Meta's Muse hit the top of the US iOS free app charts earlier this month, pulling around 730,000 downloads in its first five days and overtaking ChatGPT, Claude, and Grok in the process. This week OpenAI answered with Dots — "always-on" personal agents that run on their own cloud computers, plug into roughly 4,000 apps, and keep chasing a user's goals in the background, unattended, around the clock. Neither product was built for the enterprise. Both are landing on the personal phones of your employees right now, and a meaningful share of them are going to connect these agents to a work inbox, a work calendar, or a work file before anyone in IT or leadership even knows the product exists. That's not a future risk to plan for. It's happening this week, and it's happening without your company's permission.
Why 'Always-On' Changes the Calculus
Shadow IT has always existed — employees signing up for a free project-management tool or a personal Dropbox account because the approved system was slow. Shadow AI is the same instinct with a sharper edge, because the tool doesn't just store data, it acts on it continuously without being asked twice. A browser extension someone installed quietly reads pages; an always-on agent someone connected to their calendar and inbox keeps working after they've closed the laptop, drafting replies, scheduling meetings, and pulling context from whatever it's been given access to. The convenience is exactly why adoption will be fast and exactly why it's dangerous: nobody has to request it, budget it, or get it reviewed. They just tap connect.
What's Actually Different From the Agent Risk You've Already Heard About
Most of the AI agent risk coverage this year — and most of what gets written about agent permissions, sandboxing, and liability — assumes the business deployed the agent. That's a real problem, and a solvable one: you control the scope, the logging, the approval thresholds. Shadow AI is the opposite problem. It's an agent your business never deployed, never reviewed, and has no visibility into, that's nonetheless touching your data because an employee linked their personal Gmail-adjacent work account, their calendar, or a shared drive to a consumer product with its own data retention policy, its own security posture, and its own incentive to keep that agent "helpful" by reading as much context as it can get. You can build the most disciplined internal agent governance program in the world and still have a Dots instance quietly summarizing your Q4 pipeline because a sales rep connected it to their inbox to save ten minutes a day.
Three Ways This Shows Up Inside an Ordinary Business
- Data leaves the building through a channel nobody mapped. A personal always-on agent connected to a work email account can read, summarize, and act on anything in that inbox — client names, contract terms, pricing, internal threads — under a consumer terms-of-service agreement the company never reviewed and can't audit.
- There's no off switch when someone leaves. If an employee connects a personal agent to shared company systems and then leaves the business, that connection doesn't get revoked in an offboarding checklist, because it was never on one.
- The agent acts, not just reads. Unlike a shadow spreadsheet tool, these agents send emails, accept meetings, and take actions with 4,000 connected apps — meaning a shadow AI agent can create a customer-facing or contractual consequence, not just a data exposure.
The uncomfortable part
You don't need a single employee to act carelessly for this to be a real exposure. You just need one of them to do what the product is designed to make effortless: connect it to make their day easier. The risk isn't bad judgment — it's the default behavior of a well-designed consumer app.
A Realistic Scenario
A Wizeb client, a 40-person marketing agency, ran a routine security review after the Muse and Dots launches made headlines internally. They found that three account managers had connected a personal always-on agent to their work calendars "to help draft follow-up emails faster," and one had gone further and linked it to a shared drive folder containing client campaign budgets. No breach had occurred — the agent was doing exactly what it was designed to do, quietly and helpfully. But the agency had no record of which employees had made these connections, no way to see what the agent had already read, and no clause in its client contracts covering the possibility that a client's budget data had passed through a third-party consumer AI product's servers. The fix wasn't punitive. We helped the agency write a one-page AI connection policy, ran a 15-minute disclosure survey across the team that surfaced two more unreported connections, and stood up a sanctioned, company-controlled always-on agent so staff had a faster, equally convenient alternative that didn't require routing client data through a tool nobody had vetted.
What a Shadow AI Policy Actually Requires
- 1Find out what's already connected. Most companies have never asked. A short, blame-free survey — "what AI tools have you connected to your work email, calendar, or files?" — surfaces more than any monitoring tool will catch on its own.
- 2Write down what's allowed, in plain language. Not a 40-page AI policy nobody reads — a short, specific list of what can and can't be connected to company systems, and why, so employees aren't guessing.
- 3Give people a sanctioned alternative that's just as convenient. Employees don't adopt shadow tools to cause a problem; they adopt them because the approved option is slower or doesn't exist. A company-controlled always-on agent, scoped and logged properly, removes the reason to reach for the consumer version.
- 4Put a connection review into offboarding. If an employee connected a personal agent to a shared system, that access needs to be identified and revoked when they leave, the same way you'd revoke a login.
- 5Revisit this every time a major consumer AI product launches. Muse and Dots won't be the last always-on agents to chase mainstream adoption — this list needs to be a living one, not a one-time memo.
Four Questions to Ask Your Team This Week
- 1Has anyone on your team connected a personal AI agent — Muse, Dots, or otherwise — to a work email, calendar, or shared file, and would you currently know if they had?
- 2If a departing employee had one of these connected, is revoking it part of your offboarding checklist today?
- 3Do your client or vendor contracts say anything about data passing through a third-party consumer AI product your business never approved?
- 4If the honest answer to 'what's connected to our systems' is 'we don't know,' is that because nothing is, or because nobody's asked?
How Wizeb Approaches This
The instinct to reach for an always-on agent is a good one — the productivity gain is real, which is exactly why Muse and Dots are spreading this fast. The mistake is letting that adoption happen invisibly, through personal accounts and consumer products, instead of deliberately, through a company-controlled agent built with the same scoping, logging, and approval discipline we build into every agent deployment. When Wizeb builds a company's AI agent layer (wizeb.com/services/ai-agents), part of the job is giving your team a sanctioned, equally convenient always-on option — so the fastest way to get something done at work is also the one your business can see, audit, and stand behind.
Find out what your team has already connected
Wizeb runs a short, no-blame shadow AI discovery survey across your team and shows you exactly what's connected to your systems today — then builds the sanctioned always-on agent that makes the shadow version unnecessary. Start at wizeb.com/contact.
