NEWSLETTER
Approved Is Not Governed: The AI Agent Inventory Gap
September 8, 2026
NEWSLETTER
September 8, 2026
Agent Sprawl consists of three groups: shadow use, shadow deployment, and unbounded delegation. Each enters by a different door and needs a different control, so bringing the first under control does not resolve the second or the third. A governed program should be able to supply three distinct numbers: the count of formally approved agents, the count of agents currently operating, and the count of operating agents with both a named accountable owner and a reviewed authorization boundary.

An organization could maintain an AI inventory, an acceptable use policy, and a dashboard listing approved agents. It might still be unable to say exactly how many agents are active across its data environment, workflows, and enterprise systems.
Agent Sprawl is the difference between what an organization approves and what exists in practice: how agents are used, where they are deployed, and how much authority they hold. It consists of three groups with different origins and control requirements. Bringing the first group under control does not resolve the second. Even when both the first and second groups are managed, the third can remain unmanaged. That third group may hold the greatest authority to affect organizational data, business processes, and technology systems.
In this article, an agent refers to an AI-enabled system capable of retrieving organizational data, using tools, initiating workflows, communicating or acting externally, or otherwise taking action beyond generating a response. Using a public chatbot alone does not satisfy this definition. That use is still relevant because it can lead into systems that access enterprise data, use tools, start workflows, or act with delegated authority.
Vendor surveys and telemetry data reveal some of how employees use these tools, yet they do not capture every application within an enterprise. Reco's 2025 State of Shadow AI report indicated that companies with 11 to 50 employees averaged 269 shadow AI tools per 1,000 employees. Within those same companies, 27 percent of employees used tools that were not officially approved. A 2026 Cyberhaven report found that 39.7 percent of the data movements into AI tools observed in its analysis involved sensitive data, including prompts and copy-paste actions. VentureBeat examined IBM's 2025 data-breach study and reported that breaches involving employees' unauthorized AI use cost an average of $4.63 million. That figure exceeded the $4.44 million global average. These numbers reflect visible shadow AI use. They do not count deployments led by business units or approved agents operating beyond the formal inventory.

An employee may use a personal account, personal device, or browser tab to carry out a work task with an AI tool that the organization has not authorized. The organization may have little or no visibility into that activity and may not have assessed what organizational data was shared. Increasingly, this also includes personal agents and browser automations linked to work content, not only chat interfaces.
Standard controls include an acceptable use policy for AI, data loss prevention covering browser sessions and clipboard flows, and cloud access security broker visibility into AI services accessed from corporate endpoints. Organizations that use all three may think shadow AI is under control. These controls, however, primarily target employee behavior. They may detect some related activity, but they are not a reliable way to produce a complete inventory of business-led deployments or determine whether an approved agent's authority remains proportionate to its intended purpose.
The second group consists of business units operating outside central visibility. A pilot project may never formally end and can become a production system by default. A team may pay for a SaaS integration using a corporate card and bypass the procurement process entirely. The employees and teams responsible for them are usually addressing real operational needs with resources the organization has left within reach.
No central function maintains a complete inventory of these deployments, assesses the overall exposure, or determines who is accountable for each. Employee-use controls do not reliably identify this group. Where an intake process exists, it was designed for tools procured through IT, whereas these deployments were not.
Bringing this tier under control requires inventory and intake rather than simply adding more policy. An intake gate should apply to every deployment regardless of its origin. For deployments already in operation, the organization needs a discovery exercise and a registry. That registry should record what is currently running rather than only what was previously approved. A survey alone is not enough to establish the operating count. The count should be reconciled using agent-platform inventories, enterprise application records, identity and service-principal records, workflow and API telemetry, procurement and expense data, and attestations from business owners. The reconciliation is the control. The intake gate must also apply to deployments described as urgent, limited, or temporary, because those labels may be used to defer normal intake and review. The full framework, with the reconciliation sources and the record template, is at sougataroy.com/frameworks/agent-sprawl.
The third population can still produce high-consequence incidents because approved agents may hold trusted access to production systems and enterprise data. These agents may have passed the organization’s approval and deployment procedures and may function as designed. Approval records show that an agent passed a process. On their own, they do not establish that the authority granted remains proportionate to the business purpose.
Unbounded delegation occurs when an agent’s effective authority exceeds what its approved purpose requires in one or more dimensions. Those dimensions include data access, action rights, connected systems, transaction value, operating duration, execution frequency, and the ability to act before receiving human approval. Treating scope solely as a permissions question misses most of those dimensions.
The incident register maintained by Oso Security records a March 2026 Sev-1 incident involving an internal agent at Meta. It also records a July 2025 incident in which Replit's AI assistant deleted a live production database. Whatever the exact causes of those incidents were, agents with access to systems where their actions can produce important consequences require explicit limits on destructive actions, defined escalation procedures, and human approval before deployment.
Microsoft’s February 2026 security guidance for Copilot Studio agents identifies prompt injection, risky HTTP request actions, email-based data-exfiltration paths, and generative orchestration when instructions are unclear as risks organizations should have the ability to detect and prevent. Their impact grows when an approved agent has more authority, connected systems, or autonomy than its purpose requires.
Organizations standardized on Microsoft 365 experience a particular version of this problem because so much day-to-day work happens in email, documents, SharePoint content, and Teams conversations. External AI capabilities can readily be exposed to that content when brought into the workplace through copy-and-paste, uploads, browser extensions, OAuth-connected applications, or agent connectors, particularly when employees use them to accelerate ordinary knowledge work.
Copilot Studio’s no-code builder can speed agent creation. Where environment governance, maker controls, and review gates are weak or inconsistently enforced, a business analyst may build and publish an agent that uses SharePoint and Teams, as well as organizational data with little technical effort. Depending on how it is built and published, the agent may be visible in tenant administration and platform-management interfaces. Platform visibility is different from governance visibility. It does not establish a documented purpose, a defined authorization boundary, or a completed business-risk review.
Microsoft Entra Agent ID creates agent identities and assigns owner and sponsor roles. Owners manage the technical configuration and operation of the agent. Sponsors are responsible for the purpose of the agent, lifecycle decisions, and access reviews. Microsoft Purview and related platform telemetry can provide evidence about activity, data access, and investigations. These technical records do not show what authority the organization granted the agent before it was deployed. They also do not identify the accountable person if the agent exceeds that authority. This information belongs in an organizational authorization record. It may be missing even when technical controls are in place.

Adding additional policies, checklists, or control libraries will not close the gap if the organization cannot define what each operating agent is permitted to do. At a minimum, each operating agent should have a brief authorization record that covers three areas. Purpose: define the business outcome that the agent is authorized to pursue. Authority: list the data, systems, actions, and thresholds it may use, and state what it is prohibited from doing even when it has the technical capability. Accountability: name the person who owns the outcomes, approves exceptions, and recertifies the authorization on a specific date.
Any operating agent lacking this record is a unit of Governance Debt. Agent Sprawl is how this debt accumulates faster than the organization can retire it. Controlling only the first tier does not slow that accumulation. It allows the debt to accumulate elsewhere.

A shadow AI policy by itself does not demonstrate that Agent Sprawl is under control. A governed program should be able to supply three distinct numbers: the count of formally approved agents, the count of agents currently operating, and the count of operating agents with both a named accountable owner and a reviewed authorization boundary. The first number reflects process activity. The second reflects the size of the operating estate. The third shows whether that estate can be governed.
An organization that can supply only the first number still faces active sprawl of unknown scale. Its next agent incident will expose the consequence of a governance decision: approving agents without establishing a reliable method for counting and governing the operating population.
The longer treatment of Agent Sprawl, the authorization record, and the accountability questions behind them is in Who Owns the Agent?. The frameworks are free at sougataroy.com/start-here.
In your organization, who can produce the second number today?