In this post, we explain why uncontrolled AI agent development on managed copilot platforms is the next generation of EUC risk, why discovery is the prerequisite that most governance frameworks skip, and how a four-tier classification model can help financial institutions capture the productivity gains of citizen AI without repeating the remediation cycles of the past.