
Agency AI builds on the economic potential of generative AI, which, according to McKinsey estimates, could contribute $2.6 to $4.4 trillion annually to the global economy. This represents the next phase in the adoption of enterprise AI: the transition from pure content creation to autonomous execution, and from isolated pilot projects to productive deployment.
Uncontrolled Proliferation of AI Agents
This shift presents a new challenge for AI governance. The term “agent proliferation” refers to a situation where AI agents are developed, deployed, or linked across systems faster than the company is able to track them, assign responsibilities, control access rights, monitor their behavior, and optimize or decommission them once they no longer serve their purpose.
A recent survey on Agentic AI conducted by SAP LeanIX underscores this shift, as it found that 98 percent of companies have already implemented AI agents or plan to do so. But while adoption is accelerating rapidly, those responsible are struggling to keep up with implementing AI governance. According to the same report, fewer than half of the companies surveyed have a clear overview of which AI agents they actually have in use.
Every technology company that has ever experienced a SaaS wave is familiar with the mechanisms behind this proliferation of agents. Individual teams introduce agents on their own—motivated by genuine productivity goals. Each AI agent is designed for a specific task: a marketing automation agent here, a supply chain monitoring agent there, an HR onboarding bot elsewhere. And they all operate in isolation. Without a central platform or an overarching governance framework, this creates a fragmented landscape of agents in which the individual tools do not communicate with one another, cannot be uniformly audited, and accumulate technical debt faster than they create value.
According to Gartner, a typical Fortune 500 company will have more than 150,000 AI agents in use by 2028. Yet only 13 percent of companies believe they have the right governance in place to manage this flood of agents. Max Goss, Senior Director Analyst at Gartner, warned his audience at a London conference in April: “While CIOs and IT leaders are currently experiencing a veritable explosion of AI agents in their companies, many are struggling with uncontrolled proliferation that exposes their organizations to significant risks—ranging from misinformation to excessive data sharing to data loss.”
He went on to explain: “Many companies are responding by blocking or severely restricting the use of AI agents. But that’s not a sustainable solution in the long run. If employees can’t work with the approved tools, they’ll likely circumvent the company’s controls and turn to shadow AI, which carries even greater risks. Companies must strike the right balance: they need to manage agents and rein in uncontrolled growth, while at the same time empowering their employees to work securely with these tools to drive innovation.”
Agents typically require comprehensive, cross-system permissions to function, yet these permissions are rarely managed with the same care as those for human users. The risk posed by unmanaged or uncontrolled AI agents within the enterprise is therefore real and steadily increasing.
Security Concerns Regarding AI Agents
Cases are now known from corporate practice in which AI agents disclosed confidential information or exceeded their intended boundaries —for example, through deliberate instructions that caused agents to bypass security measures, delete production data, or trigger irreversible financial transactions.
It is precisely these security risks that are causing major headaches for leading technology companies. With chatbots and earlier forms of generative AI, security issues were mostly limited to erroneous output: an inaccurate or inappropriate response that could usually be corrected afterward. In the age of AI agents, however, the consequences of misconduct or security incidents can be significantly more serious—after all, agents independently carry out actions, use tools, access systems, and trigger business processes.
That’s why managing agents is no longer purely an IT matter. It increasingly touches on issues that fall under the purview of the executive board: risk management, regulatory risks, data protection, traceability, operational resilience, and accountability for autonomous decisions.
The New AI Governance Platform
Leading companies are rethinking their approach: They no longer view the governance of AI agents as a burdensome obligation, but rather as a critical success factor. After all, this determines whether their AI investments will pay off or become a problem. As a result, effective AI agent governance has quickly become a board-level issue and is contributing to the emergence of a new platform category: the AI governance platform.
This category is still in its infancy, but its purpose is becoming increasingly clear. Companies need to keep their agents under control: They need to know which agents exist, what they do, what access rights they have, whether they operate in compliance with regulations, and how they behave in production.
SAP is among the pioneers in the field of Agentic AI—a new technology category. And with the acquisition of LeanIX in 2023, SAP has significantly expanded its capabilities in the area of enterprise architecture management. This has quickly become a recognized differentiator for the SAP AI Agent Hub—by positioning AI artifacts such as agents, models, and MCP servers within the company’s overall architecture and business context.
Based on this, the SAP AI Agent Hub functions as a central control center. From here, all AI agents and AI tools across the enterprise can be managed and controlled—regardless of which vendor they come from or which systems they run on.
As SAP CTO Philipp Herzig explained on stage at this year’s SAP Sapphire, the SAP AI Agent Hub is intended to assume a governance role for all AI agents across the entire enterprise. “Agents are everywhere,” he said. “Some are good, some aren’t, and almost no one has a consistent picture—no central governance, no clear view of what individual agents are doing, whether they add value, or whether they comply with company policies.”
Herzig continued: “With the SAP AI Agent Hub, that’s changing. It provides a central entry point and command center to discover, manage, and control all AI agents, LLMs, and MCP servers in your landscape, regardless of vendor. The [SAP] AI Agent Hub enables you to discover all your agents in context: your landscape, your business processes. Once you’ve identified the right agents, you can manage their risk and make decisions regarding IT architecture or compliance rules.”
The window of opportunity is narrowing
AI agents are being deployed in companies at an ever-faster pace. As a result, there is less and less time to set up effective control systems in time before something goes wrong. For CIOs, CEOs, and corporate boards, the question is no longer whether AI agents should be managed. It is whether governance is built into the architecture from the start or retrofitted only after the first serious failure. The issue is whether governance is integrated into the architecture from the start or whether it is retrofitted after the first serious failure has occurred.
Companies that view the management of AI agents as a strategic priority in 2026 will be better positioned to gain a long-term competitive advantage through AI. Those who postpone planning now will likely have to clean up the mess in 2027. In IT, the rule is: Acting quickly without a well-thought-out structure will come back to haunt you sooner or later. With AI agents, however, this happens much faster and with greater consequences than with previous technologies.
– – – – –
Further Reading
👉 www.sap.com
Photo: unsplash