Agent Sprawl Is the Next Shadow IT. Most Australian Businesses Can’t See Theirs Yet
Somewhere in your business, someone has already built an AI agent. It might be reconciling invoices, drafting responses, or reaching into your CRM at two in the morning. They didn’t raise a ticket. They didn’t ask IT. They didn’t need to.
That’s the shift most organisations haven’t caught up to. For two years the AI conversation has been about capability. What can Copilot do, what can an agent automate, how much time can it save. Useful questions. But they’ve been answered.
The harder question is the one almost nobody is asking out loud. How many agents are running in your environment right now, what can they access, and who is accountable when one of them gets it wrong?
If you can’t answer that with confidence, you’re not alone. And you’re not safe either. Agent sprawl is shaping up to be the next shadow IT.
Key Takeaways
- Agents proliferate faster than any control system built for people or software. They have identities, permissions, and the ability to act, which means they don’t fit the categories IT already governs
- Most organisations can’t produce a complete inventory of the agents running in their environment, let alone who owns them or what they can reach
- Microsoft Agent 365 went generally available on 1 May 2026 as a control plane to discover, govern, and secure agents, including agents built on AWS Bedrock and Google Cloud, not just Microsoft ones
- It’s priced at USD 15 per user per month standalone, or bundled into the new Microsoft 365 E7 suite
- Australia’s major banks have already moved agents into live lending and service operations, and they’re now scrambling to wrap governance around them after the fact
- Buying the platform is not the same as running a governance program. The tool gives you visibility. Someone still has to do the discovery, set the policies, assign owners, and wire it into your existing controls
- For financial services, agent governance overlaps directly with CPS 230 material service provider obligations and Financial Accountability Regime exposure
Why Agents Break the Model You Already Have
Enterprise IT has spent decades getting good at governing four things: people, applications, infrastructure, and data. Every control you have, every access review, every audit, assumes what you’re managing falls into one of those buckets.
An agent fits none of them cleanly. It has an identity, like a person. It runs code, like an application. It calls tools and moves data across systems, like infrastructure. And it makes decisions and adapts to context, which none of the above do on their own.
Microsoft put it plainly in its own Agent 365 announcement: you can’t govern what you can’t see, and you can’t secure what you don’t understand. When an agent can invoke tools, access data, and talk to other agents, a helpful workflow can turn into data oversharing or an over-privileged action in seconds. And the number of agents is a moving target, so the gap widens on its own.
This is the part that catches people out. Agent sprawl isn’t a bigger version of app sprawl. Apps sit there and store things. Agents reason, decide, and act, often without a human in the loop. An unowned agent holding credentials nobody reviews is the pattern behind most of the incidents already being reported.
Financial Services Has Already Crossed the Line
If this still sounds theoretical, look at what’s happening across Australian financial services right now.
Major lenders have moved specialist AI agents into live lending operations. Agents are classifying payslips, extracting the data, running the calculations, and checking everything against policy before handing the output to a banker to review. At the scale the big institutions operate, that’s tens of thousands of payslips and well over a million transactions a week running through agents, with time savings already reported in the hundreds of thousands of hours. Others have gone agentic on core banking processes, and some are stress-testing the security and operational controls of their agent platforms before wider rollout, precisely because letting agents act on behalf of customers raises hard questions about what they should and shouldn’t be allowed to do.
Notice the pattern. The deployment isn’t the story anymore. The scramble to wrap registries, guardrails, grounded data, and named human owners around agents that can interpret policy and shape customer outcomes is the story. The institutions that pull ahead won’t be the ones with the cleverest model. They’ll be the ones who can prove their agents are governed.
What Agent 365 Actually Does
Microsoft’s answer to this is Agent 365, which reached general availability on 1 May 2026. The idea behind it is deliberately unglamorous. Rather than a new place to build agents, it’s a control plane to see and govern the ones you already have.
It extends the tools you’re probably already running. Entra gives each agent a managed identity, so an agent becomes a governed entity rather than a black box. Defender and Intune handle discovery and runtime protection, including finding shadow agents installed on devices. Purview covers data protection and audit-ready evidence. The point is that agents get treated like any other actor in your environment, with an identity, boundaries, logs, an owner, and a retirement path.
The part worth paying attention to for ANZ businesses is that it doesn’t stop at Microsoft. Agent 365 syncs with agents built on AWS Bedrock and Google Cloud, because Microsoft has accepted the obvious truth that agent sprawl won’t respect platform boundaries. Your environment will run agents from more than one vendor whether you planned it that way or not.
On cost, Agent 365 is USD 15 per user per month standalone, or it’s included in the new Microsoft 365 E7 suite. Each licence covers a person who manages, sponsors, or uses agents, which is worth modelling carefully before you commit, because it scales with how many of your people touch agents, not how many agents you run.
What This Means for You
If You’re Already on Microsoft
You’re in the strongest position, because the governance layer plugs into controls you already run. Entra, Defender, Intune, and Purview are the foundation, and Agent 365 extends them rather than replacing them. The work ahead is discovery and discipline, not a rip and replace. Start by finding out what’s actually running.
If You’re Considering Microsoft
This is a genuine point in Microsoft’s favour. Most vendors are still competing on how quickly they can help you build agents. Microsoft has bet on the harder and more durable problem of controlling them once they exist, and tied that control plane to identity and security tooling that already meets enterprise expectations. For a regulated business, that’s a stronger argument than another agent-building toolkit.
If You’re Just Starting
Good. Getting the framework in before you have two hundred agents is far cheaper than discovering them afterwards. Anyone who has lived through a SaaS audit knows exactly how the second scenario feels. Put the inventory and ownership model in place now, while the number of agents is still small enough to count.
Where to Start
The agents are already in your business. That part is decided. What’s still open is whether you can see them, govern them, and stand behind how they behave when a regulator, a customer, or your own board asks.
Start with the boring, essential question and answer it honestly: what’s running, who owns it, and what can it reach. Everything useful follows from there.
365 Mechanix works with organisations across Australia and New Zealand to bring agent governance under control, from the first inventory through to a running operating model, with the regulatory context that financial services demands built in. If agent sprawl is on your radar, or should be, get in touch with our team.
FAQs
What is agent sprawl?
It’s the rapid, often unmanaged spread of AI agents across an organisation. Agents are easy to create and deploy, so they multiply quickly across apps, devices, and clouds, frequently outside the visibility of the teams accountable for risk. The concern is that unlike apps, agents act on their own, so an ungoverned one can cause real harm fast.
What is Microsoft Agent 365?
It’s Microsoft’s control plane for AI agents, generally available since 1 May 2026. It discovers, governs, and secures agents by extending existing Microsoft tools, giving each agent a managed identity through Entra and applying security and compliance controls through Defender, Intune, and Purview. It also reaches agents built on AWS Bedrock and Google Cloud.
How much does Agent 365 cost?
USD 15 per user per month as a standalone licence, or it’s included in the Microsoft 365 E7 suite. A licence covers each person who manages, sponsors, or uses agents, so cost scales with how many of your people work with agents rather than the raw number of agents.
Does Agent 365 only work with Microsoft agents?
No. It manages agents built with Microsoft Copilot Studio and Foundry, prebuilt agents in Copilot and Teams, and agents from ecosystem partners. It also syncs with agents running on AWS Bedrock and Google Cloud, on the basis that most enterprises will run agents across more than one platform.
How does agent governance relate to CPS 230?
If an AI agent is material to how you operate, CPS 230 treats it like any other material system and service provider. That means you’re expected to understand it, govern how it’s used, monitor it, and have a plan if it fails. A control plane helps you evidence much of that, but the accountability sits with the regulated entity, not the tool or the vendor.
Do we need a partner, or can we manage this ourselves?
You can run it in-house if you have the capacity and the specialist knowledge across identity, security, and, for regulated businesses, the ANZ compliance landscape. Many organisations don’t, or would rather not learn it while agent numbers are climbing. A partner brings the discovery, operating model, and regulatory context together so the platform delivers control rather than just visibility.
How does 365 Mechanix help?
We work with organisations across ANZ to bring AI agents under proper governance on the Microsoft stack, from the first inventory through to policy, ownership, and a running operating model, with the regulatory context financial services requires built in throughout. If you want to know what agent governance should look like in your environment, get in touch.
This blog is intended as general guidance only and does not constitute legal or compliance advice. We recommend consulting your compliance team or legal advisors for advice specific to your organisation.