A 400-person Hong Kong insurance brokerage is preparing for a regulator meeting, and the COO asks the IT director a simple question: how many AI agents are running in the company right now?
Marketing built three agents in a low-code studio. Operations runs a claims triage bot supplied by a vendor. Finance has an agent reconciling invoices overnight. Someone in sales connected an assistant to the CRM over a weekend. Nobody can produce the full list, let alone say who owns each agent or what data it can touch.
That is agent sprawl. This guide defines it, explains why it became a board-level issue in 2026, and gives you a practical framework for building an agent inventory that will survive an audit.
What is AI agent sprawl?
AI agent sprawl is the uncontrolled growth of AI agents across an organisation without central tracking, ownership or governance. Agents are built on many platforms by many teams, so nobody holds a complete record of what exists, what each agent can access, what it costs, or whether it still delivers value.
Identity provider Okta describes agent sprawl as the uncontrolled proliferation of AI agents without centralised tracking, inventory or governance. The key word is agent, not chatbot. A chatbot answers questions. An agent reads files, calls tools, writes to systems and can act without a human pressing a button for each step.
Sprawl is the predictable result of success. Low-code builders inside Microsoft, Google, Salesforce and AWS make it easy for a department to ship an agent in an afternoon. Each platform tracks its own agents well. None of them tracks the others.
Sprawl is related to, but different from, the question of how each agent proves who it is. We covered that layer in our explainer on AI agent identity. Sprawl is the portfolio problem that sits above it.
Why has agent sprawl become a board-level issue in 2026?
Agent sprawl reached the boardroom because adoption has outrun oversight. Surveys in 2026 show almost every organisation uses AI agents, yet only about one in five keeps a real-time record of them. When an agent misbehaves, leaders cannot say quickly which systems it touched or who approved it.
The numbers are consistent across sources:
--- An OutSystems survey from January 2026, cited by Bigeye, found 96% of organisations already use AI agents, but only 21% maintain a real-time registry and only 12% have a central platform to manage sprawl.
--- According to IBM's AI in Motion research, cited by Technology Magazine, fewer than one in five organisations keep a complete, current inventory of their AI systems.
--- In Dataiku's Global AI Confessions Report, 87% of UK technology leaders agreed employees create agents faster than central teams can govern them, and 53% said an agent had violated policy in a way that affected customers.
Dataiku's chief executive Florian Douetteau put it bluntly when the company launched its Agent Management product on 24 September 2026: ask a bank how many servers it runs and you get an exact answer, ask how many AI agents it runs and you get a guess.
For a board, that guess is the problem. Directors are accountable for risk they cannot see.
How does agent sprawl create compliance risk in Hong Kong?
In Hong Kong, sprawl turns into Personal Data (Privacy) Ordinance exposure. The Privacy Commissioner's 2026 compliance checks found 95% of reviewed organisations use AI and half run three or more AI systems, while AI policies and board discussions declined. Untracked agents with broad access make that governance gap harder to defend.
The PCPD's 2026 compliance checks, summarised by Mayer Brown, reviewed 60 organisations across sectors including banking, insurance, logistics and property management. Three findings matter for agent governance:
--- 57 of 60 organisations (95%) used AI day to day, and about 51% used three or more AI systems.
--- The share with formal AI policies fell from about 63% in 2025 to 50% in 2026.
--- Board-level discussion of AI dropped by around 25 percentage points year on year.
The PCPD also singled out agentic AI as a higher-risk category, because agents often run with elevated access to files, email, credentials and browsers. Its advice: grant minimum access rights, segregate the runtime environment, vet plugins and skills before use, and keep a human in the loop for final decisions.
None of that advice can be applied to an agent you do not know exists. An inventory is the precondition for every control the regulator recommends.
What is the difference between an agent inventory, a registry and a catalogue?
An agent inventory lists every AI system you run and its risk level. A registry governs each agent's identity, permissions, lifecycle and audit trail. A catalogue helps teams discover and reuse approved agents. They are sequential layers: you cannot govern what you have not inventoried, or share what you have not governed.
Vendors use these terms loosely, which confuses buying decisions. Bigeye offers a useful separation:
Agent inventory: knowing what you have
A structured list of AI systems with owner, purpose and risk classification. It satisfies requirements such as NIST AI RMF GV.1.6, which asks organisations to maintain an inventory of AI systems resourced according to risk.
Agent registry: governing what each agent may do
Each agent gets a managed identity, scoped permissions, a lifecycle state (draft, active, retired) and an event log. Think of it as the configuration management database for agents.
Agent catalogue: helping teams find what exists
A searchable front end so teams reuse approved agents instead of building duplicates. Duplicates are often how shadow agents start.
According to Bigeye, Gartner's April 2026 framework for managing agent sprawl places building a centralised inventory at step two, before identity governance and lifecycle controls.
How do you build an agent inventory? A five-field framework
Start with five fields for every agent: owner, purpose, data, rights and value. Collect them from platform admin consoles, procurement records and a short staff declaration, then assign each agent a risk tier. A first inventory for a mid-sized enterprise is usually a four-to-six-week exercise, not a software project.
Our recommended record is deliberately short, because a long form never gets completed. We call it OPDRV:
--- Owner: one named business owner, not a team or a vendor.
--- Purpose: the business task in one sentence and the process it belongs to.
--- Data: which systems and data classes it reads, especially personal data.
--- Rights: what it can change or send, such as emails, payments, records or files.
--- Value: the metric that proves it is worth running, with a review date.
Where to find agents
Pull lists from the admin consoles of every AI platform you license, check expense claims and procurement records for AI subscriptions, review API keys issued to AI services, and ask each department head to declare what their teams built. Expect surprises: a CSA survey cited by Bigeye found 82% of enterprises discovered previously unknown agents in the past year.
How to tier risk
--- Tier 1 (high): touches customers, personal data or money, or acts without human approval.
--- Tier 2 (medium): reads internal data and drafts outputs that a human reviews.
--- Tier 3 (low): personal productivity with no system write access.
Tier 1 agents need certification before launch, scheduled testing and a named escalation path. Tier 3 agents need little more than a line in the inventory.
What does agent governance look like in a Hong Kong enterprise?
In practice, agent governance looks different by industry. A financial firm focuses on personal data and model risk, a logistics group on agents that change shipment or billing records, and a property manager on tenant data and vendor tools. The common thread is a named owner and a risk tier for every agent.
A regional bank finds 34 agents across four platforms, of which six touch customer data. It certifies those six first, aligns their records with existing model-risk documentation, and retires nine duplicates found during the review.
A logistics group discovers an agent that updates delivery status directly in its transport management system. The agent works well, but nobody approved its write access. The fix is not to switch it off. It is to give it an owner, narrow its rights and log every change. Where agents query data in place, the access model matters even more, as we explained in our guide to zero-copy AI.
A property management company learns that a vendor's tenant-enquiry agent stores conversation logs overseas. The inventory exercise surfaces the issue before a tenant complaint does, and the vendor contract is amended to cover retention and location.
What mistakes do organisations make when tackling agent sprawl?
The most common mistakes are banning agents outright, which pushes them underground, treating the inventory as a one-off spreadsheet, relying on each vendor's own console for visibility, and never retiring agents. Each leaves the organisation with a list that looks complete on paper but fails the first serious audit question.
--- Banning instead of channelling. Prohibition drives builders to personal accounts, which is worse than sprawl.
--- A spreadsheet updated once. Agents change weekly. Tie inventory updates to platform admin reviews and procurement, on a fixed monthly cycle.
--- Trusting single-vendor visibility. As Dataiku's Kurt Muehmel noted, most platforms only see agents built inside their own ecosystem. Your inventory must sit above all of them.
--- No retirement process. Agents whose owner has left the company keep running with live credentials. Every record needs a review date.
--- Ignoring value. An inventory that tracks risk but not outcomes cannot answer the CFO's question: which of these agents are worth paying for?
How should you report agent sprawl to the board?
Report agent governance to the board with four or five measures that trend over time: total agents and their tiers, the percentage with a named owner, the percentage of high-risk agents certified, time to contain a misbehaving agent, and agents retired. Trends show control improving; a single snapshot does not.
A one-page quarterly dashboard is enough for most boards:
--- Total agents by tier, and the change since last quarter.
--- Percentage of agents with a named owner and a review date (target: 100%).
--- Percentage of Tier 1 agents certified and tested on schedule.
--- Time to contain an incident. Dataiku's research found over two-thirds of UK businesses take more than 24 hours to contain a problematic agent; set a target in hours.
--- Agents retired and the value delivered by the top five.
Pair the dashboard with a short narrative on any Tier 1 incident. That is the evidence regulators and auditors increasingly expect, and it restores the board-level AI discussion the PCPD found declining.
Conclusion: you cannot govern what you cannot count
Agent sprawl is not a sign that AI adoption has failed. It is a sign that it has succeeded faster than governance could follow. The organisations that pull ahead will not be the ones with the most agents. They will be the ones that can say, at any moment, what each agent does, who owns it, what it can touch and what it is worth.
Start with the five-field inventory, tier the risk, and report the trend. That is a four-to-six-week project that turns a board-level blind spot into a governance asset.
We understand AI. We understand you. With UD by your side, AI never feels cold.
Reviewed by the UD enterprise AI team. Figures were checked on 8 October 2026 against the vendor, analyst and legal sources linked above. Survey findings are reported as published by those sources.
Bring Your AI Agents Under Control
Now that you have the framework, the next step is mapping the agents already running in your organisation and deciding which to certify, consolidate or retire. We'll walk you through every step, from agent discovery and risk tiering to governed AI staff deployment and performance tracking, backed by 28 years of enterprise service in Hong Kong.