top of page

AI Agent Sprawl is Now a Board Issue

  • Writer: Daniel Ruggles
    Daniel Ruggles
  • 2 days ago
  • 2 min read

Enterprises did not set out to hire an autonomous workforce. They set out to automate work. The result is the same: agents appearing in customer service, finance, supply chain, and IT faster than anyone can name an owner, bound their permissions, or explain what happens when one of them fails.

 

That is agent sprawl. It is the successor to shadow IT, with one important difference. A hidden app mostly stores or displays information. A hidden agent can act.

 

Gartner’s 2026 warning made the scale hard to ignore: by 2028, the average Fortune 500 firm may run more than 150,000 agents, while only a small minority of organizations believe they have the right governance in place. SAP’s own enterprise coverage has pushed the same message into executive channels: most companies are deploying or planning agents; far fewer have a complete inventory. Security communities on X have added the identity and authorization layer—who the agent is, what it can touch, and who can stop it.



A one-page agent portfolio turns “autonomous workforce” from a slogan into an inventory: owner, purpose, permissions, model, risk, override, incident path, and ROI.
A one-page agent portfolio turns “autonomous workforce” from a slogan into an inventory: owner, purpose, permissions, model, risk, override, incident path, and ROI.

Boards do not need another principles deck. They need to treat agents as a managed workforce with owners, mandates, and an incident path. Simple agent inventory:

 ·         Business owner — a named accountable executive, not a shared mailbox 

·         Purpose — the business outcome the agent is allowed to pursue 

·         Permissions — systems, data, and tools it can use 

·         Model / vendor — what is running and who supplies it 

·         Risk tier — a simple classification that drives the depth of control 

·         Human override — how a person stops or redirects the agent 

·         Incident path — who is called, in what order, when behavior goes wrong 

·         ROI — cost, value, and whether the agent still earns its keep 

 

That inventory is not the whole control system. It is the practical first step. You cannot assign roles, set risk treatment, or prove oversight for agents you cannot list.

 

ISO 42001 is the certifiable AI management system standard. Clause 5 is the board-relevant piece: top management must show commitment, publish an AI policy aligned with strategy, and assign roles, responsibilities, and authorities for AI. Auditors look for evidence that someone is accountable across the AI lifecycle—not that every model is perfect.

 

“Autonomous workforce” and “agent sprawl” convert a policy problem into a management problem. Board-level language raises urgency. The one-page inventory gives operators something they can complete this quarter. Platform vendors and enterprise architecture tools are already building the discovery and registry layer; the gap is leadership ownership, not another framework.

 

The question for the next board pack is not whether the company uses agents. It is whether the company can produce the portfolio—and name who is accountable for it.

Comments


bottom of page