Do You Know How Many AI Agents You Are Running?
Here is a sign of where things are heading: enterprises are now buying software whose only job is finding out what AI agents they are running. SAP is bringing one to general availability this quarter, pitched as a central place to discover, verify, observe, and optimize every agent in the environment. Think about what has to be true for that product to sell. Large organizations have genuinely lost track of the autonomous things operating inside their own systems. Your business is smaller. It is not immune, and the reason is that you probably did not deploy most of them on purpose.
Idle software versus active agents
We wrote recently about AI tool sprawl, the pile of overlapping subscriptions nobody fully uses. Agent sprawl is a different animal, and a more serious one. A forgotten subscription sits there costing you money until someone cancels it. A forgotten agent acts. It might be updating records, sending messages, moving data, or running a nightly task, all without anyone thinking about it. The question changes from "what are we paying for?" to something sharper: what is currently running in my business, with what permissions, and who owns it?
Why you have more than you think
The reason small businesses accumulate agents quietly is that most of them were never a decision. Reporting suggests a large share of enterprise applications will ship with agents by the end of this year, which means they arrive bundled into software you already bought and switched on with a toggle someone found useful. Add a workflow automation a staff member set up, an assistant connected to the shared inbox, and a scheduled task in the CRM, and a ten-person company can easily have several autonomous things running that have never appeared on any list.
The failures are quiet, not dramatic
Nobody expects a rogue agent story. The realistic problems are mundane and easy to miss for weeks.
| The quiet failure | How you find out |
|---|---|
| Agent keeps running after its owner leaves | Something odd happens and nobody knows why |
| Far more access than the task needs | During a security or client review |
| Two automations doing conflicting things | Duplicate emails or contradictory records |
| Agent silently stops working | A task everyone assumed was handled, was not |
That last one deserves attention. Businesses worry about agents doing the wrong thing, but an agent quietly doing nothing while everyone assumes coverage is at least as common and often more expensive.
The one-page version of a control plane
You do not need to buy what SAP is selling. You need the discipline underneath it, which for a business your size fits on a single page. List every automation and AI agent you run, and for each record four things: what it does, what systems and data it can reach, who owns it, and how you would turn it off. That is the whole exercise. Most owners doing it for the first time find at least one item they had forgotten and one with more access than it needs. Then make a simple rule that anything new gets added, and revisit the list a couple of times a year.
Where this leaves you
Agents are genuinely useful and this is not an argument for fewer of them. It is an argument for knowing what you have, because that knowledge is what lets you add more with confidence. When large organizations are buying dedicated software just to answer "what is running?", a small business that can answer it from a single page is in better shape than it sounds. Spend twenty minutes building the list this week. The value is not the document, it is that you will never again be surprised by something acting in your business that you forgot you turned on.
Frequently Asked Questions
What is an "agent control plane"?
It is software whose entire job is keeping track of the AI agents running inside a business: discovering what exists, verifying it is authorized, watching what it does, and shutting down or tuning the ones that misbehave. SAP is bringing one to general availability this quarter, described as a centralized place to discover, verify, observe, and optimize every agent in the environment. The fact that this is now a product category tells you something important: large organizations have lost track of their own agents, and buying a tool to find them is cheaper than the alternative.
How is agent sprawl different from having too many AI tools?
Tool sprawl is a spending and attention problem: overlapping subscriptions nobody fully uses. Agent sprawl is an operational and risk problem, because agents do not sit idle waiting to be opened. They act. An unmanaged subscription costs you money; an unmanaged agent might be updating records, sending messages, or touching customer data on a schedule nobody remembers setting up. The question shifts from "what are we paying for?" to "what is currently running, with what permissions, and who owns it?"
Would a small business really have this problem?
In miniature, and sooner than you would expect, because you probably did not deliberately deploy most of them. Reporting suggests a large share of enterprise applications will include agents by the end of this year, which means agents arrive inside software you already bought rather than as a decision you made. Add a workflow automation someone set up, an assistant connected to your email, and a scheduled task in your CRM, and a ten-person business can easily have several things acting autonomously that nobody has ever listed in one place.
What could actually go wrong?
Rarely anything dramatic. The realistic failures are quiet: an agent that keeps running after the person who set it up leaves, one with far more access than its task requires, duplicated automations doing conflicting things, an agent touching customer data in a way you would struggle to explain to a client, or one silently failing so a task everyone assumes is handled simply is not. None of these announce themselves. They surface weeks later as a strange result, an awkward client conversation, or a compliance question you cannot answer quickly.
What should a Canadian business do about it?
Build the list before you need it. Write down every automation and AI agent running in your business, and for each one record four things: what it does, what systems and data it can reach, who owns it, and how you would turn it off. Most owners find at least one surprise. Then set a simple rule that new agents get added to the list, and review it a couple of times a year. You do not need a control plane platform. You need the discipline that platform is selling, which for a small business fits comfortably on one page.
Know exactly what your AI is doing
We help Canadian businesses map every automation and agent, right-size permissions, and put simple oversight in place, so you can automate more with confidence.
Related Articles
AI Agents Are About to Join Your Team Chat
Your Business Software Is Quietly Growing Agents
AI-Powered COBOL Modernization: What Canadian Enterprises Need to Know
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.