system that assesses a tenant’s overall fitness for any AI model, including major rollouts like Microsoft Copilot. This score is calculated based on 13 distinct governance signals that span data oversharing, existing governance policies, and security safeguards.
The score isn't static. It's a real-time metric that improves as administrators fix the underlying issues—cleaning up public links, enforcing sensitivity labels, or tightening external sharing policies. This shifts the conversation from a reactive cleanup of rogue agents to a proactive effort to build a secure foundation for all AI initiatives. For business leaders and CIOs, this provides a tangible benchmark to answer the question, “Are we truly ready for AI?”
This proactive stance is critical. As enterprises race to deploy tools like Copilot, many are discovering that the AI is only as good—and as safe—as the data it’s fed. If a company's data hygiene is poor, with years of accumulated oversharing and inconsistent permissions, deploying a powerful AI on top of it is like giving a super-fast car to someone who has never driven on a paved road. It amplifies the potential for a crash.
The Broader Market Context
Orchestry's launch places it in a rapidly evolving market where data governance, security, and AI management are converging. While Microsoft provides a powerful suite of tools like Purview for data governance and the Power Platform Admin Center for app management, they often operate in silos. Third-party vendors are rushing to fill the gaps by providing a unified layer that simplifies management and operationalizes governance policies across these disparate systems.
The ultimate goal is to move beyond simply managing risk to enabling strategic value. The question for enterprises is no longer if they will use AI, but how they will govern it to ensure it is secure, compliant, and ultimately, worth the investment. As Pisarek noted, the finish line is shifting.
"Governing your tenant and governing the AI running on it stopped being two separate jobs," he said. "Agents are the first place that's obvious, and they won't be the last. Two years from now nobody will be asking whether their content is ready for AI. They'll be asking what the AI is costing them and whether it was worth it. That's the question we're building toward."
Topics & Related
Software & SaaS
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →