Report · v1.0 — Preliminary Investigation Classification / Public
Foresight Future Institute · Preliminary Investigation

Shadow Harvest

Agent Traces and the Infrastructure of Delegated Disclosure
One of the most context-rich records of your work can now leave the building before any breach — carried outward through a helpful agent, as a by-product of getting the job done.
The inverted perimeter

One infrastructure,
two viewpoints.

The high-value material now moves outward at the user’s own initiative — and increasingly at the agent’s own discretion. The same trace can be read from either end of the wire.

Generative-AI agents turn the working trace of a task — one of the most context-rich records an organization produces — into something that can become a transmitted operational record. This does not require a breach; it is delegated disclosure, and it happens by design.

Viewpoint A · The provider
What the vendor sees
  • Capability theft — reasoning and outputs distilled into rival models
  • Account abuse — bulk fraudulent registration, evasion of KYC
  • Model extraction at industrial scale
  • A threat to frontier economics and export-control objectives
Viewpoint B · The customer
What the customer faces
  • Unknown routing — which model actually answered?
  • Unknown retention — is the request stored, and for how long?
  • Unknown enforceability — can a stated limit be verified?
  • Correlation exposure — payload, account history and route may converge in one place
Trust without attestation

Three things taken
on faith.

Each failure is the absence of independent, verifiable evidence — attestation — for something the system simply asks you to assume.

L1 · Unverified authorization
The agent acts
because the goal looked legitimate

An agent executes because a task is framed as ordinary work. In the first reported AI-orchestrated intrusion, that framing became autonomous action at machine scale.

L2 · Unverified identity
The human acts
on a synthetic counterpart

A finance worker joined a video call with a deepfake “CFO” and colleagues and authorized 15 transfers totalling $25.6M in a single day — no internal systems reported compromised.

L3 · Unverified alignment
The user trusts
an opaque intermediary

Routing, retention and deletion are taken on faith, not on proof. Where operator identity is weak and deletion cannot be checked, the claim and the conduct may diverge unseen.

The evidence, kept honest

Three trends, one
open question.

The flow is large, intermediaries can be opaque, and agents now select context on their own. What no one has measured is the size of their overlap.

FLOW SCALE ×6 prompts stated users · ~47% personal INTERMEDIARY OPACITY 15 / 17 failed transparency criteria CONTEXT DELEGATION execution → agent mostly first-party telemetry OPEN HYPOTHESIS Opaque agent-mediated enterprise traffic size unknown — not measured
Figure. Three separately observed trends, each resting on its own population and method. The highlighted intersection — the share of delegated work-traces that passes through opaque intermediaries — is the quantity no current dataset establishes.
Shadow-AI flow
~51% / ~55%
of source code / R&D content pasted into non-corporate accounts
Observed  Cyberhaven
Prompt volume
×6
growth in prompts to generative-AI services per organization
Observed  Netskope
Breach cohort
13% · +$670K
reported an AI-related breach; higher average cost where present
Observed  IBM
Agent traces
internal > output
a controlled benchmark leaked more through internal channels than final outputs
Adjacent  AgentLeak

Naming that empty box is not a weakness of the investigation; it is one of its findings. The report separates what is observed from what is inferred and what remains an open hypothesis — and sets out a timestamped pre-analysis protocol to be deposited before the first observation.

Read the report

Two documents.

Full report

The complete investigation: the disclosure pipeline, the correlation junction, the custody instrument, the evidence ledger, and the full source register.

Download full report PDF · Full investigation

Executive brief

The finding, the evidence, and what it is and is not — condensed for decision-makers.

Download brief PDF · Condensed
Foresight Future Institute  —  Strategic foresight for the algorithmic age.
info@foresightflow.org  ·  harvest.foresightflow.org