5 min readAI Agents · Cybersecurity
How Many AI Agents Are Running in Your Company Right Now?
By Michelle Savage, Experience Design Director, PayPal

TL;DR: Most CISOs can't say how many AI agents run on company data this week. Microsoft's 2026 telemetry puts active agents in 80 percent of the Fortune 500, and one discovery scan surfaced 600 ungoverned agents in 24 hours. You can build a first inventory in a week with three moves: ask leadership, scan network logs, audit finance. No new vendor.
Last updated October 5, 2026. Rebuilt for verifiedagents.ai as the counting exercise, plus the six fields every inventory record needs.
Why can't most companies count their AI agents?
Because the agents never went through IT. Marketing built one to draft outbound emails. Sales built one to qualify leads. Finance built three for forecasting. No tickets, no reviews, no row in any system security can see. The first time most CISOs learn about a shadow agent is when it does something they have to answer for.
The numbers say this is everyone. Microsoft reports 80 percent of Fortune 500 companies running agents in production. Gravitee's State of AI Agent Security 2026 found 75.6 percent of organizations lack visibility into how their agents talk to each other. And a discovery scan at one Fortune 500 in early 2026 turned up 600 agents nobody had approved, with access to AWS, Snowflake, GitHub, and the pipeline that ships production code.
Here's the part I find almost funny: these aren't malicious insiders. They're your most eager people, moving fast. That's what makes counting so awkward. You're not hunting attackers. You're counting enthusiasm.
How do you build a first inventory in one week?
Three moves, run at the same time. None needs procurement.
The 10-minute question.
Ask your IT lead and your engineering lead, then each business unit head, all separately, before they compare notes: "What AI agents or automations run in our environment right now, and what can they reach?" The answers won't match. The distance between them is your real exposure.
The network log scan.
Run the last 90 days of logs against the API endpoints for the major AI providers. Anything calling them from a service account or an unattended machine is an agent in production, approved or not.
The finance audit.
Pull six months of vendor charges. Any AI-platform line item with no matching security review is an agent. The cost center tells you which team runs it.
Together these surface most shadow agents. Not sure what counts as an agent versus a plain automation? Run the one-question test in the difference between an AI agent and a chatbot: if the software decides the next step, it goes on the list.
What goes in each inventory record?
Six fields. Fewer than six and you have a list, not an inventory.
Field | The question it answers when things go wrong |
Agent name and version | Which one was it? |
Named human owner | Who's on the hook? |
What it can read | What did it touch? |
What actions it can take | What could it have changed? |
Kill switch procedure | How fast can we stop it? |
Last review date | Is any of this still true? |
A spreadsheet works. A ticketing system works. The tool doesn't count. What counts is that every agent has a row with all six fields, and every row gets reviewed at least quarterly.
How do you stop the count from growing while you count?
Three moves at once, because any one alone fails.
Set the standard.
No agent touches production data without an inventory record. Owner, scope, failure definition, kill switch. Thirty minutes, not a security review.
Make registration trivial.
A web form or a Slack command that takes ten minutes. If registering takes three weeks, your developers will route around it, and I'd route around it too.
Say it out loud: an unregistered agent is a security incident.
Not paperwork. The Air Canada chatbot ruling in 2024 settled that companies own what their AI says and does. An unregistered agent on production data is a liability attached to whoever turned it on.
What does good visibility look like after the first count?
A weekly rhythm, not a quarterly audit. Watch for new agents in the logs within seven days, for existing agents expanding their reach (new API call types, new systems in the audit trail, a jump in cost), and for agents failing in ways their owner hasn't acknowledged.
That last one is the expensive miss. A customer service agent at a mid-size company started issuing refunds outside policy after a customer figured out how to ask. It ran for 11 days. The refunds weren't the real cost. The six months of trust rebuilding were. Ongoing identity hygiene for everything you find lives in how to govern non-human identities at agent scale.
Frequently asked questions
What's the difference between a workflow automation and an AI agent?
An automation runs fixed steps: same input, same output. An agent reasons, plans, chooses, and adapts, so the same input can produce different outputs. Agents need all six inventory fields because their actions aren't predictable in advance.
Is shadow AI riskier than shadow IT?
Yes. Shadow IT is a tool a person uses without approval. Shadow AI acts without approval, at machine speed, often with no human in the loop. A shadow folder leaks data. A shadow agent with write access changes it.
How often should we re-run the inventory?
Continuously through registration and monitoring, with full re-validation quarterly. Anything slower than monthly means you're working from stale data.
What if a business unit refuses to register their agent?
Treat it as an incident and bring in compliance, not just security. Most refusals are misunderstanding, and they end the moment the owner learns the company owns whatever the agent does.
Key takeaways
You can't govern an agent you haven't counted.
Three moves build the first inventory in a week: ask, scan, audit.
Six fields per agent, or it's just a list.
Registration has to be easier than routing around it.
An unregistered agent is an incident, not paperwork.
Start with the ten-minute version
The free ATF assessment walks you through the same questions a real inventory asks, in about ten minutes.
Somewhere in your company, an agent is working right now that nobody wrote down. Counting it is the whole first step.