Scan your internal subnets for ports 7860, 3000, and 5678. If you find anything listening on these ports, you may have unmanaged AI infrastructure worth investigating immediately. When I audited agent infrastructure at a large enterprise, we discovered unauthorized AI builder instances holding production database credentials that no one on the security team knew existed.A Cloud Security Alliance survey released April 21 found that 82% of enterprises have unknown AI agents running in their infrastructure. Two earlier CSA surveys established the surrounding picture: 53% of organizations have had AI agents exceed their intended permissions, and 68% cannot distinguish between AI agent and human activity. A separate Gravitee report of 900+ practitioners found that 82% of executives believe their existing policies cover agent behavior, while only 14.4% of organizations report all AI agents going live with full security and IT approval.