You can name everyone who works here. Now try the agents.

How many are running right now?

An agent inventory is knowing which agents exist, what each one may do, who owns it and what it did last week. By the time agents carry real work, most companies cannot answer the first part of that.

Every person in your company sits in a system. Name, role, manager, access, and a date when all of it ends. For the things that now do the work alongside them, none of that exists.

8 min read 7 September 2026
A person who works hereAn agent that works here
NameEmma de Vries
ManagerHead of Finance
What they may decideUp to €5,000
Last reviewedMarch
Access endsOn the leaving date
The gapOne of them is in a system. One of them is not.

Start here

Say a number first.

How many agents, automations and assistants are doing real work in your company right now? Not tools people open. Things that run. Pick the range you would give if somebody asked you in a meeting.

How it turns up

He left in April. His agents did not.

Thomas was an operations lead. He was good with this, and over about a year he built four things that quietly took a lot of dull work off his team.

He resigned in March and left in April. Everything was done properly. Laptop back, accounts closed, access revoked the same afternoon. In June somebody in finance noticed that a weekly reconciliation had stopped. It had stopped on the day his account closed. Nobody had known it existed, so nobody had missed it for six weeks.

“The three that kept running were the ones that worried me. Not the one that stopped.”

Three of the four had been set up on a company key rather than on his own account. Those were still going in June. They are probably still going now. Nobody can say which of the two situations is worse, and that is the whole point of this page.

Composite. Real details, more than one source.

What it is

Every person is in a system. The agents are not in anything.

This is not a security topic, and it goes wrong the moment it is handed to security. It is the oldest organisational question there is, asked about something new. Who works here, what are they allowed to do, and who is their manager.

For people, a company answers that without thinking. There is a name, a contract, a manager, a set of permissions, a review, and a date on which all of it ends. For the things that now do the work next to them, most companies cannot produce the list at all.

In three lines

  1. In February 2026 the American standards institute launched a programme on AI agents in which authentication and identity is one of three pillars.1
  2. A separate concept paper proposes treating agents as identifiable entities inside a company rather than as anonymous automation.2
  3. OWASP published a top ten for agentic applications in December, reviewed by more than a hundred researchers.3

You are probably here because

  • Somebody asked how many you run and you said you would come back to them
  • Something stopped and it took weeks before anyone noticed
  • A person left and you are not certain what they left behind
  • You would like the list to exist before somebody external asks for it

What you take away

  • The four places agents hide, in order of how often they are missed
  • Five columns that make a usable list, and nothing more than five
  • How this differs from the two agent challenges you may already know
  • What the standards bodies are actually doing, and what they are not

What the standards bodies are doing

When NIST starts a programme, the problem is real.

On 17 February 2026 the American National Institute of Standards and Technology announced an AI Agent Standards Initiative through its Center for AI Standards and Innovation. It runs on three pillars, and one of them is fundamental research into agent authentication and identity, so that interactions between humans and agents, and between agents, can be trusted.1

Alongside it sits a concept paper on agent identity and authorisation, open for comment until early April, which proposes applying the identity machinery companies already use for people to agents instead.2 In December, OWASP published a top ten for agentic applications, reviewed by more than a hundred security researchers.3

None of that tells you how common the problem is. It tells you that the people whose job it is to write standards think a company should be able to name its agents, and that today it generally cannot.

What you will not find on this page

Numbers. Plenty circulate, most of them saying that nine in ten companies struggle with this and that two in ten can trace what their agents did. Every source found for those figures sells software that fixes it. They are left out rather than repeated with a caveat.4

How this differs

You can have the other two solved and still fail this one.

Three challenges in this set involve agents and they are often treated as one thing. They are not, and the order matters.

The first two are questions about one agent. This one is a question about the set, and you can answer the first two perfectly for every agent you happen to know about.

That is why this arrives late rather than early. A company on Wild West has agents nobody governs, which is challenge 5. A company on Blueprint has written the rules down. It is only once the rules are good and the ownership is clear that the quiet problem shows up, which is that the rules apply to a list and the list is incomplete.

Where it starts to bite

You have to have enough of them to lose track.

01Campfire60%
02Wild West25%
03Blueprint10%
04Engine4%
05Ecosystem1%Level 5 · Ecosystem
Share of companies per level. The five AI Culture Levels we use with clients, from everyone doing their own thing to AI being part of how the company runs.3

On the first levels there is nothing to count. On Blueprint there is a policy and usually a register, and the register is right because there are six things in it and everybody remembers all six. It is on Engine and Ecosystem, where agents are built by people who are not in the technical team and arrive inside software you already pay for, that the list quietly stops matching reality.

The uncomfortable part is that this is a symptom of having done the earlier work well. Nobody loses track of agents in a company that has not got any.

What to do

Five columns, and resist adding a sixth.

The failure mode here is not doing nothing. It is buying a platform. Start with a spreadsheet that a person maintains, because the discipline is the point and the tooling is not.

Five columns. What it is called and what it does. What it is allowed to do without asking. Whose name is on it. When it last did something. What happens to it when its owner leaves. If a row cannot be filled, that row is the finding.

Getting the list started takes one hour and one question, asked in the right way. Not which agents do we have, because that gets you the official ones. Ask instead: what runs on its own that would be missed if it stopped. Ask it in the finance team, in operations, in support. The answers will not match the official list, and the difference between the two is your actual position.

The one to add to leaving procedures

Every offboarding checklist has a line for the laptop and a line for the accounts. Add a line for what this person built. It costs nothing, it happens at exactly the moment the knowledge is still in the building, and it is the single cheapest thing on this page.

What it costs to leave it

The bill is not a breach. It is a question you cannot answer.

Something will go wrong with an agent eventually. That is not the expensive part. The expensive part is the twenty minutes afterwards in which nobody can say what it was allowed to do, who set it up, or whether there is another one like it.

There are three quieter costs before that. Work stops and nobody notices, because nobody knew it was happening. Two teams build the same agent twice, because neither could see the other. And a client, an auditor or an insurer asks a reasonable question about what makes decisions in your company, and the honest answer takes a week to assemble.

None of that appears on an invoice. It appears as a company that has become slightly harder to explain to itself.

Questions people ask

Keeping track of AI agents, the questions people actually search for.

What is an AI agent inventory?
It is a list of the agents running in your company with, for each one, what it does, what it may decide without asking, whose name is on it, when it last did something, and what happens to it when its owner leaves. Five columns. Most companies have the first column in somebody's head and nothing written down for the rest.
Why do companies lose track of their AI agents?
Because agents arrive from four directions and only one of them goes through a process. The technical team builds some, which are usually known. Individuals in other teams build their own. Software you already pay for ships agents in an update. And people who leave take their access with them but not the things they built.
Is agent sprawl a security problem?
It becomes one, but treating it as a security problem first is usually why it does not get solved. It starts as an organisational question and it sounds exactly like the oldest one there is: who works here, what are they allowed to do, and who is their manager. Handing that to a security team makes it a control exercise rather than a management one.
What is NIST doing about AI agent identity?
On 17 February 2026 the American standards institute announced an AI Agent Standards Initiative through its Center for AI Standards and Innovation. It has three pillars, one of which is fundamental research into agent authentication and identity so that human-to-agent and agent-to-agent interaction can be trusted. A separate concept paper covers agent identity and authorisation.
Where does this fit among the other AI challenges?
It is one of twenty-five, and one of three about agents. The full set of 25 AI challenges runs from work nobody owns and control that quietly slips through to culture that shifts before anyone names it, each with the research behind it, the level where it starts to bite, and a test you can run this week.
Should AI agents have their own identity in our systems?
That is the direction the standards work is pointing. The NIST concept paper on agent identity and authorisation proposes treating agents as identifiable entities inside the organisation rather than as anonymous automation, using the identity machinery companies already run for people. In practice the first step is a name, an owner and a review date.
How many agents does a typical company have?
Nobody credibly knows, and be careful with anyone who tells you. Figures circulate suggesting that nine in ten organisations struggle with agent sprawl and around two in ten can trace what their agents did. Every published source for those numbers sells software that solves the problem. There is no independent measurement yet.
How do you start an agent inventory?
One hour, one question, asked three times. Not which agents do we have, because that returns the official ones. Ask what runs on its own that would be missed if it stopped, and ask it in finance, in operations and in support. The gap between those answers and the official list is your actual position.
Is OWASP covering AI agents?
Yes. OWASP published a Top 10 for Agentic Applications in December 2025, reviewed by more than a hundred security researchers. It is currently the most broadly reviewed practitioner-level threat model for agents, and it is produced by a non-profit foundation rather than a vendor, which matters when almost everything else in this area is marketing.

Getting going

Who could hand you the full list by Friday?

If the answer is nobody, that is the finding. Counting is a morning of work and it tells you more about how your company runs than a quarter of dashboards.

  1. Ask each team for their own rowsThey know what they built. Nobody outside the team does.
  2. Look at the empty owner cellsThat column is the whole exercise. The rest is bookkeeping.
  3. One rule, said out loudNothing new goes live without a row in the sheet.

First profile free · no credit card · built by emaho

Paul Musters

Paul Musters works with founders and CEOs of scale-ups and innovative SMEs on leadership, teams and AI-native ways of working. He built the AI culture levels and the set of twenty-five challenges this page belongs to.

Sources and numbers used on this page
  1. National Institute of Standards and Technology, Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation, 17 February 2026, together with the programme page of its Center for AI Standards and Innovation. Source of: the three pillars of the initiative, and the pillar covering fundamental research into agent authentication and identity infrastructure for human-to-agent and agent-to-agent interaction. Also the concept paper from the Information Technology Laboratory on AI agent identity and authorisation, open for comment until 2 April 2026, which proposes treating agents as identifiable enterprise entities rather than anonymous automation. A public standards body with no commercial interest in the answer.
  2. Open Worldwide Application Security Project, Top 10 for Agentic Applications, published December 2025 and reviewed by more than one hundred security researchers. Source of: the existence of a broadly held, practitioner-level list of what goes wrong with agentic applications. A non-profit foundation.
  3. On the numbers that are missing. Widely circulated figures on this subject, such as the share of enterprises reporting agent sprawl and the share able to trace agent actions, were traced back to vendors of agent orchestration and security platforms. No independent measurement was found, so no prevalence figure appears on this page. That gap is stated rather than filled.
  4. The scene involving Adam is a composite drawn from more than one company rather than a single case, and it is marked as such where it appears.
  5. emaho AI culture levels. The placement of this challenge at Ecosystem, and the share of organisations per level, are emaho's own reading, calibrated against published adoption research rather than measured directly.