New CSA + Token Security research on 418 IT and security pros: shadow AI in 2026 is no longer a data leakage problem, it is an access control problem. AI agents inherit broad permissions from their creators and act as non-human identities with no clear owner, scope, or decommissioning path. https://go.aintelligencehub.com/ma-shadowaiaccess2026 #ShadowAI #AIsecurity #AgentGovernance #EnterpriseAI
Shadow AI is now an access control problem, CSA and Token Security say

A Cloud Security Alliance and Token Security report on 418 IT and security pros argues shadow AI in 2026 is no longer a data leakage problem. It is an access control problem across agent-driven non-human identities.

Announcing Agent Governance Toolkit MCP Extensions for .NET - .NET Blog

Announcing a Public Preview .NET package that adds policy enforcement, startup tool scanning, fallback governance, and response sanitization to MCP servers with a single builder extension.

.NET Blog

Stop treating Copilot Agents like static binaries. They are workforce units requiring HR-style lifecycle mgmt.

Use Entra Groups to 'Remove' agents from workspaces without nuking the tenant registry definition.

Soft delete = retention; Hard delete = registry wipe.

Identify dormant bots via Reports > Usage to prune API costs.

#M365 #M365Agents #Copilot #Agents365 #AgentGovernance