curiousecurity

Enterprise architecture and security governance, from the board seat

  • Posts
  • About
  • Career
  • Education
  • Contact
  • LinkedIn
  • GitHub
  • Email
You are here: Home / Architecture / AI Agent Sprawl Is SaaS Sprawl With Better PR

AI Agent Sprawl Is SaaS Sprawl With Better PR

August 11, 2026 by The Architecture Desk

Three million AI agents are now running inside corporate environments, according to Gravitee’s State of AI Agent Security 2026 report, and the mean monitoring coverage across those estates sits at 52%. That’s not a rounding error. That’s an entire shadow estate of autonomous software making decisions, calling APIs, and touching data with almost no one watching. Put that next to Gartner’s forecast that 40% of enterprise applications will ship with task-specific AI agents embedded by the end of this year, up from under 5% in 2025, and the picture gets clearer. We are not debating whether agentic AI arrives in the portfolio. It already has.

We’ve seen this movie before

Every EA board that’s been through a SaaS rationalization cycle knows the pattern. A business unit signs up for a tool without going through architecture review. Six months later there are four overlapping platforms doing the same job, nobody owns the vendor relationship, and security finds out about the integration when it shows up in an incident report. AI agents are following the identical curve, just faster, because the barrier to standing one up is a prompt and an API key instead of a procurement form.

A lot of architecture practices are treating agent governance as a brand new discipline that needs its own framework, its own review board, its own tooling stack. I’d push back on that. We already built the muscle for this. Application portfolio management, vendor rationalization, and ADR discipline exist precisely to answer “what do we run, why do we run it, and who’s accountable for it.” Point that same muscle at agents instead of reinventing governance from a blank page.

The cost of not doing it is already priced

This isn’t theoretical risk. Shadow AI usage was a factor in roughly one in five breaches and added about $670,000 to the average breach cost, according to IBM’s Cost of a Data Breach research covered by Cybersecurity Dive. That’s the premium you pay for not knowing what’s running in your environment. Set that against the cost of doing inventory and review properly, mapping every agent to an owner, a data classification, and an approved use case, and the math isn’t close. Rationalization work is cheap compared to incident response plus the legal and reputational tail that follows a breach traced back to a tool nobody in architecture had ever heard of.

What I’d actually put in front of the board

  • Every AI agent gets an entry in the same EAM system that tracks your application portfolio, not a separate spreadsheet somebody maintains until they change teams. I run ours in LeanIX specifically so agent capability maps sit next to the applications and data flows they touch, not off in a silo.
  • No agent goes into production without an ADR. Not a full architecture review, just a written record of what it’s authorized to do, what data it can reach, and who signed off. Gravitee’s data shows only 14.4% of organizations get agents into production with full security and IT approval; an ADR requirement is the cheapest way to close that gap without slowing delivery to a crawl.
  • Treat agent sprawl as a rationalization problem, not a ban list. Business units will keep spinning these up because the value is real. The board’s job is to consolidate overlapping capability, retire redundant agents, and make sure the ones that survive are actually earning their keep.

None of this requires waiting on a new regulatory framework to tell you what to do. NIST’s AI Risk Management Framework gives you a Govern, Map, Measure, Manage structure if you want a reference model, but the underlying discipline is the same one architecture practices already apply to every other category of technology spend. The organizations that get burned here won’t be the ones that moved slow on agentic AI. They’ll be the ones that let it grow off the books because governing it felt like a new problem instead of an old one wearing a new label.

Photo by Steve A Johnson on Unsplash

Related

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture