AI agent governance: What the AI sprawl data means for compliance

7 min readLast reviewed 24 August 2026
In short

AI agent governance is the practice of keeping every deployed AI agent visible, risk-classified, monitored, and auditable across its lifecycle, from the moment it is built to the moment it is retired. AI agent sprawl is the uncontrolled growth of disconnected AI agents across an organisation.

AI agents have gone mainstream and gone missing at the same time. Large organisations now run them in some form, yet very few can produce an accurate count of how many they are running, who owns them, or what data each one touches. That gap between adoption and oversight is the governance story of 2026, and it connects to the obligations the EU AI Act places on the firms deploying AI systems.

This article sets out what the current deployment data actually shows, where the numbers disagree and why, and how the updated EU AI Act timeline, as amended by the Digital Omnibus, changes what compliance and engineering teams need to have in place and by when.

Adoption is broad, but production is shallow

Two things are true in 2026. Uptake has reached most of the market, and depth has not kept pace.

Gartner forecasts that 40% of enterprise applications will ship with task-specific AI agents by the end of 2026, up from under 5% in 2025 (Gartner, 26 August 2025). McKinsey’s State of AI 2025 survey, fielded across 105 countries with nearly 2,000 respondents, found that 88% of organisations now use AI in at least one business function. On agents specifically, 23% report actively scaling an agentic system in at least one function and a further 62% are experimenting, but in any single business function no more than 10% say they have scaled agents there (McKinsey, 5 November 2025).

So experimentation is close to universal, and genuine production scale sits with a minority. Sector matters here. Banking and insurance lead on production deployment at roughly 47%, with healthcare near 18% and government near 14%, according to figures drawn from S&P Global Market Intelligence and McKinsey and widely cited across 2026 industry reporting. These are also the sectors where the EU AI Act’s high-risk rules bite hardest, which puts the most regulated buyers at the front of the deployment queue and the compliance queue at once.

The number that should worry you is the one nobody can produce

The most striking dataset across the research is not adoption. It is the count of agents per organisation, and the fact that so few teams can state it with confidence.

AI agent sprawl, as it’s called, is the shadow IT problem of the 2010s, running faster and with the ability to act rather than just store data.

SourceSampleCurrent countProjection
Salesforce Connectivity Benchmark 20261,050 enterprise IT leaders (1,000+ employees)12 agents on average~20 by 2027 (+67%)
OutSystems State of AI Development 20261,900 global IT leaders96% use agents in some capacity97% exploring system-wide strategy
Gartner (Digital Workplace Summit, April 2026)Analyst forecastFewer than 15 in 2025150,000+ at the average Global Fortune 500 firm by 2028
IDCGlobal forecast~25 million in 2025 (implied)1 billion+ by 2029 (40x)

The spread looks contradictory but it is not. Salesforce and OutSystems are counting agents that IT can currently see at large enterprises. Gartner’s 2028 figure includes fine-grained, often short-lived sub-agents, closer to one agent per workflow step than one per business use case, which is why the number runs to six figures. IDC’s billion is a global, cross-company total rather than a per-firm average. Different definitions and different horizons, but with the same trend: counts rising 40 to 70% or more year on year, with oversight trailing.

The oversight gap is measured directly. OutSystems found that 94% of organisations are concerned that AI sprawl is increasing complexity, technical debt, and security risk, yet only 12% have a centralised platform to manage it, and 38% are mixing custom-built and pre-built agents into stacks that are hard to standardise or secure (OutSystems, 13 April 2026).

Salesforce found that only 54% of organisations have a centralised governance framework with formal oversight of AI and agent capabilities, and that half of all deployed agents run in isolated silos rather than as part of a coordinated system (Salesforce Connectivity Benchmark 2026).

Gartner’s own survey of 360 IT application leaders, cited alongside its 2028 forecast, found just 13% believed they had the right governance in place.

Independent security data points the same way. Gravitee surveyed 750 CIOs, CTOs, and engineering VPs across the UK and US twice, in December 2025 and again in April 2026, and found the active-deployer cohort’s agent estate had roughly doubled in four months to between 76 and 100 agents per organisation, while security monitoring coverage barely moved (Gravitee, State of AI Agent Security Report 2026).

Strip out the exact counts and the pattern holds across every methodology. Agents are proliferating, no standard decommissioning process retires the ones that outlive their purpose, and business units spin up new ones with low-code tools without telling IT, security, or data governance.

Why AI agent sprawl is a compliance problem, not just an operations one

An untracked agent is not only an efficiency drag. Under the EU AI Act it can be an unmet legal obligation with your name on it.

The Act is risk-tiered. A handful of practices are prohibited outright. A defined set of high-risk uses, many of them in credit, insurance, employment, healthcare, and essential services, carry the heaviest requirements: risk management, data governance, logging and record-keeping, human oversight, transparency to users, accuracy and robustness testing, and post-market monitoring. Below that sit transparency obligations for systems that interact with people or generate content.

Every one of those requirements assumes you know the system exists. You cannot run a risk assessment on an agent you have not inventoried, you cannot demonstrate human oversight of a workflow you did not know was automated, and you cannot produce logs for a model whose outputs were never captured. Sprawl is, in regulatory terms, a documentation and evidence failure waiting to be found in an audit.

What good AI agent governance looks like in practice

Gartner’s recommended response to sprawl, set out in its April 2026 guidance, runs to six steps: set an agent policy, build a centralised agent inventory, define identity, permissions, and lifecycle rules, govern the underlying data access, monitor and remediate behaviour continuously, and build a culture of responsible use.

They also warn against simply banning agents, since that pushes staff toward ungoverned shadow AI that is harder to see than sanctioned tools.

Translated into what a team actually needs, effective agentic AI governance rests on a few concrete capabilities:

  • A single registry that captures every agent and model, its owner, its purpose, and its risk classification, so the inventory question has an answer.
  • Model-level monitoring for drift, bias, robustness, and performance, because portfolio-level risk catalogues do not detect a model degrading in production.
  • Explainability attached to individual decisions, so a human reviewer and, later, an auditor can see why an output was produced.
  • Meaningful human oversight, captured and measurable, rather than asserted in a policy document.
  • Automatic, prediction-level audit trails that map to the control frameworks a regulator expects, including the EU AI Act, ISO 42001, and NIST AI RMF.
  • Lifecycle control, so agents that outlive their purpose are retired on purpose rather than left running.

The distinction that matters is between knowing which AI risks exist and proving how they are controlled. Portfolio tools and workflow platforms tell you the first. Demonstrating the second requires evidence generated at the model level: bias metrics, drift alerts, explainability reports, and logs tied to specific predictions.

Where Deeploy fits

Deeploy brings every model and use case, from agents to classical ML to embedded and third-party AI, into one platform with visibility, risk control, monitoring, and automatic audit trails.

For governance and compliance teams, Deeploy lets you select a control framework (global, EU AI Act, ISO 42001, or custom), assess each use case’s risk level, configure approval workflows, and run periodic reviews from a single governance dashboard.

For AI and data science teams, it provides real-time monitoring of drift, bias, robustness, and performance, built-in explainers such as SHAP and saliency alongside bring-your-own explainers, guardrails, tracing, and human-in-the-loop feedback capture. Every decision leaves a reproducible, regulator-ready log.

The sprawl data says most organisations cannot currently list the agents they run or prove those agents are controlled. Deeploy’s MCP server gets every AI agent in an organisation to register itself, ship its traces, and live under the same controls as the rest of your AI estate.

Frequently asked questions

Disclaimer

This is general information, not legal advice. Please consult your legal/compliance team to confirm your organisation’s specific obligations. Deeploy supports your governance process; it does not constitute a guarantee of regulatory compliance.

Reading about compliance is step one. Operating it is Deeploy.See how teams use Deeploy to monitor, document and govern their AI against the EU AI Act.
Book a Demo

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one