A CIO in Sydney asks a simple question in a board pre-read: how many AI agents are running in the business, and who owns each one? The answer takes six weeks to assemble from procurement, three SaaS admin consoles and a spreadsheet a developer kept. It turns up agents nobody remembers approving, two doing the same job, and one holding an API key that has not changed in over a year. The problem is no longer whether agents work. As one ANZ vendor executive put it in September, the question has moved to how to deploy them inside the business safely.
What is AI agent sprawl and why is it a security problem?
Agent sprawl is the uncontrolled growth of AI agents across cloud, SaaS and on-premise systems without a central inventory, accountable owner or guardrails. It is a security problem because every agent authenticates with credentials, and each credential is an identity that can be over-permissioned, forgotten or stolen.
The Cloud Security Alliance's non-human identity governance whitepaper, published May 2026, cites an average of 45 non-human identities per human user, reaching 144 to 1 in cloud-native environments. It reports that only 15% of organizations were highly confident they could prevent non-human-identity attacks, 51% lacked clear ownership of AI identities, and 47% of non-human identities had gone unchanged for over a year. These are survey and audit figures from CSA's research, and your own ratio will differ, but the direction is consistent.
Why do legacy identity tools miss agents?
Traditional IAM assumes a human with a joiner, mover, leaver lifecycle. Agents have none: they are created by a developer in an afternoon, inherit a service account, and never 'leave'. Nobody's offboarding checklist retires them.
There is also a scale shift. Paul Arthur of OutSystems ANZ argues that enterprises will soon manage hundreds or thousands of agents, so the priority becomes governance, integration, security and cost management as a system, not one-off builds. That is an opinion from a platform vendor, but it matches what we see in delivery.
What should an agent registry record?
CSA's framework prescribes a centralized registry. In practice, each agent needs one record with these fields:
- **Identity and owner.** A unique ID and a named accountable human or team, not a shared mailbox.
- **Business purpose.** One sentence on the workflow it serves, so duplicates and orphans are obvious.
- **Systems accessed and privilege scope.** Exactly which APIs, data stores and tools, with read versus write called out.
- **Model and provider.** Which model version it calls, so a deprecation becomes a query, not an investigation.
- **Review date and revocation path.** When it was last reviewed and how to kill its credentials in minutes.
Which controls actually reduce the risk?
- **Zero standing privilege.** Issue just-in-time access scoped to a task, with automatic expiry, instead of permanent keys. This builds on least-privilege tool permissions.
- **Automated credential rotation.** CSA targets time-to-revoke in minutes rather than hours; a rotation you cannot automate is one you will skip.
- **Short-lived workload identity.** CSA recommends cryptographic, attestation-based credentials such as SPIFFE/SPIRE over long-lived shared secrets.
- **Third-party and vendor agents in scope.** SaaS-embedded agents count. This is where shadow AI usually hides.
- **A retirement rule.** No review in 90 days means credentials suspended. Sprawl is a lifecycle failure, so end-of-life needs an owner too.
How does this connect to regulation?
An inventory is the precondition for nearly every compliance question about agents. You cannot answer an automated-decision disclosure request under the Australian Privacy Act changes or an EU AI Act risk classification without knowing which agents make which decisions on whose data. Governance maturity is also what separates pilots that scale from those that stall, as covered in the AI adoption value gap.
How AIBOOTSTRAPPER helps
We build agents with the registry in mind from the first sprint: named owner, scoped credentials, logged tool calls and a human approval point where judgment is needed. Our Leon & Vera build for European local studios, two connected agents that generate ad creative and book enquiries into the studio's existing calendar, illustrates the principle of keeping each agent narrow, with the owner setting the ad-spend ceiling rather than the agent. We have no published client case study specifically on agent-inventory programmes, so we won't claim one; what we bring is the build discipline that makes an inventory possible.
If you want a second pair of eyes on how many agents you actually have and what they can touch, book a call or see our AI consultancy and product services.
Want this done for you?
Book a free strategy call and we'll show you how to build and market your business with AI.
