Preprint
Article

This version is not peer-reviewed.

Agentic Shadow Infrastructure: How AI Supply-Chain Drift Creates Unmanaged Enterprise Infrastructure

Submitted:

17 June 2026

Posted:

18 June 2026

You are already at the latest version

Abstract
Agent identity governance is advancing, though core agent identity and authorization questions remain unresolved: existing frameworks provision, authenticate, authorize, and retire non-human and agentic identities, governing the agent’s identity, credentials, and lifecycle while assuming the composition an agent was approved with remains the composition it runs with. This paper argues that assumption is the open seam. An agent’s effective composition—its tools, data sources, delegated authorities, policies, and child agents—is a runtime supply chain of capability, and that supply chain drifts. We introduce composition drift as the departure of an agent’s effective composition from the terms of its approval, and isolate its most consequential form, compositional drift: the accumulation of individually approved changes into capability that none authorized alone. We formalize this with a two-stage operator: a component-level diff detects that the composition changed (component divergence); a capability-closure stage detects when the change authorized something new (compositional drift)—a qualitative boundary, not a numeric threshold. The contribution is not the observation that approved changes can combine dangerously—long known to authorization security—but a temporal governance model for approved composition drift in agentic systems, linking emergent capability to reauthorization and inventory reconciliation. This drift produces shadow infrastructure: resources provisioned outside any inventory through benign, individually approved pathways. We propose composition attestation, a runtime composition-control layer complementary to identity governance. Paired positive and negative scenarios show the model discriminates, not labels. We bound our claims: the model establishes the phenomenon by construction and claims no deployment efficacy.
Keywords: 
;  ;  ;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings

© 2026 MDPI (Basel, Switzerland) unless otherwise stated