Sanctioned Apps, Unsanctioned AI: Governing the Agents Inside Your SaaS Stack

Your approved SaaS apps can still introduce unmanaged AI agents. Learn how to bring visibility and governance to the agents inside your stack.

Krishanu

Krishanu

Sanctioned Apps, Unsanctioned AI: Governing the Agents Inside Your SaaS Stack
Sanctioned Apps, Unsanctioned AI: Governing the Agents Inside Your SaaS Stack

A sparkle icon shows up in the CRM. Nobody in IT deployed it. Account executives start using it to summarize renewal risk across their book, and the help desk is fielding tickets about whether it's allowed. Security can't answer with evidence.

This is now the normal state of enterprise SaaS. Zoom gave admins four days in July 2024 to opt out before AI Companion auto-enabled. Microsoft 365 Copilot switches on in the admin center for every admin once a tenant holds one paid license. Google's Workspace Intelligence launched in April 2026 with Gemini connected to Gmail, Drive, Chat, and Calendar by default, and admin controls trailing the feature by up to 72 hours.

Turning these features off isn't realistic. They're built into the tools people use all day and can unlock real productivity. So the question for security is what happens once employees start using them: what they paste into the assistant, what it pulls back from across the app, and what it does next. A tenant review can tell you a feature is on. It can't tell you that a sales engineer pasted a customer's security questionnaire into it this morning.

AI Is Arriving Inside Apps You Already Approved

Introduces New AI Powered Tools

Over the past 18 months, nearly every major SaaS platform has added AI to its product. Microsoft 365 has Copilot, Salesforce has Einstein and Agentforce, and Slack, Zoom, Atlassian, Notion, ServiceNow, and HubSpot have all shipped their own assistants.

Your third-party risk process approved each of these apps once, at procurement. That review settled what data the app could hold, who processed it, and what it could do. An AI feature changes all three. Slack AI reads message history to write summaries.

None of this comes through procurement. The feature arrives as a product update, often switched on by default, and in many apps any user can enable it. Notice, if there is any, is a release note or an in-app banner with a few days' lead time. The review on file describes the app as it was, and nothing in the process prompts anyone to reopen it.

Defaults also vary in ways that are easy to miss. ChatGPT Enterprise ships with connectors off, while ChatGPT Business ships with them on. A Zoom tenant left on its defaults records meetings, generates transcripts and AI summaries, and keeps chat for two years. In two-party consent states, that raises the question of whether an AI summary counts as a recording, and every retained transcript adds to e-discovery exposure.

The Threat Model Changes When AI Enters Your SaaS

Gartner forecasts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from under 5% in 2025. Each one changes the risk profile of an app you already approved.

  1. What employees type. This is the biggest data loss channel. Employees paste contract terms, customer records, source code, and credentials to get a better answer, and all of it goes to the model.

  2. What the assistant can search. It pulls from email, documents, tickets, and customer records, so years of oversharing become one question away.

  3. What employees connect. They link assistants to Drive, mailboxes and CRMs and approve broad OAuth scopes, handing the model data never meant to be shared.

  4. What the model infers. A customer complaint, a pricing sheet, and an internal forecast are harmless on their own. Summarized together, they can reveal something material. No one accessed new data, but the model drew a new conclusion from it.

  5. What it creates. Summaries, drafts, and recommendations are new content with no owner, label, or retention rule, even when the sources were restricted.

  6. What it does. An assistant that drafts an email is a data risk. One that updates a CRM record, opens a ticket, or sends a message is an actor working under a person's identity.

  7. What it leaves behind. AI output becomes a business record. Google now lets Workspace users share Gemini chats and canvases through Drive, on by default and governed by existing Drive sharing rules. AI governance becomes a records-management problem too.

A Governance Model for Embedded AI

The aim is to decide which AI features are allowed, on which data, for which users, and to verify that continuously. Blocking everything gives up the productivity these features deliver, and the business won't accept it for long.

A Governance Model for Embedded AI
  1. Start with your top 50 vendors by data sensitivity. List the AI features each shipped in the past year and who can enable them. Check OAuth grants for unfamiliar model-provider apps, and ask sales, marketing, and product which features their teams use.

  2. Make an AI launch a re-review trigger for third-party risk, alongside a breach or a new subprocessor. Assume the next feature is already on.

  3. Tier features by data and action. Keep read-only features available where the data allows. Default write-back features to off, and enable them for named use cases with a named owner.

  4. Use controls you already license. Configure the AI settings in Purview, Google Workspace DLP or Salesforce Shield, and send admin usage reports to the SIEM.

  5. Put guardrails on prompts. Extend DLP to prompts for credentials, customer records, source code, and regulated data, detect prompt injection in the content assistants read, and block risky tool calls.

  6. Collect evidence at the point of interaction: which feature, which user, what data, which policy applied, and what was blocked.

  7. Write it into renewals. Require disclosure of model providers and training use, plus opt-out-by-default AI with weeks of notice.

  8. Name one owner reporting to the CISO, with legal and procurement at the table.

How Akto Secures Employee AI Use in the Browser

Employees open AI features, type prompts, and read responses in the browser, so Akto places the control there. Akto's browser extension, part of the Akto Atlas platform, secures employee use of more than 2,500 AI chatbots and the AI embedded in SaaS apps.

It builds a live inventory from observed use: which AI tools and embedded features employees use and on which device, including personal-account sign-ins. It enforces guardrails inline, blocking credentials, API keys, and personal data before they reach a model, and detecting prompt injection and risky tool calls. Every policy event is logged, which gives legal and audit the evidence they ask for.

The extension runs on Chrome, Firefox, and Safari, and deploys through MDM tools such as Intune or NinjaOne without a heavy endpoint agent.

Embedded AI is one half of the problem. It gets in through trust, so governance has to stay active after the contract is signed. Part two of our AI governance series will cover the other half, the coding assistants that developers install themselves, run with their own credentials, and connect to internal systems through MCP servers.

Follow us for more updates

The Largest Agentic AI Security Summit

The Secure, Governed AI Future.

October 27, 2026 | Virtual

Experience enterprise-grade Agentic Security solution