Why agent sprawl is a board-level issue (and how to inventory yours this week)
SAP says 98% of enterprises already feel agentic AI reshaping architecture. Here is what agent sprawl looks like in a mid-size business, and a one-hour inventory you can run before the next pilot.
In this week's headlines I flagged Boomi's Agent Control Plane launch and SAP's warning that agent sprawl has moved from an IT ops headache to a board-level risk. Same week, Microsoft reported $214 billion in annual cloud revenue with AI consumption layered on top of seat licenses. Different headlines, same underlying problem: agents are multiplying faster than governance. Start with the September control-plane headlines roundup if you want the news context.
If you run a business, "agent sprawl" might sound like enterprise jargon. It is not. It is what happens when copilots, intake bots, Zapier workflows with LLM steps, and someone's weekend ChatGPT project all touch real customer data, and nobody can produce a list on Monday morning.
What agent sprawl actually looks like
SAP defines sprawl as agents created, deployed, or connected across systems faster than the organization can inventory them, assign ownership, control permissions, monitor behavior, or retire them when they stop working.
In the field, that usually means:
- Marketing runs a CRM copilot with send-email permissions nobody audited.
- Operations tests an intake agent that reads shared drives with PII.
- Finance approved Copilot seats but not the Azure OpenAI workflow engineering built.
- A contractor spun up an MCP server last month. Security found out from a vendor invoice.
Each tool has its own admin console, log format, and approval story. That is sprawl. It is also how you get a Friday-night incident with no owner.
Why boards care now
SAP frames the shift clearly. Agent governance touches risk ownership, regulatory exposure, data protection, auditability, operational resilience, and accountability for autonomous decisions. When 98% of surveyed organizations say agentic AI is already affecting architecture decisions, this is not a 2028 problem.
Boomi's launch on September 2 makes the same point from the vendor side: giving agents deep access to transactional systems without governance is "the largest unmanaged risk in enterprise technology today." Gartner's quote in their release is blunt: by 2027, 40% of enterprises will demote or decommission agents because governance gaps surface only after production incidents.
Boards do not need to understand MCP or RAG. They need to know whether the company can answer three questions in a board packet:
- How many AI agents or copilots touch customer, financial, or employee data?
- Who owns each one, and where is the audit trail for external actions?
- What is the kill switch if one misbehaves tonight?
If those answers are "we are not sure," sprawl is already a governance failure.
Control planes help, but inventory comes first
Cycle 3 was about Enterprise AI Control Planes: one governance layer above every platform. That is still the right end state. Boomi, Guild, Obot, and others are productizing pieces of it this month.
You do not need to buy a platform to start. You need a list. Vendors cannot govern agents they do not know exist. Shadow agents are how sprawl wins.
A one-hour agent inventory (practical)
Block 60 minutes with whoever owns IT, ops, and one line-of-business lead. Open a shared doc and fill this table. No perfect data required. Names and guesses beat silence.
| Agent / copilot name | Owner | Data it reads | External actions | Kill switch? |
|---|---|---|---|---|
| M365 Copilot | IT | M365 tenant | Email, docs | Disable license |
| CRM copilot | Sales | CRM contacts | ? | ? |
| … | … | … | … | … |
Rules for the session:
- Every row needs a named human owner, not "the team."
- "External actions" means anything a customer could see: email, SMS, billing, public posts.
- If kill switch is blank, the agent is not production-ready. Pause it until documented.
- Anything nobody admits to owning goes on a "shadow" list for security review.
Finish by counting rows with blank kill switches. That number is your sprawl score for the quarter. Track it monthly.
What to do after the inventory
- Week 1: pause shadow agents with external access until logged and owned.
- Week 2: standardize one log destination for external actions (channel, DB, or SIEM).
- Week 3: draw approval tiers: auto, notify-after, approve-before.
- Week 4: report sprawl score to leadership. Repeat monthly.
That is how you earn a control plane later. Inventory proves the problem. Policy proves you are serious. Then tools like Boomi's Agent Control Plane or an open-source MCP gateway stop being science projects and start closing gaps you can name.
How Swift Media thinks about this
We run Jarvis agents with explicit scope, dispatch logs, and human oversight in channels because sprawl is the default outcome if you do not design against it. Every agent gets a boundary, an audit trail, and a human who can stop it. That is boring infrastructure. It is also how you scale past the first demo.
If you want help running an agent inventory or standing up lightweight governance for one business unit, talk with us. We will keep it practical. One hour and a spreadsheet beats a six-month strategy project.
Matt Potter · Swift Media
← Back to September headlines · Newer: approval queues & board AI KPIs · approval queue deep dive