How enterprises can control AI agent sprawl

How enterprises can control AI agent sprawl

Insights

  • Democratized AI agent creation increases duplication, lifecycle costs, access risks, and governance workloads.
  • Automated integrity checks help enterprises control AI agent sprawl while reserving human judgment for complex and high-risk cases.
  • Executive ownership, a responsible AI office, a central agent registry, and lifecycle controls provide the foundation for agent governance at scale.

Enterprises are adopting AI faster than their governance models can adapt. Infosys Knowledge Institute’s AI and the Future of Work report found that only around a fifth of middle managers and junior staff say their employer always provides well-defined safeguards for AI use (Figure 1). Even among senior leaders, the figure reaches only 30%.

This governance gap will become harder to manage as AI agent creation spreads across business functions. Gartner predicts that the average Fortune 500 enterprise will use more than 150,000 AI agents by 2028, up from fewer than 15 in 2025. Yet only 13% of organizations believe they have suitable AI agent governance. The uncontrolled growth of agents without centralized visibility, ownership, or life cycle controls creates AI agent sprawl.

Agent sprawl makes agents harder to discover and reuse, increases duplication and life cycle costs, and leaves governance teams reviewing more systems than their existing processes can support.

Figure 1. Formal AI safeguards are patchy even where AI use is widespread.

Figure 1. Formal AI safeguards are patchy even where AI use is widespread.

Source: Infosys Knowledge Institute

AI agent sprawl follows democratized creation

For decades, enterprise software followed a relatively controlled path. Business teams defined requirements, IT teams built or bought the solution, and governance teams assessed architecture, security, compliance, and business fit before deployment. AI agents are upending that sequence.

Agent-building platforms put creation within reach of almost anyone. Companies find themselves not with a handful of carefully managed systems but with hundreds or thousands of agents, sprouting faster than anyone can catalog them. Companies have scrambled for infrastructure to host them and rationed tokens to contain budgets. But in letting everyone build, they have opened the floodgates.

As the number of agents climbs into the hundreds or even thousands, five cracks have started to appear.

  • Discoverability: As the library of agents swells, employees struggle to find out whether a relevant agent already exists. A useful agent could be overlooked simply because no one can identify its capabilities.
  • Duplication: Even when a similar agent can be found, teams tend to trust their own creations, insisting that their use case is different from what the existing agent can handle. Over time, organizations accumulate overlapping and adjacent agents that perform similar tasks.
  • Utilization: Each agent requires infrastructure, monitoring, security review, maintenance, and periodic reassessment. A growing estate of low-use or near-duplicate agents can increase token consumption, maintenance costs, and governance effort without delivering proportional business value.
  • Efficacy: As the library of agents swells, companies need a standardized way to determine whether agents are delivering value, being reused, or performing as intended. Without that view, leaders will struggle to separate productive agents from redundant or poorly designed ones.
  • Governance: Traditional AI governance models are difficult to apply when hundreds of agents require assessment. The US National Institute of Standards and Technology AI Risk Management Framework, for example, defines governance as a cross-cutting function that should be infused through AI design, development, deployment, evaluation, and monitoring.

Evidence of this visibility gap is emerging. Industry research found that only 18% of organizations maintain a complete and current inventory of their AI agents. Without an accurate inventory, enterprises cannot consistently identify ownership, detect duplication, review access permissions, or retire agents that no longer serve a business purpose.

Bigger teams are not the answer

These mechanisms are useful for a limited number of large, strategic AI initiatives where expert review can go deep into architecture, data sources, model behavior, responsible AI (RAI) controls, integration points, and implementation plans. But the same model becomes difficult to scale when hundreds of smaller agents require assessment. Human review does not scale at the same speed as agent creation.

The instinctive response to a governance overload is to hire more people to do the governing. The evidence suggests this scales badly. Infosys Knowledge Institute’s Responsible Enterprise AI in the Agentic Era report found that 86% of executives familiar with agentic AI expect it to introduce new risks and compliance challenges. The same research found that only 2% of companies met the full standards of Infosys’ RAI capability benchmark, while 83% delivered RAI in a piecemeal manner.

Bigger teams certainly do more. The same research shows that companies with RAI teams of more than 25 people had worked on over 100 enterprise AI initiatives in the previous two years, about 24% more than organizations with teams of five to 25, and about 50% more than those with five or fewer. But volume is not the same as maturity. As teams grew, the share of successful deployments declined from 24% to 21%. Larger teams fared worse on damage. Those above 25 members suffered, on average, 16% higher financial losses from misbehaving AI than smaller ones (Figure 2).

Figure 2. Bigger RAI teams run more projects, but succeed less often

Figure 2. Bigger RAI teams run more projects, but succeed less often

Source: Infosys Knowledge Institute

Governance maturity is not created by oversight volume alone. Enterprises need repeatable mechanisms, clear ownership, stronger data foundations, and embedded controls that work inside the AI development life cycle.

Governance today is a human-in-the-loop affair, where experts assess projects one by one. That can work for a few large deployments. But when agents arrive in their hundreds or even thousands, the model starts to buckle. Who sits on the council? How many experts are needed? At what cost? Would enterprises convene marathon sessions to review every new agent? Applying a playbook built for a handful of major AI programs to a swarm of smaller agents is neither practical nor affordable.

The case for an agent integrity framework

An AI agent integrity framework provides an automated governance layer that ingests an agent’s code, configuration, and declared purpose, then validates those against enterprise policies and governance principles. The aim is to let machines do the repeatable pre-work so human experts can make faster, more consistent, and better-informed decisions.

The framework should assess three things before an agent moves into production.

  • Need: Determine whether the proposed agent is genuinely unique or whether a similar or adjacent agent already exists. This helps reduce duplication and steer teams toward reuse.
  • Safety: Validate whether the agent follows enterprise guardrails, RAI principles, and approved data and tool access boundaries. This includes whether the agent can reach confidential data, systems, or tools it is not authorized to use.
  • Fitness: Test whether the agent’s actual behavior matches its declared intent, whether its autonomy level is appropriate, and whether its code needs optimization before release.

An agent demonstrates integrity when it behaves as intended, operates within approved boundaries, and remains consistent with enterprise policy.

For this to work, every agent needs a structured declaration of what it is meant to do. That declaration should include the agent’s goal, autonomy level, tools and models it can call, systems of record it can access, permissions to create, read, update, or delete data, external integrations, internet access, and links to its code base. The automated scan can then check the agent’s code and configuration against that declaration and produce an integrity report.

The payoff

For developers, automated integrity checks make responsible design the path of least resistance. Declaring intent, autonomy, data access, and integrations up front means that the scan can compare what the agent claims to do with how the agent behaves.

Scrutiny that once meant joining a queue for an expert council now happens in near-real time. The integrated report creates an audit trail of the checks performed, issues identified, and remediation required. When the system flags duplication, developers are steered toward reuse rather than building another version of an existing agent.

For RAI teams and enterprise leaders, the scans turn oversight from a manual, sampling exercise into continuous, comprehensive control. A centralized dashboard shows which agents exist, who owns them, what each is permitted to do, and whether its live behavior still matches declared intent. The view serves two goals. On the risk side, it helps catch agents that overreach on data or autonomy before they can do harm. On the efficiency side, it exposes the redundant, poorly designed or low-adoption agents that inflate token bills and maintenance costs.

Human experts retain control of the final decision. Automation clears the backlog of routine checks so that scarce expert judgment is spent on the genuinely novel, borderline and high-risk cases.

The payoff

An operating model for agent governance

The integrity framework requires an operating model that establishes accountability, policy ownership, agent visibility, and governed data.

  • Executive ownership: Assign explicit ownership of AI agent governance to the chief information officer or chief technology officer, with a mandate to sponsor the framework, set the risk thresholds that trigger human review, and hold business units accountable for compliance before agents reach production.
  • RAI office or center of excellence: Establish a cross-functional function to define guardrails, update policies, oversee audits, adjudicate exceptions, and coordinate across technology, legal, risk, cybersecurity, compliance, and business teams. Infosys Knowledge Institute’s report recommends a dedicated RAI office and guardrails embedded into AI platforms.
  • Central registry of AI agents: Build a centralized, searchable agent registry that logs every agent’s integrity report, owner, and status, with the automated assessment wired directly into the development pipeline. Integrate the assessment into the development pipeline so that every agent is checked before release and its results feed the registry automatically.
  • Data, identity, and life cycle controls: Give every agent a distinct identity, scoped permissions, approved data access, and a named owner. Establish data quality, lineage and access control, continuous monitoring, and criteria for reviewing or retiring dormant, redundant, or noncompliant agents.

Elements of this model are already being implemented. A consumer healthcare company replaced spreadsheet-based RAI reviews with a centralized inventory and automated, cross-functional approval workflows, reducing approval times from two to three weeks to one week. Microsoft Digital reports using a centralized control plane to track ownership, usage, metadata, and life cycle information across more than 500,000 internal agents. The first case demonstrates measurable process improvement across AI governance, while Microsoft’s implementation shows how registry-based controls can support agent creation at enterprise scale.

Guardrails that keep pace

Building an automated agentic governance framework is an effective way for enterprises to control AI agent sprawl without overwhelming governance teams. It rewards reuse and collaboration, and helps contain the cost of tokens, maintenance, and infrastructure. Most valuably, it speeds the work of expert human councils while keeping the enterprise faithful to its own governance philosophy. As the machines multiply, every enterprise will need such a framework to master the complexity of building agentic systems and to ensure that the guardrails keep pace.

Connect with the Infosys Knowledge Institute

All the fields marked with * are required

Opt in for insights from Infosys Knowledge Institute Privacy Statement

Please fill all required fields