AI agents inside companies are no longer a boardroom talking point or a small pilot program.
In a survey conducted from December 2025 to January 2026, OutSystems asked nearly 1,900 IT leaders around the world about agentic AI adoption. The headline finding was blunt: 96% of enterprises have already deployed AI agents in some form, and 97% are building an enterprise-wide agent strategy.
Then came the catch: 94% of respondents said they are worried that AI sprawl is adding complexity, technical debt and security risk.
The rollout is moving quickly. Control is not keeping pace.
What Is Sprawling?
AI sprawl is a new phrase for a very concrete problem: the number of AI agents in a company is growing quickly, while management remains fragmented.
The data points to that gap:
- 38% of enterprises are using both internally built agents and third-party agents, creating two hard-to-govern systems at once.
- Only 36% have a centralized model for agent governance.
- Only 12% use a unified platform to manage AI sprawl.
The other 88% are largely living with team-by-team decisions, regional differences, incomplete access records and scattered activity logs. Many cannot easily say which agent touched which system, under which permission, or why a decision was made.
OutSystems CEO Woodson Martin said the shift from AI experimentation to measurable business results is no longer a future scenario; it is the reality companies face now.
That sounds positive on its own. Read alongside the 94% concern figure, it feels much less comfortable.
The August Deadline
The issue is especially urgent this year because the EU AI Act enforcement deadline arrives in August 2026.
For companies deploying AI systems, several requirements are hard to ignore:
Article 9: companies need continuous, documented risk management across every deployment stage. In practice, that means a unique identity for each agent, a record of its permissions and a record of what it is doing.
Article 13: when a third-party AI system is used, suppliers must provide enough documentation for users to understand the system's output. Saying that nobody knows what the agent was doing is not a defense.
Taken together, those rules mean companies need to:
- Maintain a registry of all agents, including how many are running, where they run and what permissions they have.
- Keep operation logs in a centralized, encrypted store, rather than stitching together isolated platform logs.
- Revoke an agent's access within seconds when necessary.
- Give human auditors enough context to understand agent decisions, not just a confidence score.
The problem is that only 12% of enterprises currently have a unified platform to do this.
Multi-Agent Chains Make It Harder
A single agent can still be tracked. The harder pattern is the agent chain: a large task is broken into dozens of subtasks, passed across multiple agents and then handed back to a person for approval.
Auditing one action in that architecture means reconstructing the full chain. Every hop needs its input and output recorded. If something goes wrong, responsibility is almost impossible to find manually.
That is why the governance gap becomes especially dangerous in multi-agent systems.
Regional Differences
The survey covered multiple regions, with maturity varying sharply.
| Region | Maturity |
|---|---|
| India | Most mature, with the highest share of production deployments |
| Australia | Moving from pilots into production |
| Japan | Also moving from pilots into production |
| Brazil | Mid-level maturity |
| Germany and the United Kingdom | Mid-level maturity |
India's lead is a little surprising, but it makes sense: a dense IT services sector, lower engineering costs and high acceptance of new tools can make agent adoption move faster.
What To Do Now
The study's advice comes down to three basics:
- Count first: how many agents are running, and what permissions do they have? If the answer is unclear, start there.
- Centralize logs: every action by every agent needs a traceable record in one place, not a patchwork of platform-specific logs.
- Build an emergency breaker: if an agent misbehaves, can access be cut within 30 seconds? If not, that is the first control to fix.
August is still a few months away, but for companies managing agents through loose, team-level practices, those months are not much time.
Sources: CocoLoop, Agentic AI Goes Mainstream in the Enterprise, but 94% Raise Concern About Sprawl (OutSystems / Business Wire); Agentic AI's governance challenges under the EU AI Act in 2026 (AI News)