Cross-Platform Agent Register: Closing the Agent Inventory Gap · Enterprise Agentic AI Insights

Only 18% of enterprises hold a complete agent inventory. How CIOs build a cross-platform agent register that survives discovery, ownership and Article 50 attestation.

The number nobody has There is a question going around board meetings this quarter that sounds like it should take a minute to answer. How many AI agents are running in this company right now. Most CIOs cannot answer it. Not because the work has been sloppy, but because the question changed shape while everyone was busy shipping. A year ago an agent was a project. Now it is a feature inside a licence somebody already bought. It gets created in a workflow builder, in a copilot studio, in a service console, in a notebook, and none of those creation events look like the kind of thing that generates a CMDB record. The numbers around this are unusually consistent. Only 18% of organizations maintain a current, complete inventory of the agents already running inside their walls CITED C04. Roughly half of enterprise agents operate in isolated silos with no shared context or unified governance, and 27% of the APIs connecting them carry no audit trail or access controls CITED C03. Gartner puts the trajectory at more than 150,000 agents in the average global Fortune 500 enterprise by 2028, up from fewer than 15 in 2025 VERIFIED C01, while only 13% of organizations believe they have the right governance in place for them CITED C02. That last pair is the whole story. The population is compounding. The control plane is not. What is actually happening this month ServiceNow expanded AI Control Tower this year from governing agents built on ServiceNow to discovering, observing, governing, securing and measuring AI deployed across any system in the enterprise CITED C07. The discovery reach runs through thirty new enterprise integrations covering AWS, Google Cloud and Microsoft Azure, plus SAP, Oracle and Workday. General availability for the expanded capabilities lands in August 2026. There is a deepened integration with Microsoft Agent 365 so that Foundry, Copilot Studio and Agent 365 agents surface in the same plane. On the Microsoft side, Conditional Access for Agents and ID Protection for Agents finish rolling into Agent 365 and M365 E7 this month CITED C08. Any agent published through M365 channels with an Entra Agent ID lands in the Agent 365 inventory automatically. Read those two together and the market has just told you something useful. The vendors have decided that the control plane is a product category. Both of them are now shipping the ability to find agents you did not build. Which is genuinely helpful, and also where the trap sits. The operational mechanic that fails A control tower is a reconciliation engine. It compares what it discovers against what you declared. That comparison is only as good as the declaration. Here is the pattern we keep seeing in diagnostics. The platform team turns on discovery. Discovery returns a number. The number is four to twenty times larger than the register. Everybody stares at it. Then the conversation immediately becomes an argument about whether the discovered objects are really agents, or prompt templates, or flows, or somebody's saved query. Nobody can settle the argument, because there is no agreed definition of what counts and no owner attached to any of it. The discovery run produces a spreadsheet, not a position. Six weeks later the Now Assist deflection target comes up in a QBR, and the deflection number cannot be defended either, because the denominator was never stable. Three things break in sequence: 1. No definition. Agent, assistant, flow and skill get used interchangeably across four platforms. Discovery counts by platform semantics, not by yours. 2. No owner. An agent without a named human accountable for it cannot be paused, retired or explained. Ownership is the field most registers skip because it is the only one you cannot automate. 3. No evidence. Knowing an agent exists is not the same as being able to show what it did. Registers hold names. Auditors ask for actions. Why this became a board issue on 2 August Article 50 of the EU AI Act became applicable on 2 August 2026 VERIFIED C09. It applies immediately to all in-scope systems regardless of when they were placed on the market. The relevant duty is short: systems that interact directly with people, including chatbots, voice assistants and AI agents, must disclose that the person is engaging with AI unless it is already obvious. Providers of systems generating synthetic audio, image, video or text must mark those outputs machine-readably and make them detectable. The marking and detection duty for generative systems already on the market has transitional relief to 2 December 2026. Exposure runs to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The word doing the work there is per system. The duty attaches to each agent that talks to a person. Not to your AI policy, not to your programme, not to a paragraph in the privacy notice. An agent you cannot enumerate is an agent you cannot attest for. That is the turn from operations to liability, and it is why the register stopped being an IT hygiene item. One correction, because it matters Several vendor and analyst posts published this month state that the EU AI Act "reaches full enforcement in August 2026", with penalties up to EUR 35 million or 7% of global turnover FLAG C10. Both halves of that are wrong, and we follow the primary legal sources: - 2 August 2026 activated Article 50 transparency only. High-risk obligations were deferred under the Digital Omnibus. Annex III high-risk moves to December 2027. Annex I product-embedded high-risk moves to August 2028. - The EUR 35M and 7% tier attaches to Article 5 prohibited practices, which have been applicable since 2 February 2025. It is not a new August 2026 exposure. If your programme was re-planned around a "full enforcement" date this month, it was re-planned around a date that does not exist. That is worth an hour with counsel before your next steering committee, because the correction cuts both ways: you have more runway on high-risk classification than the noise suggests, and less excuse on transparency, which is live now. The move Do not buy the control plane first. Do the four things that make the control plane produce a defensible number instead of an argument. 1. Write the counting rule before you run discovery. One page. What counts as an agent in this company, what does not, and why. If it can take an action against a system of record or hold a conversation with a person on your behalf, it counts. Circulate it to the four platform owners and get disagreement out in the open before the tool produces a number. 2. Reconcile against identity, not against tickets. Entra Agent ID, service principals, integration users, connected app records. Identity systems know what actually authenticated. Ticket systems know what somebody remembered to ask for. 3. Assign one accountable human per agent, and let the list be short and ugly. An agent with no owner gets a 30 day clock and then gets paused. This is the step that generates political heat and the step that makes everything after it possible. 4. Classify human-facing agents first. Those carry the Article 50 disclosure duty today. Everything else can wait a cycle. Write the actual disclosure sentence for each, and store it next to the agent record so the attestation is a lookup rather than a project. None of that requires a new licence. All of it makes the licence you are about to buy worth something. Estimate your own gap The calculator below models the distance between the agents you can name and the agents that are probably running, using four inputs you already have. It runs entirely in your browser and sends nothing anywhere. It is a planning estimate for a board conversation, not an audit result. <div data-ariana-embed="agent-attestation-gap-calculator"</div --- What we would do in your first two weeks The AEGIS Diagnostic (Agentic Enterprise Governance and Intelligence Standard) runs exactly this sequence: counting rule, identity-led discovery across your actual plat

Open the formatted article on Ariana.Digital →