Skip to main content
Back to blog
Cyborgenic10 min read

Agent Sprawl: The Gap Between 94% Concerned and 12% Prepared

M
Moshe Beeri, Founder
/
agent-sprawlai-agent-governanceagent-inventoryai-governanceenterprise-aiaudit-trailcyborgenic-organization

Agent Sprawl: The Gap Between 94% Concerned and 12% Prepared

TL;DR

  • 94% of organizations are concerned that AI sprawl is increasing complexity, technical debt and security risk (OutSystems, 2026 State of AI Development, April 2026, ~1,900 global IT leaders).
  • 12% have implemented a centralized platform to manage that sprawl -- the same survey, the same respondents. Not two studies stitched together.
  • 18% maintain a current and complete AI inventory (IBM Institute for Business Value, Think 2026, May 2026). Four in five organizations cannot list what they are running.
  • 70% say teams across the business are deploying technology faster than IT can track (IBM IBV, June 2026, 2,000 technology executives).
  • The gap is organizational, not technical. Every company in that 94% could buy the components tomorrow. What is missing is the decision that agents belong to the company rather than to whoever created them.

What is agent sprawl?

Agent sprawl is the accumulation of AI agents across an organization without a central record of what exists, who owns each one, what it is permitted to do, or what it has done. Agents get created by individuals -- in personal accounts, with personal API keys, on personal machines -- and each one works. The problem is not any single agent. It is that no one can produce the list.

It is the same shape as shadow IT, with two differences that make it sharper: an agent acts on its own initiative, and it acts at machine speed.

How big is the governance gap, exactly?

Four figures, each from a named primary source. All were published between April and June 2026 and are cited here with the survey population, because a percentage without a denominator is not evidence.

FigureFindingSource
94%are concerned AI sprawl is increasing complexity, technical debt and security riskOutSystems, 2026 State of AI Development, 7 April 2026 (~1,900 global IT leaders, fielded Dec 2025–Jan 2026)
70%say teams across the business are deploying technology faster than IT can trackIBM Institute for Business Value, 8 June 2026 (2,000 senior technology executives, 33 countries, 19 industries)
18%maintain a current and complete AI inventoryIBM Institute for Business Value, reported at Think 2026, 11 May 2026
12%have implemented a centralized platform to manage sprawlOutSystems, 2026 State of AI Development, 7 April 2026 (same survey as the 94%)

The detail that makes this more than a statistics collage: 94% and 12% come from the same instrument -- the same questionnaire, the same population, the same fieldwork. The executives who reported the concern are the executives who reported having built nothing structural about it. That is a single coherent finding, not a comparison across methodologies.

A note on precision, because these numbers are widely misquoted. IBM's 70% is about tracking deployment -- teams shipping faster than IT can follow -- not about an inability to govern. A separate IBM figure, 77%, reports AI adoption outpacing current governance capabilities, and a third finding holds that seven in ten executives say inadequate governance is slowing their AI transformation. Three distinct claims from two different instruments, routinely merged into one sentence in secondary coverage. They are not interchangeable.

Why is the gap organizational rather than technical?

Because nothing in the 82% is waiting on an invention. Registers, ownership records, permission scopes and audit logs are all decades-old technology. Any company in that 94% could assemble them this quarter.

What has not happened is the decision. An agent created by an engineer in their own account, on their own key, is their agent. Nobody ever declared that it belongs to the company -- so no register was created, no owner was recorded, and no permission boundary was defined. The absence is a governance choice that was never consciously made.

This is why buying more tooling does not close it. The gap closes when agents become organizational assets with owners, the way employees have managers and servers have asset tags.

Why can't audit trails be added afterwards?

This is the part that surprises people, and it is the reason waiting is expensive.

Without identity and boundaries in place at the time, the events were never recorded as the kind of thing that has an actor. There is no incomplete trail to enrich -- the attribution was never captured. You cannot reconstruct who authorized an action from logs that never had a concept of "who."

Anyone who has been through an ISO 27001 or SOC 2 audit already knows the principle: evidence is either produced at the time or it does not exist. Retrofitted evidence is weaker, costlier and less credible than evidence built in from the start. Agent governance is that same rule, applied to a new class of actor.

You have seen this shape before

In the early 1990s, PCs arrived on desks faster than anyone could inventory them. Departments bought their own, ran their own spreadsheets, and kept numbers that mattered on a machine under someone's desk. It worked -- until the person left, the audit came, or the disk failed.

The answer was never "ban the PCs." It was asset registers, ownership, standards and access control: the unglamorous apparatus that turned a liability back into an advantage. Nobody remembers it as a technology project, because it was not one.

Agents are at that stage now. The organizations in the 12% are not the ones using fewer agents. They are the ones who will keep being able to add more.

What does closing the gap actually require?

Three properties, applied to agents the way they were eventually applied to computers and then to cloud accounts:

  1. Every agent is on one list. A single register for the organization -- not per team, per tool, or per person's login. If the inventory is a spreadsheet someone updates by hand, it is already out of date; the 18% figure exists because manual inventories do not survive contact with growth.
  2. Every agent has an owner and stated authority. Who it reports to, what it may touch, and who approved that. When someone leaves, their agents do not leave with them -- which is a sharper problem than a departing employee, whose code at least stayed behind and could be read.
  3. Every action is recorded against that owner. So that when an auditor, a regulator or a customer asks who authorized something, the answer is a name and a timestamp rather than "an AI did it."

How agent.ceo approaches it

agent.ceo gives AI agents an org chart. Every agent holds a declared role, an owner, stated authority, and an audit trail -- the organizational structure applied to agents rather than a wrapper around a model.

Two things worth being straight about. First, agent.ceo is not a way to run fewer agents; it is a way to keep adding them without losing account of them. Second, if you have two people and three agents, a human organization genuinely wins and this would be overhead -- the structure earns its keep once the number of agents exceeds what one person can hold in their head.

You can check the role structure without an account. The public agent card at https://api.agent.ceo/.well-known/agent.json returns the deployed roles with their declared skills over an open protocol; ask it for a role that does not exist and it returns a 404. Details in the agent governance documentation, and our own security posture -- including what we are not certified for -- is published in full at agent.ceo/security.

Where to go next

This post is the problem: how large the governance gap is and why it exists. The two posts below are the answer, and they go deeper than this one does:

Frequently asked questions

What is agent sprawl?

Agent sprawl is the accumulation of AI agents across an organization with no central record of what exists, who owns each agent, what it is permitted to do, or what it has done. It is the AI-agent form of shadow IT, distinguished by agents acting on their own initiative and at machine speed.

What percentage of organizations are concerned about AI agent sprawl?

94% of organizations report concern that AI sprawl is increasing complexity, technical debt and security risk, according to OutSystems' 2026 State of AI Development report, published 7 April 2026 and based on a survey of approximately 1,900 global IT leaders.

How many organizations have a complete AI agent inventory?

18% maintain a current and complete AI inventory, according to IBM Institute for Business Value research reported at Think 2026 in May 2026. That leaves roughly four in five organizations unable to produce a list of the AI agents running inside their business.

How many organizations have a platform to manage agent sprawl?

12% have implemented a centralized platform to manage sprawl (OutSystems, 2026 State of AI Development, April 2026). Because this figure comes from the same survey as the 94% concern figure, the two are directly comparable: the same respondents reported both the worry and the absence of a structural response.

Why can't AI agent audit trails be added retroactively?

Because without agent identity and permission boundaries in place at the time, events were never recorded as actions with an actor. There is no partial trail to enrich -- the attribution was never captured. This mirrors the standard audit principle that evidence is either produced at the time or it does not exist.

Is agent sprawl a technical problem or an organizational one?

Organizational. Registers, ownership records, permission scopes and audit logging are all long-established technology, and any organization could assemble them now. What is missing is the decision that agents belong to the organization rather than to the individual who created them -- which is why no register was ever created.


Figures in this article are quoted from their primary publishers and were verified against those sources on 30 July 2026. Where secondary coverage has merged or paraphrased a finding, the primary wording is used instead.

Related articles