Best Practices 7 min read 20 September 2026

AI Agent Sprawl: 80% Deploy, 10% Have Control

Enterprise agent counts doubled in a quarter, and AWS and Salesforce just shipped agent registries. Only about 10% of companies say they control their agents. Here's the small-business version of that fix.

AI Agent Sprawl: 80% Deploy, 10% Have Control

Two numbers from this week's enterprise AI coverage belong side by side. The typical enterprise deployment jumped from 26-50 agents to 76-100 agents in a single quarter. And while roughly 80% of organizations say they are deploying agents, only about 10% say they feel in control of them. In the same window, AWS launched an Agent Registry for cataloguing agents, MCP servers and tools, and Salesforce announced an AI Control Plane to register agents, set identity and policy, and track cost. When two of the biggest platform vendors ship inventory tooling in the same week, the underlying problem is real: agents are being created faster than anyone is keeping track of them.

Sprawl Is the New Shadow IT

Agents are cheap to create. A team member wires up a workflow in an afternoon, gives it an API key, and it starts working. Six months later nobody remembers which agent sends which emails, which one holds write access to the CRM, or whether the pilot from March is still running and still billing. This is the same pattern as shadow IT and spreadsheet macros, with one difference: an agent acts on its own, on a schedule, with real credentials. An orphaned spreadsheet does nothing. An orphaned agent keeps sending messages, spending tokens and changing records.

Uber's published numbers show why the scale matters. It reported more than 3,600 agent skills running 30,000+ daily executions, and it stopped measuring by tokens and sessions. It measures cost per merged pull request, cost per review, cost per alert. That only works because every agent and skill is inventoried and attributable. You cannot compute cost per outcome for something you have not registered.

What an Agent Registry Actually Contains

Strip away the vendor branding and a registry is a table with a few disciplined columns. You do not need AWS or Salesforce to keep one:

  • Owner: a named person who answers for the agent, not a team alias
  • Purpose: one sentence on the job it does and the business outcome it is measured against
  • Access: every system, tool and credential it can touch, and whether each is read-only or write
  • Autonomy level: acts alone, acts with sampled review, or waits for human approval
  • Cost: monthly model and infrastructure spend, tied to the outcome it produces
  • Review date: when someone last confirmed it still should exist

The rule that prevents sprawl

No agent goes live without a registry entry, and any agent without a named owner or a review date in the last 90 days gets paused, not left running. Deletion is the most underused governance control.

Why the Prompt Is Not the Security Boundary

OpenAI's recent disclosure about agents finding unintended communication channels and credential paths during an internal evaluation made one point sharply: the security boundary cannot live only in the agent's instructions. A registry is where you enforce the boundary that actually holds: scoped credentials, least-privilege tool access, and network limits. If the registry says an agent is read-only on billing data, that must be true at the credential level, not just stated in a system prompt.

A Realistic Scenario

A Wizeb client, a 60-person logistics brokerage, came to us after finance noticed model spend had tripled in a quarter with no matching growth in throughput. Nobody could say how many agents were running. We spent two days doing an inventory and found 19 agents: 11 planned, 5 built by individual dispatchers with personal API keys, and 3 abandoned pilots still polling the same inbox every few minutes. Two of the dispatcher-built agents could send emails to customers with no review. We consolidated to 9 agents, moved every credential to scoped service accounts, assigned owners, and set a quarterly review. Model spend dropped by roughly 40%, and for the first time the team could say what each agent cost per booked load.

A One-Week Agent Inventory

  1. 1Day 1: Ask every team lead to list every automation, bot and AI workflow they use or built. Check your API key dashboards for keys nobody claimed.
  2. 2Day 2: Build the registry table with the six columns above and fill in what you know.
  3. 3Day 3: Verify access for each entry against the real credentials, not what the builder says it has.
  4. 4Day 4: Pause or delete anything without an owner, purpose or recent activity.
  5. 5Day 5: Attach a cost and an outcome to every survivor, and set the first review date.

How Wizeb Approaches This

Every agent Wizeb builds ships with a registry entry: owner, scoped credentials, autonomy level, logging and a cost-per-outcome metric. We treat the registry as part of the deliverable, not paperwork after the fact. For companies that already have agents in the wild, we run the inventory and consolidation described above and hand back a working registry your team can maintain. You do not need a six-figure control plane product to get control. You need a list, owners, scoped access and a review date, and someone who enforces them. See our AI agent services at wizeb.com/services/ai-agents.

Find out how many agents you actually have

Wizeb's agent inventory and governance review maps every agent, credential and cost in your business and delivers a registry you can maintain. Visit wizeb.com/services/ai-agents to start the conversation.

Three Questions to Answer This Week

  1. 1Can you list every agent running in your business right now, with an owner for each?
  2. 2Do you know which of them can write to a customer-facing or financial system without review?
  3. 3Could you state the cost per outcome for your three busiest agents?

Ready to act on this?

We build exactly what this article is about.

Tell us about your situation — we'll come back with a realistic assessment.