Share with your CISO
Agent sprawl, the condition where AI agents multiply across the enterprise faster than anyone can track or control them, has officially become a board-level risk. A LeanIX survey conducted for SAP finds fewer than half of enterprises maintain a clear inventory of their deployed AI agents, exposing them to data security gaps and uncontrolled autonomous actions. SAP, Salesforce, ServiceNow, and Microsoft are each racing to own the governance layer, with the next platform competition shaping up around orchestration and operational trust rather than model performance.
What this means for your business
The inventory problem is the real exposure here. Most enterprises know which servers they own and which SaaS contracts they’ve signed, but they genuinely don’t know how many AI agents are acting on their behalf, what data those agents can touch, or who authorized them. That’s not a governance maturity gap, it’s a shadow IT problem scaled by the speed of agentic deployment, and the CISO who hasn’t started an AI agent audit already owns the liability when something goes wrong.
The vendor race to provide governance tooling is real, but the framing from Futurum, an analyst firm whose advisory business serves several of the vendors it ranks here, skews toward the premise that buying a platform solves the problem. That tilt is worth naming because it’s consequential. SAP’s AI Agent Hub, ServiceNow’s AI Control Tower, and Microsoft Purview are all genuine products addressing genuine risks, but centralized governance tooling only works if the agents being deployed are discoverable in the first place. The harder institutional problem is that business units are spinning up agents without IT or security sign-off, and no vendor dashboard fixes that without an internal policy backstop.
Microsoft’s position deserves particular attention from a security architecture standpoint. Spanning productivity, identity, infrastructure, and security in a single stack means Microsoft can enforce governance at the layer where agent actions actually execute, not just log them after the fact. That’s a structural advantage over point solutions. The falsification condition for this whole governance-as-differentiator thesis is simple: if enterprises standardize on a single hyperscaler stack, governance becomes a default feature, and the multi-vendor orchestration story collapses before the platforms competing on it ever reach scale.
Concept deep-dive: Agent Sprawl
Agent sprawl is what happens when autonomous AI systems, software that takes actions and makes decisions without human approval on each step, get deployed faster than any central team can inventory or monitor them. Think of it as the AI equivalent of the SaaS sprawl problem from the 2010s, where employees signed up for cloud tools on personal credit cards before IT knew they existed. The business risk is identical in structure but higher in stakes, because agents don’t just store data, they act on it.
Based on reporting from Is AI Governance Finally Taking Center Stage in Enterprise Strategy?, originally published 2026-08-05 09:43:00.

