June 17, 2026 ·
Agent sprawl is the new shadow IT
Microsoft put Agent 365 into general availability this month because most large organisations have lost count of the agents running inside them. Why a control plane is necessary but not sufficient — and what real agent governance looks like.
Microsoft put Agent 365 into general availability this month, and with it a phrase we have been using on client calls for a year finally has a vendor stamp on it: agent sprawl. The pitch is a control plane to discover, govern, and secure AI agents across Microsoft, AWS, and Google Cloud — and the reason a product like that needs to exist is that most large organisations have already lost count of how many agents are running inside them. The market spent 2025 asking whether AI agents were real. In June 2026 it is asking a harder question: who, exactly, owns the seventeen agents that someone in finance stood up last quarter?
This is shadow IT again, with the volume turned up. A decade ago it was unsanctioned SaaS subscriptions on someone’s corporate card. Today it is agents — each one holding credentials, reading from a system of record, and occasionally writing back to it — spun up by people who are not in the security review and would not know how to be. The difference is that a rogue SaaS tool mostly leaked data. A rogue agent acts.
How the sprawl happens
It starts as a win. Someone in operations wires up an agent that drafts supplier emails, and it saves them an afternoon a week. They tell two colleagues. By the end of the quarter there are nine variants of that agent, each with its own prompt, its own API key, and its own quiet access to the inbox and the ERP. None of them are documented. All of them are load-bearing now.
The credentials are the real exposure. An agent is only useful when it can touch a system. So it gets a token. That token rarely gets scoped properly, rarely gets rotated, and almost never gets revoked when the person who created the agent changes teams. Six months in, you have a fleet of long-lived credentials attached to automations nobody on the security team has heard of, doing things at 3am that no human approved that night.
Nobody can answer the audit question. When a record gets changed incorrectly, the first question is “which system did that?” With sprawl, the honest answer is “we are not sure — possibly one of the agents, we are checking.” That sentence is fine in a startup. It is a finding in a regulated business, and the regulators have stopped accepting it.
A control plane is necessary, not sufficient
Tools like Agent 365 — and the governance layers arriving from the other hyperscalers, including Defender’s work to map the relationships between agents, the MCP servers they call, the identities they hold, and the cloud resources they can reach — are genuinely useful. They give you an inventory, and you cannot govern what you cannot see. If you are running agents at any scale and have no control plane, getting one is a sensible first move.
But a control plane tells you what you have. It does not tell you what you should have, which of your agents are safe to keep, which need to be rebuilt against a real schema with scoped permissions, and which should be switched off this afternoon. That is a judgement call about your operations, your data, and your risk appetite — and it is the part no dashboard makes for you. A discovery tool that surfaces forty agents and a recommendation of “review these” has handed you a backlog, not a decision.
What good governance actually looks like
- An inventory with an owner per agent. Not a list — a register where every running agent has a named human accountable for it, a documented purpose, and a date it was last reviewed.
- Scoped, rotating, revocable credentials. Each agent gets the narrowest access that lets it do its job, issued through identity infrastructure you already trust, and killed automatically when the owner leaves the team.
- A replayable audit trail. For anything touching a system of record, you can reconstruct what the agent saw, which tools it called, and why it acted — not a screenshot after a support ticket, a replay.
- A kill switch and a graduation path. An obvious way to stop any agent immediately, and a defined route for promoting a useful experiment into something the engineering team actually maintains.
This is unglamorous work, and it is exactly the work a Cravings readiness assessment is built to do: walk the real estate of agents already running inside your business, separate the ones earning their keep from the ones quietly accumulating risk, and hand you a register with owners, permissions, and a remediation order — a decision, not just a dashboard.
The honest counter-argument
You could argue that clamping down on agent sprawl kills the experimentation that produced the wins in the first place. There is something to this. The operations person who built the supplier-email agent created real value, and a governance regime that makes that impossible has overcorrected. The answer is not to stop people building — it is to give them a safe sandbox to build in and a clear path to production, so the useful experiments get adopted and hardened rather than left to rot into liabilities. Governance done badly stops the building. Governance done well just makes sure the building does not happen on top of the production database by accident.
What to do in the next 30 days
- Run a discovery pass. Whether through a control plane or a manual sweep, find out how many agents are actually running and what they can touch. Most teams are surprised by the number.
- Assign an owner to every one. An agent without a named human is the first one to switch off.
- Audit the credentials. Look for long-lived, over-scoped tokens attached to automations. Those are your highest-leverage fixes.
- Decide before you renew. If a vendor’s governance bundle is up for purchase, buy the inventory — but own the keep-rebuild-kill decision yourself.
Agent sprawl is not a reason to slow down on AI. It is a sign you moved fast enough to create something worth governing. The companies that handle this quarter well are the ones who treat the agent fleet the way they already treat the rest of production — owned, scoped, logged, and answerable — rather than as a pile of clever experiments nobody is quite responsible for.
Not sure how many agents are already running inside your business — or who owns them? A Cravings readiness assessment maps the fleet, scores each agent on value and risk, and hands you a register with owners, permissions, and a remediation order. Yours to keep, whether or not we do the remediation.