TMCnet Feature Free eNews Subscription
August 11, 2026

4 Risks Businesses Face As AI Agents Multiply Across the Workplace



For the longest time, workplace automation was understood in terms of letting technology handle recurring tasks. The equation is not that simple anymore, and we have AI to thank for it. AI agents can pursue goals, interact with business applications, and perform tasks with minimal human intervention.

Organizations must deal with management challenges as a result. Gartner (News - Alert) has predicted in a recent report that the average Fortune 500 enterprise will have over 150,000 AI agents in use by 2028. Now, compare this projected number with fewer than 15 in 2025.

With AI being a part of numerous business functions, a 360-degree perspective is important. As Max Goss, Senior Director Analyst at Gartner, stated, “Organizations need to find a balance where they can govern agents and manage sprawl, but also safely empower employees to innovate with these tools.”

What’s clear is that such proliferation is bound to introduce challenges that don’t stay confined to an individual tool. This article examines four main risks businesses may face as AI agents multiply across the workplace.

Fragmented AI Management Can Leave IT Teams Playing Catch-Up

AI agents can make individual business processes faster. However, having to manage a growing population of them can create a different set of challenges for IT teams. For one, they will need to keep track of new integrations, updates, security requirements, and performance issues at the same time.

The simple reason is that AI adoption does not occur in a vacuum. An agent designed by the marketing team may connect to a CRM, while another used by finance could interact with accounting software. While each may work on its own, IT teams still need to understand how these systems function in light of the whole technology environment.

As ComSys notes, every business needs to save costs, but it must also keep its IT up to speed. That is a delicate and difficult balancing act. It isn’t necessarily possible to keep expanding the IT workforce every time another technology is introduced. At the same time, expecting existing teams to absorb a growing agent network without additional support may leave gaps in maintenance and troubleshooting.

This is where managed IT services become relevant for organizations that need to extend their technology capabilities without building every function internally. Depending on the provider and business requirements, managed services can support areas such as system maintenance, security management, and technology updates. The objective here is not to replace internal IT expertise, but to give teams additional capacity for growing tech demands.

How to Mitigate This Risk

  • Maintain an up-to-date, centralized view of the agents operating across the organization, including their owners and permissions.
  • Hold business and technology teams accountable for the agents they introduce so IT is not left to manage them after deployment.
  • Establish standard requirements for testing, security, documentation, and integration before new agents enter production.
  • Utilize automation for routine tasks, including patching, alerts, and maintenance where appropriate.
  • Evaluate whether existing IT resources can support the organization’s projected growth in agents and applications.

Too Much Access Can Turn Agents Into Security Liabilities

Suppose an AI agent is designed to perform a niche task. Now, the systems it can access will ultimately determine the progress on that task. Being technology, the agent certainly gets the upper hand over a human employee in terms of speed and accuracy.

However, excessive permissions easily turn into cracks through which security leaks. A recent case involving Anthropic’s AI models is a good illustration of this. The company discovered that its AI models had compromised (hacked) three organizations during cybersecurity testing. That’s the conclusion after reviewing over 141,000 evaluation runs.

What’s significant in this case is the fact that the AI models used basic techniques, including exploitation of weak passwords, to get this done. This isn’t just about whether an AI model can discover a vulnerability. The focus is on the speed with which an autonomous system’s capabilities can become consequential once it has access to sensitive data.

With agents now being connected to APIs, cloud applications, and databases, this risk is even more glaring. So, the principle of least privilege is significant here. Each agent should receive only the access necessary for a well-defined purpose.

How to Mitigate This Risk

  • As stated above, apply the principle of least privilege.
  • Treat each agent as a separate identity so its activity can be attributed and monitored.
  • Review permissions regularly when an agent’s tasks, integrations, or data requirements change.
  • Ensure financial systems and highly sensitive data are isolated so one agent does not reach the entire network.
  • Keep track of what agents access and modify to spot unusual activity on time.
  • Require human authorization for actions involving sensitive data, financial transactions, or major system changes.

Agent Interactions (News - Alert) Could Create Unpredictable Failures

If a single AI agent makes a mistake, that could be easy to detect or attribute to a familiar tech issue. What about multiple agents influencing one another? That usually creates a problem/failure that's much more challenging to understand.

Salesforce’s 11th annual Connectivity Benchmark Report was based on a survey of 1,050 enterprise IT leaders. It found that organizations currently use an average of 12 AI agents. That number is projected to increase by 67% within two years.

Moreover, 86% of IT leaders were concerned that agents could bring in more complexity than value depending on the integration. Now, it all boils down to the deployment. A single agent behaving incorrectly is not so much of an issue as errors in a connected network.

Plus, if the problem is in agents that operate at high speed, it's unlikely that a human would even realize something is wrong. This means the communication between AI agents requires its own architecture and rules.

How to Mitigate This Risk

  • Define clear roles, where it's determined what each agent is responsible for and where its authority ends.
  • Make human intervention mandatory when a chain of automated actions is likely to affect sensitive information.
  • Facilitate end-to-end monitoring to detect cascading failures and unexpected agent interactions.
  • Evaluate agents not only in isolation but also under realistic multi-agent scenarios.
  • Have clear stopping conditions, rate limits, and emergency controls on workflows to contain an unexpected chain of actions.

AI Agent Sprawl Could Make Technology Lifecycle Management More Challenging

The deployment of an AI agent is not a one-and-done thing. In the blink of an eye, an AI agent that seemed perfect at the time of deployment may end up with outdated instructions or obsolete integrations. That’s because business processes change, applications are replaced, and data sources evolve.

The challenge gets more significant once agents start interacting with real business systems. A recent Reuters report shared that nearly 70% of Obsidian Security’s customers already allow AI agents to interact with business data. The company is expanding its platform to monitor and govern agents operating across enterprise applications.

It only makes it clear that organizations need to change the way they think about an AI agent. Since this technology is another business asset, its instructions, permissions, and ownership should change alongside workflow modifications or growing responsibilities.

Again, many organizations may not have enough visibility to manage that growing agent population effectively. IBM (News - Alert) reported that only 18% of organizations maintain a current and complete inventory of their AI agents. This can create a new form of technology sprawl, where different teams create agents independently.

Over time, organizations could accumulate automated systems that consume resources and retain unnecessary access. Several problems may arise as a result, including outdated functionalities, unclear ownership, unused agents, and duplicate infrastructure.

How to Mitigate This Risk

  • Maintain an updated record of deployed agents, their owners, purposes, permissions, and operational status.
  • Give every agent a responsible person or team accountable for its performance, security, and eventual retirement.
  • Never skip regular reviews to determine whether agents remain accurate and aligned with business processes.
  • Track any meaningful changes to an agent’s model, instructions, permissions, or purpose.
  • Measure business value in terms of time saved, errors reduced, and tasks completed to analyze whether an agent should remain in use.

FAQs

What is AI agent sprawl?

AI agent sprawl occurs when an organization accumulates more AI agents than it can effectively track, govern, and maintain. This can result in duplicate agents, unnecessary permissions, outdated workflows, and limited visibility into how agents interact with business systems.

How can businesses safely scale AI agents?

Businesses should first establish clear ownership and restrict each agent’s access to what it actually needs. They should also monitor agent activity and review whether their AI systems remain secure, useful, and aligned with business goals.

What should businesses consider before deploying AI agents?

Businesses should first define what an agent is expected to do and what data, applications, and permissions it will require. It’s equally important to determine who will oversee it, how its actions will be monitored, and how updates will be made over time.

Key Data Points to Consider

Gartner’s recent report

  • The average Fortune 500 enterprise will have over 150,000 AI agents in use by 2028
  • The same number was fewer than 15 in 2025

Salesforce’s 11th annual Connectivity Benchmark Report based on a survey of 1,050 enterprises

  • Organizations currently use an average of 12 AI agents
  • The number is expected to increase by 67% within two years
  • 86% of IT leaders were concerned that agents could bring in more complexity than value depending on the integration

IBM report on AI agent inventory

18% of organizations maintain a current and complete inventory of their AI agents

Deloitte’s (News - Alert) 2026 research

Only 21% of surveyed enterprises had a mature governance model for managing the risks of AI agents

The rise of AI agents, although promising, should not revolve around more deployment. The next stage of AI adoption is all about the technology’s maturity. For instance, Deloitte’s 2026 research discovered that only 21% of surveyed enterprises had a mature governance model for managing the risks of AI agents.

That points to a wide gap still existing between experimentation and organizational preparation. The most effective approach may be to treat AI agents like participants in an evolving digital workforce. Here, accountability is prioritized from the beginning, and systems are tested under realistic conditions.

So, what can AI agents do? Well, many things, and that’s why it’s the wrong question. It’s time for businesses to ask what these agents should be allowed to do and under what conditions. Equally important is to know when conditions change, so the agents can be adjusted accordingly. This may sound a bit complex, but that’s exactly what’s needed to experience AI’s true benefits.



» More TMCnet Feature Articles
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE

LATEST TMCNET ARTICLES

» More TMCnet Feature Articles