Shadow IT was the polite version.
We used to worry about a developer spinning up a rogue cloud account or sneaking some unsanctioned SaaS past the security team. Annoying, sure. But it moved at human speed, and you could mostly catch up to it.
Gari Singh has a better name for what's coming next. He calls it Ninja IT in the latest episode of the [Dev]olution Podcast.
Gari's a product manager at Google Cloud working on the containers and Kubernetes runtimes carrying a big chunk of the world's AI workloads, and before that he put in 15 years at IBM as a distinguished engineer and a blockchain CTO. So he's watched three infrastructure waves wash through the enterprise. When he describes the current one, it's not agents quietly bending the rules. It's agents executing in secret, in their own little groups, wiring themselves to systems at a speed no human approval chain was built to keep up with. (He coins it around 19:10.) Shadow IT at least waited for a person. This doesn't.
And here's the part that should make a platform engineer sit up. Deloitte's 2026 State of AI survey found that close to three-quarters of companies plan to deploy agentic AI within two years, but only 21% have a mature model for governing it. So the stampede is already in motion, and four out of five companies are running into it without the controls to hold the line.
Let's be honest about what makes this hard. An agent doesn't sit there waiting for instructions like a command line that runs once and dies. It runs in a loop, calling the model, picking tools, acting on what comes back, going again. Point it at a problem and it'll reach for every tool in the box to solve it. If Bash is on the machine, it'll use Bash. Nobody told it not to.
So what does a platform engineer actually do about it on Monday morning? That's the back half of the latest episode of the [Dev]olution Podcast, and Gari's answer is refreshingly un-fancy. It isn't "buy a firewall" and it isn't "ban the agents." It's three specific things you can start this week, and the third one is the one that'll get under your skin: go build one of these things yourself and watch what it does when you're not looking. (He walks through the checklist around 44:11.) Also on the table: why he thinks MCP servers are the new SOAP, not the new HTTP, and what a no-op user mapping in a container has to do with surviving the next breach.
Watch the full episode on YouTube
If agent governance, infrastructure at machine speed, and a Google PM cheerfully telling you to go scare yourself sound like your kind of conversation, subscribe. New episode every two weeks.
Nicky Pike spent 20+ years making developers' lives easier at some of tech's biggest names before joining Coder. From launching Xbox Live to rebuilding how CVS Health develops software, he's helped shape developer productivity and team experiences at Microsoft, Dell, and VMware/Broadcom Tanzu. A respected voice in the Cloud Foundry community and regular conference speaker, Nicky has a talent for making cloud-native development and platform engineering actually make sense to humans.
Want to stay up to date on all things Coder? Subscribe to our monthly newsletter for the latest articles, workshops, events, and announcements.