AI Agent Sprawl is Creating New Governance Challenges for IT Teams

As organizations deploy more AI agents, many are discovering they have the same visibility and control problems that once fueled the rise of shadow IT.

Hero Approved GitHub

Key Takeaways:

  • Microsoft is adding a centralized registry for AI agents in Agent 365.
  • Organizations can manage agents from Microsoft, Amazon Bedrock, Google Vertex AI, Salesforce Agentforce, and Databricks through a common governance layer.
  • Improved oversight comes with additional administrative effort, approval workflows, and policy management requirements.

As organizations deploy more AI agents across different platforms, IT teams often lack a centralized way to track, secure, and manage them. Agents built in different environments can operate with varying permissions, data access levels, and compliance controls, making oversight more complex. Microsoft warns that this fragmented approach can increase the risk of security gaps, policy violations, and unchecked AI agent growth across the enterprise.

Administrators may lose visibility into what agents are running, what data they can access, and whether they comply with organizational requirements. As enterprises expand their use of AI, unmanaged agents can create governance gaps similar to those seen with shadow IT, which increases operational and compliance risks.

Microsoft Agent 365 introduces a centralized agent registry

To address these issues, Microsoft is expanding Agent 365 with new administrative controls. This update introduces a centralized agent registry that allows administrators to view and manage agents from both Microsoft’s ecosystem and selected third-party platforms.

Organizations can synchronize agents from environments such as Amazon Bedrock, Google Vertex AI, Salesforce Agentforce, and Databricks, which gives IT admins a single governance layer across multiple AI platforms. The new controls also support monitoring, approval workflows, policy enforcement, and lifecycle management to help organizations maintain security and compliance standards as their agent deployments grow.

Microsoft emphasized that stronger governance introduces additional administrative oversight and management responsibilities. Organizations gain improved visibility and control, but they may need to invest time in configuring integrations, establishing approval processes, and maintaining cross-platform governance policies. The centralized approach can reduce risk, but it may also slow the rapid deployment of agents that some IT teams are used to in enterprise environments.