8 min read

Agent Sprawl Is the New Shadow IT

Every team is quietly running AI agents. Nobody can list them. Why unregistered agents are a bigger problem than unregistered SaaS ever was, and why the register has to come before the governance.

James Oldham

James Oldham

Founder, Sentry AI

15 July 2026

Ask your leadership team a simple question: how many AI agents does the business run right now?

Nobody can answer it. Not IT, because half the agents never touched an IT process. Not finance, because agents hide inside SaaS line items. Not the teams themselves, because each one only knows its own. We have asked this question across dozens of businesses in the last year and have never once received a correct number.

That gap between what runs and what is known has a name from the last time this happened. It is shadow IT, upgraded, and the upgrade matters.

The last time this happened

Through the 2010s, teams tired of waiting for IT and swiped a credit card. Marketing bought its own analytics, sales its own CRM add-ons, everyone their own file sharing. By the time anyone counted, the average enterprise ran hundreds of SaaS tools, most unsanctioned, and a whole security category had to be invented to see them.

Shadow SaaS was a real problem: data in unapproved places, subscriptions nobody tracked, compliance gaps everywhere. But note what a rogue SaaS tool fundamentally was. It sat there. It held data. The worst case was mostly about where information rested.

Why agents are worse

An agent does not sit there. It acts. It sends the email, updates the record, replies to the customer, moves the ticket, triggers the workflow, and increasingly it spends: every action burns tokens on somebody's bill and some actions move actual money.

An unlisted SaaS tool is a compliance gap. An unlisted agent is an unsupervised employee.

Nobody would let a contractor start work without anyone knowing their name, what they are allowed to touch, or who they report to. That is precisely the status of most AI agents in most businesses today. And they arrive faster than staff ever did, through four doors at once:

- **Built.** Engineering ships Claude agents and internal automations. Sometimes documented, rarely registered anywhere a non-engineer can see.

- **Bought.** Sales signs an AI SDR. Support turns on an AI triage bot. Each lives in its own console with its own admin, invisible to the rest of the estate.

- **Embedded.** The stack you already own keeps growing agents: the CRM added one, the security platform shipped a copilot, the HR suite has an assistant now. Nobody chose these. They came with the renewal.

- **Personal.** Individuals wire up their own automations with consumer AI tools, pointed at real company data, on personal accounts.

Four doors, no doorman, and the population grows every quarter whether anyone decides or not.

Why you cannot see them

Traditional IT visibility was built for the network perimeter and the procurement process. Agents dodge both. They live inside sanctioned SaaS, so no new vendor appears. They ride existing per-seat licences, so no new spend line appears. The embedded ones arrive by feature flag. There is no anomaly to detect, because every individual step looked legitimate.

This is why the answer is not detection. It is registration.

The register comes first

You cannot govern what you cannot list. Before approvals, before policies, before any optimisation, the estate needs a register: every agent, what it is, who owns it, what it may touch, and how deeply it can be seen. Including, especially, the ones you bought and the ones that came embedded, because that is where estates go dark.

Once the register exists, the rest follows in order. Monitoring puts every agent's activity on one set of axes, tokens to tool calls, whichever vendor it lives in. Governance holds consequential actions, a payment, an outbound email, a record update, in a human approval queue, with an audit trail and a kill switch on every agent. Optimisation then has the visibility to cut the spend, which is a story we told in [frontier prices for commodity work](/blog/ai-cost-optimisation-model-routing).

We wrote a plain-language definition of this whole category in [what an agent management platform actually is](/blog/what-is-an-agent-management-platform). The short version: it has to be neutral. A register that only lists one vendor's agents is a product dashboard, not a register.

No agent acts alone. Every agent is killable. That is the standard, and it is only reachable if the list is complete.

Where to start counting

The register starts with knowing what your business actually runs, and that is a mapping exercise. Our [AI Opportunity Audit](/ai-opportunity-audit) draws the map in about two minutes, free, in your browser: every tool, every team, every place context and automation already live. It will not enumerate your agents by itself, but it makes the sprawl visible, and the follow-up conversation is where the estate gets counted properly.

The [Sentry Agent Management Platform](/agent-management-platform) then keeps the register live, and it is in free beta with no lock-in.

Every team is quietly running agents. The only question is whether the business finds out on its own schedule or on an incident's.

Build your context layer

Sentry AI helps companies structure their organisational knowledge for AI consumption. We build knowledge graphs, semantic context layers, and AI agent infrastructure for enterprise teams.

More from the blog