# AI agent governance: What the AI sprawl data means for compliance > AI agent governance is the practice of keeping every deployed AI agent visible, risk-classified, monitored, and auditable across its lifecycle, from the moment it is built to the moment it is retired. AI agent sprawl is the uncontrolled growth of disconnected AI agents across an organisation. **Author:** Maarten Stolk **Last reviewed:** 24 August 2026 **Source:** https://deeploy.ai/eu-ai-act-hub/articles/ai-agent-sprawl-data-compliance/ AI agents have gone mainstream and gone missing at the same time. Large organisations now run them in some form, yet very few can produce an accurate count of how many they are running, who owns them, or what data each one touches. That gap between adoption and oversight is the governance story of 2026, and it connects to the obligations the EU AI Act places on the firms deploying AI systems. This article sets out what the current deployment data actually shows, where the numbers disagree and why, and how the updated EU AI Act timeline, as amended by the Digital Omnibus, changes what compliance and engineering teams need to have in place and by when. ## Adoption is broad, but production is shallow Two things are true in 2026. Uptake has reached most of the market, and depth has not kept pace. Gartner forecasts that 40% of enterprise applications will ship with task-specific AI agents by the end of 2026, up from under 5% in 2025 (Gartner, 26 August 2025). McKinsey's State of AI 2025 survey, fielded across 105 countries with nearly 2,000 respondents, found that 88% of organisations now use AI in at least one business function. On agents specifically, 23% report actively scaling an agentic system in at least one function and a further 62% are experimenting, but in any single business function no more than 10% say they have scaled agents there (McKinsey, 5 November 2025). So experimentation is close to universal, and genuine production scale sits with a minority. Sector matters here. Banking and insurance lead on production deployment at roughly 47%, with healthcare near 18% and government near 14%, according to figures drawn from S&P Global Market Intelligence and McKinsey and widely cited across 2026 industry reporting. These are also the sectors where the EU AI Act's high-risk rules bite hardest, which puts the most regulated buyers at the front of the deployment queue and the compliance queue at once. ## The number that should worry you is the one nobody can produce The most striking dataset across the research is not adoption. It is the count of agents per organisation, and the fact that so few teams can state it with confidence. AI agent sprawl, as it's called, is the shadow IT problem of the 2010s, running faster and with the ability to act rather than just store data. | **Source** | **Sample** | **Current count** | **Projection** | | --- | --- | --- | --- | | Salesforce Connectivity Benchmark 2026 | 1,050 enterprise IT leaders (1,000+ employees) | 12 agents on average | ~20 by 2027 (+67%) | | OutSystems State of AI Development 2026 | 1,900 global IT leaders | 96% use agents in some capacity | 97% exploring system-wide strategy | | Gartner (Digital Workplace Summit, April 2026) | Analyst forecast | Fewer than 15 in 2025 | 150,000+ at the average Global Fortune 500 firm by 2028 | | IDC | Global forecast | ~25 million in 2025 (implied) | 1 billion+ by 2029 (40x) | The spread looks contradictory but it is not. Salesforce and OutSystems are counting agents that IT can currently see at large enterprises. Gartner's 2028 figure includes fine-grained, often short-lived sub-agents, closer to one agent per workflow step than one per business use case, which is why the number runs to six figures. IDC's billion is a global, cross-company total rather than a per-firm average. Different definitions and different horizons, but with the same trend: counts rising 40 to 70% or more year on year, with oversight trailing. The oversight gap is measured directly. OutSystems found that 94% of organisations are concerned that AI sprawl is increasing complexity, technical debt, and security risk, yet only 12% have a centralised platform to manage it, and 38% are mixing custom-built and pre-built agents into stacks that are hard to standardise or secure (OutSystems, 13 April 2026). Salesforce found that only 54% of organisations have a centralised governance framework with formal oversight of AI and agent capabilities, and that half of all deployed agents run in isolated silos rather than as part of a coordinated system (Salesforce Connectivity Benchmark 2026). Gartner's own survey of 360 IT application leaders, cited alongside its 2028 forecast, found just 13% believed they had the right governance in place. Independent security data points the same way. Gravitee surveyed 750 CIOs, CTOs, and engineering VPs across the UK and US twice, in December 2025 and again in April 2026, and found the active-deployer cohort's agent estate had roughly doubled in four months to between 76 and 100 agents per organisation, while security monitoring coverage barely moved (Gravitee, State of AI Agent Security Report 2026). Strip out the exact counts and the pattern holds across every methodology. Agents are proliferating, no standard decommissioning process retires the ones that outlive their purpose, and business units spin up new ones with low-code tools without telling IT, security, or data governance. ## Why AI agent sprawl is a compliance problem, not just an operations one An untracked agent is not only an efficiency drag. Under the EU AI Act it can be an unmet legal obligation with your name on it. The Act is risk-tiered. A handful of practices are [prohibited](https://deeploy.ai/eu-ai-act-hub/topics/prohibited-ai-practices/) outright. A defined set of high-risk uses, many of them in credit, insurance, employment, healthcare, and essential services, carry the heaviest requirements: risk management, data governance, logging and record-keeping, human oversight, transparency to users, accuracy and robustness testing, and [post-market monitoring](https://deeploy.ai/eu-ai-act-hub/articles/eu-ai-act-post-market-monitoring-deployers/). Below that sit transparency obligations for systems that interact with people or generate content. Every one of those requirements assumes you know the system exists. You cannot run a risk assessment on an agent you have not inventoried, you cannot demonstrate human oversight of a workflow you did not know was automated, and you cannot produce logs for a model whose outputs were never captured. Sprawl is, in regulatory terms, a documentation and evidence failure waiting to be found in an audit. ## What good AI agent governance looks like in practice Gartner's recommended response to sprawl, set out in its April 2026 guidance, runs to six steps: set an agent policy, build a centralised agent inventory, define identity, permissions, and lifecycle rules, govern the underlying data access, monitor and remediate behaviour continuously, and build a culture of responsible use. They also warn against simply banning agents, since that pushes staff toward ungoverned [shadow AI](https://deeploy.ai/knowledge/shadow-ai/) that is harder to see than sanctioned tools. Translated into what a team actually needs, effective [**agentic AI governance**](https://deeploy.ai/knowledge/agentic-ai-governance/) rests on a few concrete capabilities: - A single [registry](https://deeploy.ai/knowledge/ai-model-registry/) that captures every agent and model, its owner, its purpose, and its risk classification, so the inventory question has an answer. - Model-level [monitoring for drift](https://deeploy.ai/knowledge/model-drift-detection/), bias, robustness, and performance, because portfolio-level risk catalogues do not detect a model degrading in production. - Explainability attached to individual decisions, so a human reviewer and, later, an auditor can see why an output was produced. - Meaningful human oversight, captured and measurable, rather than asserted in a policy document. - Automatic, prediction-level [audit trails](https://deeploy.ai/knowledge/ai-audits/) that map to the control frameworks a regulator expects, including the EU AI Act, ISO 42001, and NIST AI RMF. - Lifecycle control, so agents that outlive their purpose are retired on purpose rather than left running. The distinction that matters is between knowing which AI risks exist and proving how they are controlled. Portfolio tools and workflow platforms tell you the first. Demonstrating the second requires evidence generated at the model level: bias metrics, drift alerts, explainability reports, and logs tied to specific predictions. ## Where Deeploy fits Deeploy brings every model and use case, from agents to classical ML to embedded and third-party AI, into one platform with visibility, risk control, monitoring, and automatic audit trails. For governance and compliance teams, Deeploy lets you select a control framework (global, EU AI Act, ISO 42001, or custom), assess each use case's risk level, configure approval workflows, and run periodic reviews from a single governance dashboard. For AI and data science teams, it provides real-time monitoring of drift, bias, robustness, and performance, built-in explainers such as SHAP and saliency alongside bring-your-own explainers, guardrails, tracing, and human-in-the-loop feedback capture. Every decision leaves a reproducible, regulator-ready log. The sprawl data says most organisations cannot currently list the agents they run or prove those agents are controlled. [Deeploy's MCP server](https://deeploy.ai/product/agent-governance/) gets every AI agent in an organisation to register itself, ship its traces, and live under the same controls as the rest of your AI estate. [Schedule a personal demo >](https://deeploy.ai/book-demo/) ## Frequently asked questions ### What is AI agent sprawl? AI agent sprawl is the uncontrolled growth of AI agents across an organisation, where new agents are created faster than they can be inventoried, governed, or retired. It typically results from low-code tools letting business units deploy agents without informing IT, security, or data governance, leaving no single record of what exists. ### How many AI agents does an average enterprise run in 2026? Estimates vary by definition. Salesforce's 2026 Connectivity Benchmark puts the average large enterprise at about 12 visible agents today, rising to roughly 20 by 2027. Gartner forecasts more than 150,000 agents at the average Global Fortune 500 firm by 2028 once fine-grained sub-agents are counted. The counts differ because "an agent" is not a standardised unit across sources. ### What does the Digital Omnibus change? The Digital Omnibus on AI, Regulation (EU) 2026/1744, was approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, published in the Official Journal in July 2026, and entered into force on 27 July 2026. It defers the deadline for standalone Annex III high-risk systems to 2 December 2027, and for Annex I product-embedded systems to 2 August 2028. These are now the legally binding dates, replacing the original 2 August 2026 deadline for both categories. It does not defer the Article 50 transparency obligations, which applied as planned from 2 August 2026, and it adds new prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material, taking effect on 2 December 2026. ### Which part of the EU AI Act is already enforceable right now? Five sets of obligations are currently in force. Prohibited AI practices under Article 5 have been enforceable since 2 February 2025. AI literacy obligations under Article 4 also applied from that date. GPAI model obligations under Articles 51–56, along with the governance framework (the AI Office, the European Artificial Intelligence Board, and national competent authorities) and the general fine mechanism under Article 99, became applicable on 2 August 2025. The Act reached its general application date on 2 August 2026, bringing the Article 50 transparency obligations into force. The remaining high-risk obligations under Annex III now apply from 2 December 2027, and Annex I embedded systems from 2 August 2028, following the Digital Omnibus's entry into force on 27 July 2026. ### Does the EU AI Act regulate AI agents specifically?  The Act does not name agents as a separate category. An agent is governed according to the risk classification of the system it belongs to. In practice, an agent operating in a high-risk use case inherits the Article 9 to 15 requirements, and its deployer inherits the Article 26 duties. ### How do you govern AI agents for EU AI Act compliance? It's best to have a structured [compliance checklist](https://deeploy.ai/eu-ai-act-hub/articles/how-to-build-an-eu-ai-act-compliance-checklist/) in place: start with a complete inventory of every agent and model, classify each by risk, and attach model-level monitoring, explainability, human oversight, and automatic audit trails mapped to the Act's requirements. A dedicated governance platform such as Deeploy centralises this so the evidence exists before an audit asks for it.