verifiedagents.ai
All posts

4 min readAI Agents · Cybersecurity

What Is AI Agent Sprawl, and How Do You Get Control Back?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: What Is AI Agent Sprawl, and How Do You Get Control Back?

TL;DR: AI agent sprawl is running more AI agents than you can count, own, review, or shut off. The Wall Street Journal reported it at Lyft, GitLab, DaVita, and FICO in 2026, with DaVita employees building more than 10,000 agents. Gartner projects 150,000 per average Fortune 500 inside two years, while 13 percent of organizations believe their controls are adequate.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai around the part nobody budgets for: what happens to an agent when its builder leaves.

What is AI agent sprawl?

Sprawl is what sets in when agents pile up across a company with no single list of what exists and who's responsible. Not a hacking story. A counting story, and most companies can't produce the count.

Think of it like office keys. Hand out keys for years without writing down who holds which one, and you don't have a lock problem. You have a records problem. Sprawl is the same failure at software speed.

The scale is already public. DaVita told the Journal its employees had built more than 10,000 agents. Gartner expects the average Fortune 500 company to run more than 150,000 within two years. Thirteen percent of organizations think their controls are ready for that.

Why does sprawl happen to well-run companies?

Because good employees solve real problems, and building an agent got easy. Beth in Marketing needed help organizing leads, so she built an agent. Sam in Customer Service needed after-hours coverage, so he built one too. Both calls were right. Both agents work. Neither is on any master list, because there isn't one.

Multiply Beth and Sam across every department and every month. The problem was never a bad decision. It's a hundred reasonable decisions with nobody keeping score.

What happens when an agent's builder leaves?

The agent keeps working, and it keeps its access. Nobody reviews it. Ask who can shut it off and you get a shrug and "Beth's been gone since April."

That orphaned agent has the same reach it had on day one. Depending on what it was built to do, it can still pull customer records or move money. A digital worker with real access and no manager isn't help. It's a liability idling on your systems.

One CIO lived the sharp version. One of his agents created 12 automated login accounts over a single weekend. The agent was built to do exactly that. He spent a morning explaining to his audit committee why nobody knew it could. The technology worked as designed. The oversight didn't exist.

Lifecycle stage

Employee

Sprawled agent

Hired or built

Onboarding, manager assigned

Built in an afternoon, no record

Working

Reviews, access by role

Full original access, no reviews

Owner leaves

Accounts closed on exit

Keeps running, keeps access

Something goes wrong

A manager answers for it

A shrug answers for it

How do you get control back?

The way you'd regain control of any workforce you lost track of: count it, then manage it like headcount.

  1. Build the list this week.

    Every agent and automated account that can reach a real system, with its owner and its access. The mechanics are in

    how to count the AI agents in your company

    .

  2. Assign an owner to every orphan.

    One named person per agent, the way every employee has a manager.

  3. Shut down what has no job.

    An agent with no owner and no current purpose gets retired, not left idling with its access intact.

  4. Add agent offboarding to employee offboarding.

    When a person leaves, their agents get a new owner or a shutdown, the same day their badge dies.

If your team can't build the list in a day, that isn't failure. That's your first finding, and the most useful thing you'll learn this quarter.

Frequently asked questions

How is sprawl different from shadow AI?

Shadow AI usually means outside tools used without IT's knowledge, like pasting company data into a public chatbot. Sprawl is often worse: agents the company built on purpose, with real access, that outgrew anyone's ability to track them.

Is this a security problem or a management problem?

It starts as management. The agents usually work exactly as designed. Fix ownership and visibility, and most of the security risk becomes manageable.

How many agents does a typical company have?

More than leadership thinks, and usually more than IT can count. The honest answer at most firms is "we don't have a firm number," which is itself the finding.

Who should own each agent?

One named human, accountable for what the agent can reach and whether it still has a job, including shutting it down when it doesn't. The agents without owners are the ones that turn into audit mornings.

Key takeaways

  • Sprawl is a counting failure, not an attack.

  • Every sprawled agent was a reasonable decision. The missing piece was the roster.

  • Orphaned agents keep their access after their builders leave.

  • Count first, assign owners second, retire the jobless third, then wire agents into offboarding.

  • Not producing the list in a day is the finding.

Take the roster test

The free ATF assessment takes about ten minutes and shows how much of your agent workforce is actually governed.

You haven't been hacked. You're running digital workers with real access and nobody keeping the roster.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.