"Every department that deployed an agent last quarter thought it was solving its own problem. None of them thought they were building your shadow IT department."
In Today’s Email:
Gartner projects enterprises will run an average of more than 1,600 AI agents by the end of 2026, and only 18% of those organizations can name every agent already operating inside their walls. That gap between deployment speed and organizational awareness is the subject of this issue: agent sprawl, the shadow IT problem of the digital workforce, where sales ops builds an agent in the CRM, marketing builds one in the campaign platform, and finance builds a third in a spreadsheet copilot, all without a single shared record that any of them exist. We covered why integration, not intelligence, holds agents back in "The Quiet Crisis" (Feb 18), and why the org chart needs a digital layer in "The Agent Operating Model" (Mar 19). Agent sprawl is what happens when neither problem gets solved: fragmented tooling meets undefined ownership, and the result is a fleet nobody can see, secure, or account for.
News
1. The "2% Reality Check" on Workforce AI Maturity
Despite the massive hype surrounding enterprise AI, a sweeping new report from the ActivTrak Productivity Lab released on July 21 reveals a stark implementation gap. After analyzing the behavioral data of over 120,000 workers, the study found that while 82% of employees consistently use AI, only a staggering 2% have actually integrated it into their end-to-end workflows. The vast majority are stuck in "Stage 1" (using AI for basic research) or "Stage 2" (drafting simple content). The data highlights a critical blind spot for corporate leaders: simply distributing AI licenses and tracking login counts does not mean the workforce has fundamentally changed how it operates.
Key Takeaway: Don't mistake AI access for operational maturity. To capture real ROI, leaders must shift their focus from buying software to actively redesigning departmental processes so that AI is embedded across multiple workflow steps, rather than just being used for isolated, routine tasks.
2. Hackers Deploy AI Agents to Compress Attack Timelines
Cybersecurity took a concerning turn this week with the release of the Sophos AI Security 2026 Report on July 22, which confirmed that threat actors are now actively operationalizing artificial intelligence as a force multiplier. Sophos uncovered a campaign where hackers ran an operation inside a customer's network using roughly a dozen AI agents to write, test, and iterate attacks, collapsing an attack timeline that would normally take weeks down to just a few days. Crucially, attackers are now heavily targeting enterprise "Non-Human Identities"; such as internal AI agents, API keys, and OAuth tokens; turning the very tools companies are deploying for productivity into high-value vulnerabilities.
Key Takeaway: AI is now a severe identity and governance issue. As cybercriminals leverage autonomous agents to rapidly execute attacks, your IT and security teams must immediately lock down the permissions, credentials, and access levels of your own internal AI tools to prevent them from being hijacked.
3. Intel and Google Cloud Push "Agentic" AI into Core Operations
Demonstrating how major enterprises are attempting to overcome the AI maturity gap, Intel announced a massive strategic expansion with Google Cloud on July 16 to deploy Gemini Enterprise across its global workforce. Moving far beyond administrative chatbots, this collaboration explicitly targets the creation of "scalable agentic workflows" designed to bolster heavy-duty corporate functions, including engineering and supply chain operations. By integrating generative AI directly into its core business workflows, Intel is signaling a critical transition: enterprise AI is graduating from a personal productivity assistant into a foundational operational engine.
Key Takeaway: The blueprint for enterprise AI is advancing rapidly. If your organization's AI strategy is still entirely focused on helping employees summarize meetings or write emails faster, you are falling behind competitors who are actively using interconnected agents to optimize their core supply chains and engineering cycles.
The Proliferation Nobody Approved
Six months ago, most enterprises were running pilot programs. Today they're running fleets. Gartner's latest forecast puts the average enterprise at more than 1,600 AI agents by the close of 2026, spread across sales, marketing, finance, HR, customer support, and IT itself. Salesforce's own research found organizations already operate an average of 12 agents today, a number it expects to climb to 20 by 2027, and that 83% of organizations report most or all of their teams have adopted agents in some form.
None of that growth is centrally coordinated. It's happening inside CRM platforms with built-in agent builders, inside low-code automation tools that product teams adopted without a procurement review, inside spreadsheet copilots that finance analysts configured on a Tuesday afternoon. Each deployment solves a local problem. Each one is invisible to everyone outside the department that built it.
The inventory numbers make the scale of the blind spot concrete. Only 18% of enterprises maintain a complete inventory of the agents already running in their environment, according to Gartner, a figure IBM's own research corroborates almost exactly. The Cloud Security Alliance's January 2026 survey of 418 IT and security professionals found that 82% of enterprises have unknown AI agents operating in their infrastructure right now, discovered only after the fact. This isn't a future risk. It's a present-tense operational reality that most organizations have not yet admitted to themselves.
Why This Isn't Shadow IT 2.0
The comparison to shadow IT is useful, but it understates the problem. Classic shadow IT meant an employee signed up for a SaaS tool without approval. The risk was data sitting somewhere it shouldn't, unencrypted, unbacked-up, outside the compliance boundary. Bad, but bounded: the tool stored things. IT could eventually find it, revoke a login, and close the gap without much operational disruption beyond the initial discovery.
Microsoft's Cyber Pulse research puts a number on how far the underlying adoption has already run: 80% of Fortune 500 companies now deploy active AI agents in some form, and 29% of employees admit to using agents their organization never sanctioned. That's a wider base of unauthorized deployment than shadow IT ever reached at a comparable stage, and it's spreading through a category of tool that doesn't just hold data. It acts on it.
Agents don't store things. They act. An unsanctioned agent built in a sales platform can pull customer records, draft and send communications, update pricing, and trigger downstream workflows, all without a human clicking send. A finance agent built to reconcile invoices can approve payments. A support agent can issue refunds. When "The Quiet Crisis" (Feb 18) described integration gaps as the barrier holding agents back, it was describing the same fragmented, ad hoc tooling landscape that now makes sprawl so dangerous: agents connected through brittle point-to-point integrations, MCP and A2A protocols bolted on inconsistently, legacy systems exposed through whatever access the builder happened to have. An agent with too much access and no oversight isn't a data governance problem anymore. It's an operational one.
The Cloud Security Alliance's numbers back this up directly. Sixty-five percent of enterprises reported an AI agent-related incident in the past 12 months. Of those, 61% involved data exposure, 43% caused operational disruption, and 35% resulted in measurable financial loss. Shadow AI-related breaches now average $4.63 million and account for roughly 20% of all data breach incidents tracked. Shadow IT was a compliance headache. Agent sprawl is an incident waiting for a trigger.
The authentication layer makes the exposure worse than the incident numbers alone suggest. A meaningful share of agent deployments, by some estimates close to half, still rely on shared API keys for agent-to-agent authentication rather than individually scoped credentials. A compromised key doesn't expose one agent's access. It exposes every agent built on the same shared credential, which in a sprawled environment could mean dozens of unrelated workflows across multiple departments going dark or going rogue at once. Traditional shadow IT never had that kind of blast radius, because a rogue spreadsheet doesn't cascade into other systems the way a compromised agent credential can.
The Inventory Illusion
The most dangerous part of agent sprawl isn't that leaders don't know their agent count. It's that most of them think they do. The Cloud Security Alliance's survey found that 68% of respondents believe they have strong visibility into the AI agents running in their organization, even as 82% of those same organizations were shown to have unknown agents in production. A separate Cloud Security Alliance analysis published this July found the gap widens further at the executive level: 90% of executives report confidence in their organization's visibility into AI tools, while 52% of employees admit to using unapproved AI applications, often through personal accounts specifically to avoid detection.
That confidence gap isn't dishonesty. It's a measurement failure. Most organizations built their visibility processes around applications, not agents: a security review when software gets purchased, a data classification pass when a new system goes live. Agents don't go through that funnel. They get spun up inside tools the organization already approved, using credentials that already exist, by employees who never thought of themselves as deploying infrastructure. Only 21% of organizations in the Cloud Security Alliance survey have a formal process for decommissioning agents once they're no longer needed, which means the fleet only grows. Forty-one percent discovered unknown agents in their environment more than once in the past year, which means discovery itself isn't solving the problem. It's just producing a rolling series of surprises.
Where the Agents Are Hiding
If you're building a discovery plan, start where the Cloud Security Alliance found them. Fifty-one percent of shadow agents live inside internal automation and scripting environments, the kind of thing an ops-minded analyst builds to save themselves an afternoon of manual work. Forty-seven percent run inside LLM platforms, as custom tools, assistants, or plugins nobody registered anywhere. Forty percent sit inside SaaS platforms with agent capability built directly into the product, meaning your CRM, your support desk, and your marketing automation platform may already be running agents you never explicitly turned on. Another 40% come from developer-created workflows, engineers automating their own pipelines with agents that never touch a formal deployment process.
The pattern across all four categories is the same: agents get built by the people closest to the work, using whatever tools are already in their hands, with no requirement to tell anyone. Salesforce's research on organizations running a dozen or more agents found that half of them operate in complete isolation from each other, not as a coordinated system but as parallel, disconnected experiments. That's the practical definition of sprawl: not too many agents, but too many agents nobody planned for, integrated, or is tracking against a shared record.
What Sprawl Looks Like Up Close
Consider a composite drawn from conversations with several enterprise IT leaders this year, representative of a pattern showing up across financial services, healthcare, and retail alike. A global insurer's claims organization built an agent to triage incoming claims and draft initial coverage determinations, using a low-code platform the business unit had already licensed for something else entirely. It worked well enough that three regional offices copied the approach independently, each with slightly different data access, different escalation logic, and no shared documentation between them. Eight months later, a routine data audit turned up eleven claims-triage agents running in parallel, three of which had access to a data source that had been restricted for an unrelated compliance reason months earlier. Nobody in the security organization had approved any of them. Nobody in the business had asked whether eleven agents should have been one.
That isn't a failure of intent. Every regional team was solving a real problem with the tools already in front of them, faster than waiting on a centralized build queue would have allowed. It's a failure of the discovery, visibility, and ownership gaps described throughout this issue, showing up in a single department at a scale that's easy to imagine repeating across every function of a large enterprise at once. Multiply eleven claims agents by every business unit running its own version of the same story, and 1,600 agents by year's end stops sounding like an outlier estimate and starts sounding conservative.
The Cost of Not Knowing
Every one of the risks above compounds the longer an organization goes without a real inventory. Enterprises are treating agent governance as binary, either locked down or fully trusted, and that binary framing is the reason governance keeps failing. Locking everything down drives builders toward unsanctioned tools, which is exactly how sprawl accelerates. Trusting everything by default means autonomous agents execute actions at a speed and scale that outpaces any human's ability to catch a problem before it happens.
Gartner now predicts that 40% of enterprises will demote or fully decommission autonomous agents by 2027, specifically because governance gaps get identified only after a production incident forces the issue. That's an expensive way to build a governance program: ship first, discover the agent exists during an audit or a breach, then rip it out. Only 34% of organizations currently apply the same security controls to AI agents that they apply to human employees, despite agents routinely holding equivalent or greater access to sensitive systems. Just 25% of CIOs report full visibility into every agent running in production, even though 87% say agents are now embedded in critical systems. The gap between where agents sit in the business and how closely anyone is watching them is the whole story of agent sprawl in one comparison.
Ownership Is the Missing Layer
Agent sprawl isn't at its core a discovery problem. It's a symptom of the question we raised in "The Agent Operating Model" (Mar 19): who owns an agent once it's live? Most organizations still don't have an answer. IT owns infrastructure but not the business logic a sales agent executes. The business unit owns the use case but has no security or compliance function attached to it. Nobody owns the full lifecycle, from approval through monitoring through decommissioning, which is exactly why only 21% of enterprises have a formal process for retiring an agent once it's no longer needed.
Federated ownership, where each department deploys and manages its own agents, is how sprawl gets created in the first place. Fully centralized ownership, where every agent has to route through a single team for approval, is how sprawl gets replaced by bottlenecks and the shadow deployments that follow when the approved path is too slow. The organizations getting this right are building a middle model: a central registry and a set of non-negotiable baseline controls, paired with delegated authority for department-level teams to build and operate agents within those guardrails. Ownership doesn't mean one team touches every agent. It means every agent has exactly one team accountable for knowing it exists, what it can access, and when it should be retired.
In practice, that accountability has to be assigned before the agent goes live, not discovered after the fact during an audit. A workable model names a business owner responsible for the use case, a technical owner responsible for access and integration, and a governance function that reviews both against a common set of controls before anything reaches production. None of that requires every agent to be built by IT. It requires every agent to be registered by IT, or by whatever function holds the registry, at the moment it's created. That single requirement, enforced consistently, closes most of the gap between the 82% of enterprises with unknown agents and the 18% who can currently account for their entire fleet.
Building the Registry
An inventory is not a spreadsheet somebody updates quarterly. It has to be a living registry, populated automatically, that answers three questions for every agent in the environment: what can it access, who is accountable for it, and is it still needed. Managing agent sprawl starts with automated discovery scans running continuously across cloud and SaaS environments, rather than periodic manual audits that are stale the moment they're published.
From there, governance has to scale with risk rather than apply uniformly. A low-autonomy agent doing scoped, reversible work needs baseline controls: scoped data access, logged usage, basic security testing. A highly autonomous agent making consequential decisions at speed needs meaningfully stronger oversight, including human review that stays meaningful rather than becoming a rubber stamp. That tiered approach is the direct fix for the binary trap. It's also the only model that scales past a few dozen agents to the 1,600 an average enterprise will be running by year's end. Standardizing the platforms agents get built on, rather than allowing unlimited proliferation of tools, further shrinks the surface area any registry has to track. None of this is optional infrastructure anymore. It's the baseline cost of running a digital workforce at the scale enterprises are now running one.
The organizations further along treat the registry the same way they'd treat an asset management system for physical hardware: nothing goes into production without an entry, and nothing stays in production past its useful life without a review. That discipline sounds basic because it is. What's new isn't the concept, it's the speed at which agents get created and the ease with which any employee with access to a modern SaaS platform can stand one up without touching a procurement process at all. A registry built for a world where deployment took months doesn't hold up in a world where it takes an afternoon.
The Bottom Line
Agent sprawl feels like a technology problem because it shows up as a technology symptom: unknown systems, undocumented access, unmonitored actions. But the root cause sits upstream of any tool. It's the absence of a clear answer to who owns an agent, paired with the absence of any mechanism that forces every new agent through a shared point of visibility. Fix the ownership question from "The Agent Operating Model" and fix the integration fragmentation from "The Quiet Crisis," and sprawl stops accelerating. Leave both unresolved, and the 1,600-agent estimate for this year becomes a conservative floor for next year.
The organizations that get ahead of this aren't the ones that slow down deployment. Slowing down is what pushes builders toward the unsanctioned tools that created this problem to begin with. The organizations getting ahead are the ones building the registry now, while the fleet is still countable, rather than waiting for an incident to force a headcount. Eighteen percent of enterprises can currently say with confidence how many agents they're running and what each one can touch. The other 82% are one audit, one breach, or one regulator's question away from finding out the hard way.
Visibility isn't a compliance checkbox. It's the precondition for every other governance decision this newsletter has covered, from identity and privilege to human-in-the-lead oversight to the operating model that assigns accountability in the first place. You cannot govern, secure, or measure the return on an agent you don't know exists.
Getting a handle on agent sprawl starts with an honest assessment of what's already running in your environment, and most organizations are surprised by what that assessment turns up. The Complete Agentic AI Readiness Assessment includes structured frameworks for conducting an agent inventory, defining ownership models across centralized and federated structures, and building the tiered governance controls that scale from a dozen agents to a thousand. Get your copy on Amazon or learn more at yourdigitalworkforce.com. For organizations that suspect their real agent count is higher than their official one, our AI Blueprint consulting helps run a full agent discovery and inventory process, design the ownership model that keeps sprawl from recurring, and stand up the registry infrastructure that turns an unknown fleet into a governed one.

