The Signal

Twenty-four member companies in sixteen industries asked for the same thing last month. Not a platform. An inventory.

They want a list of the AI already running inside their own walls. Agents, assistants, models, connectors. Whatever their own people stood up without telling anyone.

That inverts how enterprise software normally gets bought. You start by knowing what you have. Then you buy what is missing. These leaders are paying to find out what they have.

Fifteen of the twenty-four were expanding AI in the same breath. A construction IT director is rolling Copilot out company-wide and approving other agents by request, with no way to track either. A pharmaceuticals infrastructure director is building an AI practice and shopping for agent governance at the same time. An education leader is pushing AI projects into production specifically to stay ahead of shadow AI.

None of this is a procurement problem. The AI arrived through people who never filed a ticket. Engineers pulling local models into their editor. Business teams assembling agents in no-code tools. Staff who got a Copilot seat approved and then kept going.

The existing stack does not see any of it. One software IT leader in the network named the gap precisely. Intune and Entra ID cannot tell him what proprietary data is feeding those workflows. Those tools were built to track people and laptops. An agent is neither.


From the people who send this

CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you up to $500, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.

Claim your invite

Or reply to this email with the word "briefing" and Ryan will set you up personally.


From the Network

"As the usage of AI continues to explode, I'm looking for solutions to monitor and contain it. I'm not overly concerned about intentional insider threat (although there's some of that) - mostly concerned with people not understanding what they're doing."
— Vice President, IT and Security, Finance

"Would love to learn about monitoring AI agents via real-time telemetry, trace latency, and drift detection. Deploying automated circuit breakers and human-in-the-loop workflows to halt loops and remediate risks proactively."
— Director of Software/Cloud Engineering, Business Services

"I want to see if this is simply just a discovery tool or will it help defend against AI-related threats. There are many visibility tools, not so many effective prevention tools."
— CIO/CISO, Non-Profit

Three leaders, three positions on the same curve. The first cannot see what is running. The second can see it and is already designing the brake. The third is warning that seeing is not stopping. Nobody in that sequence is debating whether to use AI.


Top Open Priorities This Week

Two raw asks pulled directly from member submissions in the last 14 days, unedited:

"I would like to see your approach to detecting shadow AI. I am actively looking for a solution in this area. I am looking for browser based detection as well as endpoint app detection."
— Deputy Chief Information Officer, Law Firms and Legal Services

"Our engineers are deploying unsanctioned AI agents across our multi-cloud environment faster than we can track them. We currently lack a centralized way to monitor what corporate data these models are accessing."
— IT Director, Software

Both are asking to find AI their own colleagues deployed. Neither is asking whether to allow it.


What vendors are paying to discuss this week

Across the briefings enterprise vendors are currently funding, four topics carry most of the spend:

Shadow AI discovery that produces audit evidence, not just a dashboard. This is the Signal's ask with a price on it.

Securing code that AI agents wrote, from generated APIs through to the software supply chain. The software IT director above is describing the buy side of this.

Asset and dependency inventory reconciled into one authoritative record across hybrid estates. The inventory problem predates AI. Agents made it urgent.

Continuous third-party and supplier risk scoring rather than onboarding questionnaires. No tie to this week's stories. It is simply what is being funded.


The Context

The headlines are catching up to what the network already knew. A Morning Consult survey of 362 IT decision-makers, published this week, found that 96 percent are confident their organization holds a complete and accurate inventory of its AI agents.

In the same survey, 61 percent said it is likely their employees are deploying agents without formal approval. Fewer than half have centralized monitoring. Fewer than a third have an automated kill switch. Two-thirds had an agent-related operational consequence in the past year.

Both answers came from the same people. The study was fielded in early August and paid for by a vendor selling agent management, so read the direction and not the decimal. The direction is unambiguous.

Bottom Line: An inventory you believe in but cannot print is not an inventory. It is a memory.


What to Do About It

Pick one team that ships software. Ask them to list every AI agent, assistant, and model connector they have wired into a production system this quarter. Give them 48 hours and no blame, then compare their list against whatever your CMDB or SaaS management tool reports. The size of that gap is your real starting number.


The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.
Know a CIO who needs this? Forward it and they can subscribe here.
Run IT or security at a $100M+ company? Claim your invite.