The Next Cybersecurity Problem: Too Many AI Agents - Xecunet

Latest News

The Next Cybersecurity Problem: Too Many AI Agents

ai-agent-cybersecurity

A marketing employee creates an AI agent to analyze customer feedback. Sales builds another to research prospects. Someone connects an agent to Microsoft 365, while another department creates one that can update CRM records.

Individually, each project makes sense. Six months later, someone asks a much harder question:  How many AI agents do we actually have?

Nobody knows.

That’s the emerging problem of agent sprawl. As businesses make it easier for employees and departments to deploy AI agents, tracking those agents may become as important as securing them.

What Is Agent Sprawl?

Agent sprawl happens when AI agents multiply faster than an organization can inventory, secure, monitor, and manage them.

Microsoft describes agent sprawl as the uncontrolled proliferation of unmanaged or over-permissioned agents. Its guidance for managing agentic AI risk recommends maintaining inventories, establishing ownership, applying least privilege, and governing agents throughout their lifecycle.

Think of this as the next evolution of a familiar IT problem.

  • First there was Shadow IT.
  • Then Shadow SaaS.
  • Then Shadow AI.
  • Now we’re entering the era of shadow agents.

The Rise of the Shadow Agent

Employees usually don’t create unauthorized technology because they’re trying to create cybersecurity problems. They’re trying to get work done.

Someone discovers an AI tool that automates a repetitive process. They connect it to a business application, grant a few permissions, and start using it. Then someone else does the same thing.

This becomes more significant when agents can access Microsoft 365, CRM systems, databases, customer information, internal documents, and other business applications.

Microsoft has warned about a growing wave of shadow AI, including agents operating outside traditional IT governance. Its Agent 365 announcement discusses discovering and managing these agents as organizations move from AI experimentation toward broader deployment.

Your biggest AI governance problem may not be the IT agents approved. It may be the agents IT doesn’t know exist. Consider that for a second.

Who Created This Agent?

Imagine your cybersecurity team discovers an AI agent accessing customer information.

Who created it? That should lead to several other questions:

  • Who owns the agent today?
  • Why was it created?
  • What systems can it access?
  • What permissions does it have?
  • Which credentials does it use?
  • Is anyone monitoring its activity?
  • Is it still needed?

If nobody can answer those questions, you have an AI governance problem.

Microsoft’s Entra ID Governance for agent identities addresses this by assigning owners and human sponsors to agent identities. The sponsor provides human accountability for decisions about the agent’s access and lifecycle.

That’s a useful principle regardless of which AI platform you’re using. Every AI agent needs a human owner.

What Can the Agent Actually Access?

Knowing an agent exists is only the beginning. You also need to know what it can reach and what it can do once it gets there.

An agent might have access to email, SharePoint, CRM records, customer databases, financial systems, cloud applications, APIs, or internal documents. Some agents may only retrieve information, while others can modify records or execute actions.

That’s why Agentic AI Management Services should focus on identity, access control, governance, monitoring, and human oversight rather than simply deploying AI tools.

It also builds on the security principles discussed in our recent post, AI Agents Need Their Own Security Strategy. Once an AI agent has credentials, permissions, and the ability to act, treat it as an identity.

The rule should be straightforward: Give an agent only the access required to perform its specific job.

More Agents Means More Permissions

Suppose your organization has five well-managed agents. You know who owns them, what they access, and what they’re allowed to do.

Now imagine 50.

Each may have its own credentials, APIs, connectors, permissions, data sources, and integrations. Without centralized oversight, those permissions can quietly accumulate.

Microsoft’s security guidance for AI agents recommends maintaining a centralized inventory, assigning owners, governing access, and tracking agents through their lifecycle.

An agent originally created to read customer records shouldn’t gradually acquire the ability to modify them, export them, and connect them to other systems simply because nobody reviewed its permissions.

That’s not only an AI problem. It’s an identity-management problem.

Is Anyone Monitoring the Agents?

Imagine an employee suddenly downloading thousands of customer records at 2:00 a.m.

Your cybersecurity tools might notice. What happens when an AI agent does it?

Was the activity legitimate? Was the agent compromised? Did someone change its configuration? Without monitoring, you don’t know.

NIST’s work on AI agent identity and authorization specifically highlights identification, authorization, auditing, and accountability as important considerations as agents gain access to business data, tools, and applications.

Organizations should be able to determine:

  • Which agent performed an action
  • Which resources it accessed
  • What information it retrieved
  • What changes it made
  • Which identity or credentials it used
  • Whether the behavior was expected

If you can’t reconstruct what an agent did after something goes wrong, you don’t have enough visibility.

Don’t Forget to Decommission the Agent

Someone created an AI agent for a six-month project.

  • The project ends. The employee changes departments.
  • The agent doesn’t.
  • It still has credentials, permissions, integrations, and possibly access to business systems.

That’s why agent lifecycle management matters. That’s scary.

Decommissioning an agent may require removing more than the agent itself. You may also need to revoke:

  • API keys and OAuth (Open Authorization) tokens
  • Application registrations
  • Service accounts
  • Database permissions
  • SaaS (Software as a Service) integrations
  • Cloud resources
  • Automation workflows
  • Connected tools

Microsoft’s agent security guidance recommends managing agents from registration and approval through expiration, access review, deactivation, and decommissioning.

Every agent should have an exit strategy.

Create → Approve → Monitor → Review → Retire

You Can’t Govern What You Can’t See

Before you can secure AI agents, you need to know they exist.

That means organizations need a centralized inventory. At minimum, you should know:

  • What is it? Establish the agent’s identity.
  • Who owns it? Establish accountability.
  • Why does it exist? Document its business purpose.
  • What can it access? Understand exposure.
  • What can it do? Understand authority.
  • How is it monitored? Establish visibility.
  • When was it reviewed? Prevent permission creep.
  • Is it still needed? Identify orphaned agents.
  • How will it be retired? Manage the lifecycle.

Gartner has also identified centralized agent inventory, governance policies, lifecycle management, monitoring, and employee education as important elements of managing AI agent sprawl.

Its guidance on managing AI agent sprawl also notes that simply blocking agents can push employees toward unsanctioned alternatives.

The objective isn’t to stop innovation. It’s to make innovation visible and manageable.

Centralized Governance Doesn’t Mean Centralized Development

Marketing should be able to explore AI. Sales should automate repetitive work. Customer service should improve workflows. Operations should look for efficiency.

Those departments shouldn’t need to become cybersecurity experts.

Centralized governance gives them boundaries within which they can innovate. A practical governance model should establish standards for:

  • Agent registration and ownership
  • Approved platforms
  • Identity and credential management
  • Data access and permissions
  • Human approval requirements
  • Logging and monitoring
  • Periodic access reviews
  • Decommissioning

That’s the philosophy behind Agentic AI Management Services. The objective isn’t to prevent businesses from adopting AI. It’s to provide the governance, security, identity controls, and monitoring necessary to use it responsibly.

Start With an AI Environment Review

You don’t need a massive AI governance program to get started. First, figure out what you already have.

Look across Microsoft 365, SaaS applications, automation platforms, cloud services, development environments, and department-specific tools. Then identify the agents operating within them.

For each one, ask:

  • Who created it, and who owns it now?
  • What business purpose does it serve?
  • Which systems and data can it access?
  • What actions can it perform?
  • What credentials does it use?
  • Is anyone monitoring it?
  • When was its access last reviewed?
  • Do we still need it?
  • How will we decommission it?

If you can’t answer those questions, you’ve identified where the work needs to begin.

More AI Shouldn’t Mean Less Control

AI agents can create tremendous value. They can automate repetitive work, connect systems, retrieve information, assist employees, improve customer service, and accelerate business processes.

But more agents also mean more identities, credentials, permissions, integrations, and potential exposure.

Eventually, someone will discover an agent and ask:

“Wait. Who created this thing?”

That’s not the question you want to ask during a cybersecurity incident.

  • Know what agents exist.
  • Find who owns them.
  • Know what they can access.
  • Know what they’re doing.
  • And when they’re no longer needed, remove them.

Because the next AI cybersecurity problem may not be one incredibly powerful agent.

It may be hundreds of small ones nobody remembered they had.

If your organization is already experimenting with AI agents or connecting AI to business systems, Xecunet can help identify what’s operating in your environment and where governance gaps may exist.

Schedule an AI Environment Review with Xecunet