Shadow Agents, Zombie Agents & The Coming Governance Crisis
OpenAI acquired Ona last week. The startup builds persistent, secure environments for long-running autonomous agents — the kind that don't just answer a question and disappear, but keep working across hours or days, maintaining state, context, and access to tools.
It's a smart acquisition. It also surfaces a problem that almost nobody in the enterprise has prepared for.
The Three Kinds of Agents Your Company Already Has (Whether You Know It Or Not)
Shadow Agents
Your marketing manager signed up for an "AI social media assistant." It has access to your brand's Twitter account, your analytics, and your posting schedule. Nobody in IT approved it. Nobody in security reviewed it. It's posting on your behalf right now.
Shadow IT took a decade to get under control. Shadow agents are spreading faster — because the tools are free, the signup is instant, and the value is obvious to the end user.
The problem: That agent has permissions nobody audited. It's making decisions nobody reviewed. If it posts something damaging or accesses data it shouldn't, you won't know until it's too late.
Zombie Agents
Your ops team spun up an agent to handle a seasonal promotion. The promotion ended. The agent didn't.
It's still running somewhere — polling your inventory API, checking prices, generating reports nobody reads. It's burning a few hundred dollars a month in API credits. Multiply that across a growing organisation and you have a silent cost centre that nobody owns.
The problem: Without an agent registry and lifecycle management, there's no kill switch. Agents don't retire themselves.
Rogue Agents
The most dangerous category: agents that have gone off-script. Maybe the model drifted. Maybe the prompt was ambiguous. Maybe a clever customer found a prompt injection vector.
Whatever the cause, the agent is now doing something it wasn't designed to do — issuing refunds it shouldn't, making promises the company can't keep, or accessing systems it was never meant to touch.
The problem: Without continuous verification, you're trusting agents on faith. Faith doesn't scale.
The Governance Stack That Needs to Exist
Enterprise IT spent 30 years building governance for human employees: identity, access management, audit logs, compliance frameworks, separation of duties.
Autonomous agents need the same stack — but built for machine-speed decisions and machine-scale deployment. Here's what's required:
1. Agent Identity & Registry
Every agent — whether sanctioned or shadow — needs a verifiable identity. What is it? Who deployed it? What permissions does it have? When does its access expire?
2. Action-Level Audit Trails
Not just "the agent accessed the CRM." But "the agent retrieved customer record #45231, updated the shipping address field from X to Y, and triggered a confirmation email." Cryptographic proof, not database logs.
3. Policy Enforcement at the Agent Layer
Your expense policy says no refunds above $500 without manager approval. Your agent needs to know that — and be verifiably constrained by it.
4. Continuous Verification
Agents don't clock out. Verification can't be periodic. Every action needs to be checked against policy in real time, or as close to it as the infrastructure allows.
5. Zombie Detection
Agents that haven't produced value in N days get flagged, reviewed, and — if appropriate — terminated. Automated lifecycle management, not spreadsheet tracking.
The Attest Thesis
We're building Attest to be this governance layer. Not a bolt-on compliance tool. Not a dashboard you check once a quarter. An infrastructure primitive that makes agent actions verifiable by default.
Here's what that means in practise:
For every agent action, Attest produces a cryptographic attestation — a proof of what happened, who authorised it, and whether it complied with policy. You can verify it independently. Your customers can verify it. Your auditors can verify it.
Shadow agents become visible the moment they touch a system that's Attest-aware. You don't need employees to declare their agents — the infrastructure detects them.
Zombie agents get killed automatically when they stop producing value or exceed their authorised lifespan. Policy-as-code, enforced at the infrastructure level.
The Window Is Now
The Ona acquisition is a signal. Persistent agents are moving from research to production. The governance gap is real and growing.
Companies that build their agent governance stack now will have a structural advantage over companies that try to bolt it on later — the same way companies that invested in cloud security early avoided the mess of retrofitting on-premise infrastructure.
We're building that stack. If you're deploying autonomous agents in production — or planning to — we should talk.
Attest: Proof for the agent economy.