There's a quiet crisis unfolding inside enterprise IT departments right now. AI agents are multiplying across organisations at a rate that would have seemed impossible just two years ago. Executives are announcing adoption milestones. Dashboards are flashing green. And yet, beneath that surface confidence, a deeply unsettling reality is taking shape: most organisations have no idea who is actually responsible for the AI agents they've deployed.

The gap between perceived control and actual accountability is one of the defining challenges of the agentic AI era — and if your organisation hasn't confronted it yet, it almost certainly will.


The Illusion of Control

IT leaders are remarkably confident about their AI deployments — until you start asking the hard questions.

Surveys consistently show that organisations believe they are managing their AI agents effectively. The budgets are growing, the deployment numbers are climbing, and the productivity wins are real.

79% of companies say AI agents are already being adopted, and of those adopting, two-thirds say they're delivering measurable value through increased productivity.

But confidence in results is not the same as confidence in control. When researchers began probing the specifics of governance — who owns each agent, who can audit its behaviour, who is accountable when something goes wrong — the picture changed dramatically.

Nearly 80% of organisations deploying autonomous AI cannot tell you, in real time, what those systems are doing or who's responsible for them.

That is not a minor gap in documentation. That is a fundamental breakdown in enterprise governance.


Who Actually Owns Your AI Agents?

The ownership question is where the confidence gap becomes most visible. Responsibility for AI agents isn't clearly absent — it's fragmented to the point of meaninglessness.

Ownership is split across Security teams (39%), IT departments (32%), and emerging AI security functions (13%), with no clear accountability.

When everyone owns something, no one owns it. And without a designated, accountable owner, agents can operate in production environments for months without review, audit, or oversight.

Only 23% of organisations have a formal, enterprise-wide strategy for agent identity management, while another 37% rely on informal practices — essentially making it up as they go.

The traceability problem compounds this further.

Only 28% of organisations can reliably trace agent actions back to a human sponsor across all environments, and just 21% maintain a real-time inventory of active agents.

If you can't see your agents and can't connect their actions to a responsible human, you don't have control — you have the appearance of it.


The Agent Sprawl Problem Is Accelerating Fast

What makes the ownership gap so urgent isn't just the current state — it's the trajectory. AI agent deployments are scaling at a speed that governance teams are simply not equipped to match.

Gartner predicts that by 2028, an average global Fortune 500 enterprise will have over 150,000 agents in use, up from fewer than 15 in 2025

— an almost incomprehensible rate of growth that will make today's governance challenges look trivial by comparison.

Even today, the numbers are already alarming.

According to Salesforce's 2026 Connectivity Benchmark of 1,050 IT leaders, enterprises average 12 AI agents deployed — with 50% of those agents operating in isolated silos with no coordination, no shared context, and no unified governance.

This is the essence of AI agent sprawl: the uncontrolled, decentralised deployment of AI tools across an enterprise without centralised oversight, security standards, or governance frameworks — and it is already one of the most significant enterprise AI risks of 2026.

Only 13% of organisations believe they currently have the right AI agent governance in place

— which means the remaining 87% are operating with known gaps and hoping nothing goes wrong.


Why This Is a Compliance and Security Time Bomb

The ownership gap isn't just an operational inconvenience. It creates direct exposure across compliance, security, and regulatory risk.

When asked about audit readiness, results are sobering: less than half of organisations feel "somewhat confident" they could pass a compliance review focused on agent behaviour, and the majority simply cannot demonstrate proper control over their autonomous systems as mandated by corporate governance and regulatory measures.

The security risks are equally serious.

When agents share credentials or use hardcoded logic, accountability breaks down entirely. If an agent creates and tasks another agent — a capability held by 25.5% of deployed agents — the chain of command becomes impossible to audit.

Meanwhile, shadow AI is adding fuel to the fire.

98% of organisations report unsanctioned AI use, and 49% expect shadow AI incidents within 12 months.

Unsanctioned agents created by individual teams — without IT knowledge, without governance review, and without a designated owner — are arguably the fastest-growing category of enterprise risk right now.

AI agent sprawl refers specifically to the uncontrolled growth of AI agents without enough visibility, ownership, governance, or lifecycle management, and it creates risks around data leakage, oversharing, excessive permissions, compliance exposure, and unmanaged automation.


The Governance Gap Is Not Inevitable

The good news? This is a solvable problem. The organisations pulling ahead aren't necessarily the ones with the most sophisticated AI — they're the ones that treated governance as a prerequisite, not an afterthought.

Companies that implemented AI governance pushed 12x more projects to production

— a striking data point that reframes governance not as a brake on innovation, but as an accelerant.

According to a Deloitte survey of 3,235 IT and business leaders from 24 countries, only 21% of respondents say their organisations have a mature governance model in place for agentic AI.

That low baseline means there is significant competitive advantage available to any organisation willing to act now.

Alignment around ownership is key. Organisations are moving from shared committees to clear lines of accountability, embedding governance directly into how AI systems are designed and deployed.


Practical Tips: How to Close the AI Agent Ownership Gap Today

If your organisation is among the majority without clear AI agent ownership, here is where to start:

Maintain an agent registry

that captures every deployed agent, its purpose, its permissions, and who is responsible for it. You cannot govern what you cannot see.

Deploying agents without designated owners creates accountability gaps

that compound over time. Every agent should have an individual or team responsible for its monitoring, performance, and compliance.

In many enterprise environments, AI agents are significantly over-permissioned — granted far more access than their tasks require.

Start restrictive and expand access based on demonstrated need.

Build controls and review cycles directly into agentic systems and integrate oversight early so you can stay ahead of innovation.

The next wave of AI maturity will come from teams that treat feedback and oversight as part of the production process, not a safety net.

Schedule monthly reviews, quarterly policy updates, and annual audits.

Best practice is to assign ownership for agent governance to the same leaders responsible for cloud governance, security, and compliance, aligned with existing governance structures.

Avoid creating parallel frameworks that nobody follows.

Shadow AI is the unauthorised use of AI tools by employees and a symptom of broader sprawl. Treating it in isolation leaves the underlying conditions that produce it untouched.


Conclusion: Confidence Is Not the Same as Control

The gap between IT teams who feel in control of their AI agents and those who actually are is one of the most consequential divides in enterprise technology today. Confidence without accountability is not governance — it is risk dressed up as progress.

Only about one-third of organisations report maturity levels of three or higher in strategy, governance, and agentic AI governance, suggesting that while technical and risk management capabilities are advancing, organisational alignment and oversight structures are struggling to keep pace with the rapid expansion of AI use.

The organisations that will win in the agentic era are the ones that answer the hard questions now — not after a compliance breach, a data leak, or an audit failure forces the issue. Who owns your AI agents? Who can trace their actions? Who is accountable when something goes wrong?

If you can't answer those questions with certainty, it's time to act. Start with an agent inventory, assign clear ownership, and build governance into your AI deployment pipeline from day one. The window to get ahead of this problem is still open — but it is closing fast. Download our AI Agent Governance Checklist or book a consultation with our team today to build the accountability framework your AI strategy depends on.