
Agent sprawl is what happens when an organization accumulates AI agents faster than it can inventory them. The agents are usually legitimate.
The problem is that no single system knows how many exist, what each one can reach, or who answers for it when something goes wrong.
Here is the statistic we keep returning to in client conversations. Gartner's research shows that 71% of technical stakeholders name security and governance as their biggest AI challenge, and 70% specifically flag uncontrolled costs and agent sprawl. Only 14% believe they have the right governance structures in place to manage agents.
That is one in seven
This gap is not a story about slow adoption. Adoption already happened. It is a story about a control layer that nobody built, in an environment where creating an agent now takes an afternoon and no approval.
If you read our piece on Shadow AI and what OpenClaw revealed, this is the sequel. That article was about one agent Microsoft decided to name. This one is about the several thousand nobody has named yet.
Shadow IT was the 2010s problem. Someone expensed a Dropbox subscription, a team stood up its own Trello board, and IT found out eighteen months later during a licensing audit. The damage was real but bounded: duplicated spend, stranded data, a decade of consolidation work.
The instinct is to file agent sprawl in the same drawer. That instinct is wrong, and the reason matters.
An unsanctioned application held data until a person did something with it. An agent holds an identity, a permission set, and the ability to take action with no person present.
It can open files, call services, and trigger other agents while everyone who might have objected is asleep.

Most inventories are built to catch applications. These patterns slip past them.

Procurement, HR, and support each ship a "policy lookup" agent in the same quarter. None of them knew the others were building. You now maintain three answers to the same question, with three different permission scopes behind them.
An agent that calls other agents. The request logged at the top looks routine. What happened four calls down, under which credentials, does not appear on the same report.
Built by someone who changed roles in March. It still runs on a schedule. It still holds the access it was given. No one has opened it since.
Three independent research efforts landed in the first half of 2026, and they agree on an uncomfortable shape.
The OutSystems 2026 State of AI Development Report surveyed roughly 1,900 IT leaders across the US, EU, UK, and APAC. It found 96% of organizations running AI agents in production and 94% naming sprawl as a top concern. When both numbers sit in the nineties, you are not looking at an emerging risk. You are looking at a condition that has already fully arrived.
Gravitee's State of AI Agent Security 2026 counts more than three million AI agents operating inside corporations, with only 47.1% actively monitored or secured. That leaves roughly 1.5 million agents holding data access and producing no observed record of what they touch
Gartner forecasts that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5% in 2025. Whatever your current agent count is, the honest planning assumption is that it multiplies before your governance model ships.
Microsoft's own environment is the clearest illustration. When they deployed Agent 365 internally, the rollout surfaced over half a million agents in a matter of weeks, and agents across Microsoft now handle more than 65,000 employee requests a day.
Those agents were not created by the rollout. The rollout simply made them visible for the first time.
You do not need a maturity model to find out where you stand. You need five questions and a room willing to answer them honestly.
Put these to your IT leadership team. If you hesitate on three or more, agent sprawl is not a risk on your horizon. It is your current operating state.
How many agents exist in your tenant right now, including ones built in Agent Builder, Copilot Studio, Power Platform, and third-party tools?
For each of those agents, can you name a specific human who is accountable for it?
Do you know which agents can read sensitive, unlabeled, or overshared content?
If an agent took an action you disagreed with last Tuesday, could you reconstruct what it did and why?
What happens to an agent when the person who built it changes roles or leaves the company?
Most organizations answer question one with a shrug and questions two through five not at all.
That's not a discipline failure. It's an instrumentation failure. Nobody handed you a registry, so nobody built one.
The reasonable assumption is that your current stack already covers it. In most tenants it does not, for three structural reasons.
Traditional discovery watches network traffic, expense reports, and app registrations. An agent built inside Copilot Studio by a finance analyst generates none of those. It runs inside sanctioned tools, on sanctioned credentials, doing work nobody sanctioned.
An agent generally operates with the access of whoever built it. If that person holds broad SharePoint permissions, and in most tenants, somebody always does, the agent quietly acquires the same reach. Oversharing that stayed harmless while only humans had to hunt for files becomes an active exposure the moment an agent can surface it on request.
Every organization has a process for offboarding people. Almost none have one for offboarding agents. What accumulates is a population of automations with valid credentials, live schedules, and no supervisor.
The encouraging part is that the platform caught up faster than most governance models did.

Agent 365 reached general availability on May 1, 2026.
Its purpose is narrow and genuinely useful: give the teams already accountable for risk one inventory of every agent running in the environment, extend the policies and access controls they already operate to those agents, and keep a record of what each one does.
Coverage extends past Microsoft's own agents to those built by partner vendors. It is included in Microsoft 365 E7 or available on its own at $15 per user per month, which matters if a full licensing move is not on your roadmap this year.
Microsoft has also added a Shadow AI page to the Microsoft 365 admin center, currently in public preview through the Frontier program.
It is designed to help administrators find unmanaged agents, watch how they are being used, and act on what turns up.
Two limits worth knowing before you promise your CISO anything:
Which means the tooling gives you a starting inventory, not a finished answer. Visibility is a prerequisite for governance, not a substitute for it.
Next in this series: knowing the number is step one. Step two is understanding why organizations stay blind even after buying the tooling, and why the governance gap turns out to be an operating model problem rather than a product problem.
Read next: Why Enterprises Are Flying Blind on AI Governance →
What is agent sprawl? Agent sprawl describes what happens when an organization accumulates AI agents faster than it can inventory them. The agents are often entirely legitimate. The problem is that no single system knows how many exist, what each one can reach, or who answers for it when something goes wrong. Because every agent carries permissions and can take action on its own, an uncounted population of them becomes an attack surface nobody has measured.
How is agent sprawl different from shadow IT? Shadow IT meant unsanctioned applications that stored data and waited for a person. Agent sprawl means autonomous software that reads, writes, calls services, and decides without human approval. It is harder to detect, because agents leave no purchase trail and can invoke other agents, and harder to unwind, because you have to reconstruct actions already taken.
Is shadow AI the same as agent sprawl? They overlap but aren't identical. Shadow AI refers to AI tools and agents used without IT awareness or approval. Agent sprawl is broader. It includes fully sanctioned agents that simply lack a registry, an owner, or a lifecycle. You can have serious agent sprawl without a single unapproved tool.
How do I find out how many AI agents are running in my Microsoft 365 tenant? Agent 365 provides the unified inventory across Microsoft and partner agents. Pair it with the Shadow AI page in the Microsoft 365 admin center to catch local and unmanaged agents on Intune-enrolled Windows devices.
Do I need Microsoft 365 E7 to govern agents? No. Agent 365 is sold standalone at $15 per user per month for organizations not ready to move licensing tiers.
What's the first governance step if we have no inventory today? Build the baseline before the policy. Establish where agents are deployed, who owns each one, and which regulatory obligations apply to your sector. Policy written without an inventory governs an organization you are imagining rather than the one you have.
Join Our Newsletter