The blind spot
Your EDR sees a signed process. It doesn’t see an agent.
An AI agent is a legitimate, signed binary doing legitimate things, until the moment it does something its own rulebook forbids. Classic endpoint tooling has no concept of a declared agent permission, so shadow AI hides in plain sight: approved-looking software, unapproved behaviour.
Shadow AI
Agents installed without approval, running with broad file and network scope. Nobody has an inventory.
Silent re-scoping
Permissions and trusted folders widen over time. The change is never reviewed.
No attributable record
When something moves, you can’t prove which agent did it, on which machine, or when.
HOW DISCOVERY WORKS
Four ways Aeguard finds an agent your inventory missed.
Aeguard doesn’t wait for a signature to exist. It identifies AI agents by how they announce themselves and how they behave, then attributes their file, network and process activity back to the agent that caused it.
Signature
Known agent binaries, CLIs and runtimes identified on sight.
Behavioural
Agent-shaped activity: model calls, tool use, autonomous file and network actions, caught even when the binary is unknown.
MCP inventory
Enumerates the MCP tool grants an agent holds: which external tools it can call.
Process lineage
Follows the process tree, so a child action is attributed to the agent that spawned it, not the shell it ran in.
Every finding is attributed, per agent and per machine · chained into the tamper-evident log.





