Agent inventory evidence gap: Microsoft Agent 365 and the number your board will ask for · Enterprise Agentic AI Insights
48% of production AI agents run with no governance and only 7.2% of organizations can name one person accountable. What a CIO needs before the next platform review, with a free agent accountability gap check.
The control plane arrived before the coverage did. Microsoft Agent 365 has been generally available since May 1, 2026, at fifteen dollars per user per month standalone, or bundled into the new Microsoft 365 E7 SKU. It inventories Copilot Studio agents, custom agents built on Azure AI Foundry, partner agents from Genspark, Zensai, Egnyte, Zendesk, Kasisto, Kore and n8n, and, through discovery, local desktop agents running on managed Windows endpoints. That registry now surfaces into Defender and Intune, so endpoint and security teams see the same list IT sees. ServiceNow moved the same direction from a different starting point. AI Control Tower was extended to discover, observe, govern, secure and measure AI deployed across any system in the enterprise, not only ServiceNow. The completed Traceloop acquisition added runtime tracing into how agents reason and where they decide. Quality and safety are now scored on every agent execution in near real time, with step, tool and output traces. Gateway-level metrics are captured per server, tool and client with no agent-side instrumentation required, on an AI Gateway rebased from Spring Boot onto an Envoy data plane. Both of these are real engineering. Neither of them answers the question a CIO is actually being asked this quarter. The number on the renewal and the number in production Here is the mechanic that is failing. A control plane reports on the agents it can see. Across a survey of 750 senior technology leaders in the UK and USA, fielded in April 2026 against the same instrument fielded in December 2025, the enterprise agent estate roughly doubled in four months. The modal deployment bracket moved from 26 to 50 agents up to 76 to 100. Nearly 38 percent of organizations reported running more than 100 agents. Over the same four months, mean monitoring coverage went from 46.96 percent to about 52 percent. The fleet doubled. Coverage moved five points. Which means the absolute number of agents nobody can trace went up, not down, and it went up while every organization in the sample was buying tooling specifically to bring it down. Stated confidence went the other way. Confidence in agent visibility rose from 82.6 percent to 91.8 percent over the same window. Ninety-two percent of leaders say they can see their agents. Fifty-two percent of agents are actually instrumented. That spread is the finding. Three numbers to carry into your next platform review: - 48 percent of production AI agents run with no security or governance controls at all. - 9.5 percent of organizations secure more than 80 percent of the agents they have deployed. - 7.2 percent have a named individual with formal accountability for agent behavior. Another 32.4 percent describe accountability as unclear or situation-dependent, and 22.9 percent say it has simply not been discussed. The pre-deployment picture is thinner still. No single control is used by even 40 percent of organizations before an agent goes live. A named accountable person tops the list at 37.8 percent. A security review from IT or the CISO sits at 35 percent. A documented process to pause or revoke agent access, 34.1 percent. And 81 percent of respondents report pressure to deploy agents quickly even when governance is not in place. The top driver cited is maximizing ROI on AI investment, at 38.1 percent, with boardroom and investor pressure close behind at 33.7 percent. The same board asking for the return is the board that will ask for the evidence. The bill for this is already being written Gartner expects more than 40 percent of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. A separate Gartner forecast published May 26, 2026 expects 40 percent of enterprises to demote or decommission autonomous agents by 2027 after governance failures surface in production. Note which of those two is the harder conversation. A canceled project is a write-off. A decommissioned production agent is a workflow your operation had already absorbed, pulled out after something went wrong, with the incident on record. The same Gartner note carries a warning worth reading twice: applying uniform governance across all AI agents will itself lead to enterprise AI agent failure. Blanket policy across a fleet of a hundred agents doing a hundred different things slows the low-risk ones to a stop and still under-covers the high-risk ones. Tiering is the requirement. A tier assignment requires an inventory. The inventory is the thing that does not exist. Why this became a board item and not an IT item This is the turn, and it lands after the operational problem, not before it. The regulatory calendar moved this year. It did not empty. Under Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force three days later, high-risk obligations for standalone Annex III systems were deferred to December 2, 2027, and for AI embedded in regulated products under Annex I, to August 2, 2028. The Commission cited harmonized standards work at CEN and CENELEC and conformity-assessment infrastructure that had not matured. Real reprieve, publicly reasoned. But Article 50 transparency and marking obligations land on December 2, 2026. That is roughly ten weeks out. And to know which of your systems fall under Article 50, you have to be able to list them. In the United States, Colorado repealed and reenacted its AI Act as SB 26-189, signed May 14, 2026 and effective January 1, 2027, after a federal magistrate blocked enforcement of the predecessor statute in April. The rewrite dropped the risk management program requirement, the impact assessment requirement, and the reasonable-care duty against algorithmic discrimination. It kept notice, post-decision disclosure and consumer rights around automated decision-making technology in consequential decisions. The Attorney General has said he will not enforce until rulemaking concludes. And on September 16, state bank supervisors published an examination framework that asks, for every autonomous system, five documented things: the actions the system is permitted to take, the human intervention checkpoints, the logging, the reversibility of those actions, and the ability to restrict or halt operations. Different jurisdictions. Different scopes. Different dates, several of them softened. Every one of them opens with the same artifact request. A dated inventory of your agents, with a named owner against each one. That artifact is what 92.8 percent of surveyed organizations cannot currently produce. The move The instinct is to treat this as a monitoring backlog and put it behind the rollout. It is not a monitoring backlog. Untraced agents are unevidenced decisions sitting in your operational record, and they accrue whether or not anyone is looking. Four lines of evidence, in this order: Count what is actually running. Not what was approved. Agent 365 discovery on managed endpoints and AI Control Tower cross-system discovery will each surface things that were never registered. Run both if you have both. The gap between the approved list and the discovered list is your first real finding, and it is usually the one that changes the conversation with the board. Put one name against each agent. Not a team, not a function, not a shared inbox. The December 2025 survey asked who was accountable and got confident answers, CTO at 28.2 percent, CISO at 26 percent. The April 2026 survey asked how accountability was handled and found that most of what looked like ownership was informal or undefined. The first question in an examination is who, not what. Document the halt. For each agent: permitted actions, intervention checkpoint, logging, reversibility, and the named authority to stop it mid-action. This is the requirement most organizations report being least ready to meet, and it is the one that now appears in an active examination framework. Date it. An inventory without a