{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-013.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-013",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-013.json",
    "title": "Shadow AI discovery and registry reconciliation",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Discovery runs continuously against the places AI appears (identity providers, cloud accounts, network egress, code repositories and SaaS integrations); each finding is reconciled against the registry, an unknown system gets an entry and an owner asked to claim it, the unclaimed are escalated, and the result feeds the registry drift check.",
    "failureModes": [
      "The registry is fed only by voluntary declaration and lags production: models, agents and AI-enabled tools run with no entry.",
      "A finding is logged but never registered, claimed or escalated.",
      "A retired system keeps a copy serving because no sweep checks for it."
    ],
    "scope": "The environments where staff and systems can run or reach AI: identity, cloud, network, code and SaaS. Local models and personal devices stay a discovery problem that the sanctioned gateway does not cover.",
    "enforcementPoints": [
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Discovery findings reconciled against the registry, with the entries opened, claimed and escalated",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "An unknown system is registered as unclaimed, its owner is asked to claim it and the unclaimed are escalated; in the pattern's example its scope is frozen until claimed."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "shadow-ai-discovery",
        "title": "Shadow-AI Discovery",
        "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "shadow-ai-discovery",
        "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART49-71",
          "name": "EU AI Act Art. 49/71 registration of high-risk systems in the EU database",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [
        {
          "id": "GOVERN 1.6",
          "title": "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities."
        }
      ],
      "owasp": [
        {
          "id": "asi10",
          "externalId": "ASI10",
          "name": "Rogue Agents",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
        }
      ],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 49,
        "title": "Pattern: Shadow-AI Discovery",
        "text": "Pattern: Shadow-AI Discovery (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery",
        "verified": "primary"
      },
      {
        "n": 50,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Retirement and decommissioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#retirement-and-decommissioning",
        "verified": "primary"
      },
      {
        "n": 51,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 21,
        "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)",
        "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (Art. 49 and 71 registration in the EU database; Art. 60 testing of high-risk AI systems in real-world conditions outside sandboxes). Publications Office of the EU (EUR-Lex). 2024-07-12.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
        "verified": "primary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Turn each find into an intake request (register, tier, approve or replace) before it becomes a sanction; identity, network and expense data show the tools used outside the sanctioned gateway."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "The source material sets no cadence for discovery sweeps beyond the pattern's illustrative weekly sweep, and no deadline for an owner to claim a finding."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
