Copilot agent sprawl is the buildup of AI agents inside Microsoft 365, mostly created in Copilot Studio by employees outside IT, that nobody has inventoried, assigned an owner, or reviewed for what data and systems they can touch. Unlike classic shadow IT, these agents inherit trust from a platform IT already approved, so they run without ever crossing a procurement or security review. If your team has not pulled a full agent list from the admin center this quarter, you almost certainly have more of these than you think.
Most IT leaders I talk to assume this is a large-enterprise problem.
It isn't. A 500-person company with Copilot Studio licensing already has the tooling for any employee with a Power Platform seat to stand up an agent that reads a SharePoint library or drafts emails on their behalf, no ticket required. The gap between what IT thinks is running and what is actually running is the whole problem, and it is measurable now in ways it wasn't a year ago.
Agent sprawl is broader than shadow AI. Shadow AI covers tools used without IT's knowledge; agent sprawl includes agents IT technically approved at the platform level (Copilot Studio itself) but never reviewed individually, so each one lacks a registry entry, an owner, or a lifecycle. A marketing coordinator who builds a Copilot Studio agent to summarize competitor RFPs from a shared drive has not broken any rule. Nobody wrote the rule, because nobody knew the agent existed until it showed up in a permissions audit.
According to a Cloud Security Alliance survey commissioned by Token Security (April 2026, 418 IT and security professionals), 82% of organizations discovered at least one AI agent or workflow in the past year that security or IT did not previously know existed, and 41% said it happened more than once. The same survey found 68% of respondents reported high confidence in their AI agent visibility, which means most of the people who found a surprise agent thought they had this covered before they went looking.
According to Gravitee's State of AI Agent Security 2026 report (919 executives and practitioners surveyed), 88% of organizations reported a confirmed or suspected AI agent security incident in the prior twelve months, and only 21% said they have runtime visibility into what their agents are actually doing after deployment. Just 14.4% reported that every agent in their environment went live with full security and IT approval.
The most common source of shadow agents in that CSA survey was internal automation or scripting environments, at 51%, followed by LLM platforms and custom assistants at 47%. Both categories sit inside tools your organization probably already licenses, which is exactly why an agent built there does not trip any procurement alarm.
Microsoft Agent 365 reached general availability on May 1, 2026, and the Agent Registry inside the Microsoft 365 admin center is the piece most mid-market teams should start with for this specific problem. It lists every registered agent in the tenant, who created it, what data sources it can reach, and whether it has been reviewed, which is exactly the gap a Copilot Studio agent built outside IT falls into. We covered the MSP-facing side of Agent 365, multi-tenant agent management and the GDAP and licensing details that come with it, in our Microsoft 365 Admin Agent GA piece; this post is about the single-tenant discovery problem that comes before any of that.
A registry is only useful if someone runs it on a schedule. Here is the sequence that works for a lean IT team without a dedicated AI governance hire.
| Inventory Method | Coverage | Effort |
|---|---|---|
| Manual check of Power Platform admin center | Catches Copilot Studio agents only; misses agents built through other Microsoft 365 surfaces | Low tooling cost, high time cost, easy to skip a quarter |
| Agent Registry (Microsoft 365 admin center) | Full tenant view: agent owner, data sources, review status | Low effort once set up; native to your existing licensing |
| Multi-tenant agent management (public preview) | Same view as Agent Registry, extended across every governed tenant | Best fit for MSPs and holding companies managing more than one tenant |
None of this replaces a real access review. It just makes the review possible, because you cannot govern what you have not counted. We built the same principle into the tiered access model we deploy for ServiceNow and Microsoft 365 automation, covered in our three-tier security model for IT automation: read-only actions run unattended, state-changing actions need admin enablement, and anything privileged needs explicit confirmation every time. Employee-built Copilot agents deserve the same tiering, not a blanket allow because Copilot Studio itself was already approved.
The honest caveat: the Agent Registry only sees agents built inside Microsoft's own agent-building surfaces. An employee pasting company data into a personal ChatGPT account or a browser extension never shows up there, and that gap is bigger at companies without a licensed enterprise AI tool that competes with the free options. Agent Registry solves the Microsoft 365 half of shadow AI, not the whole problem.
A finished inventory also is not the end of the job. Once you know which agents exist, someone has to own each one, and we walked through how to assign that ownership without falling back on "the AI team owns it" in who is accountable when your AI agent breaks something. Inventory and ownership are two different failures, and most mid-market teams we talk to are missing both.
It is the accumulation of AI agents, mostly built in Copilot Studio by employees, that IT never individually reviewed, assigned an owner to, or added to a registry. The agents run on infrastructure IT already approved at the platform level, so they never trigger a separate security review the way a new SaaS purchase would.
Open the Agent Registry in the Microsoft 365 admin center, which lists every registered agent along with its creator, connected data sources, and review status. Teams managing more than one tenant can use multi-tenant agent management, in public preview as of August 2026, to pull the same view across every governed tenant from one screen.
It is a security risk. Gravitee's 2026 survey of 919 organizations found 88% had a confirmed or suspected AI agent security incident in the prior year, and the Cloud Security Alliance found 51% of unknown agents originate in internal automation and scripting tools your org already licenses. An unreviewed agent with read access to an HR or finance library is a live exposure, not a hypothetical one.
Monthly for organizations under roughly 1,000 employees, tied to a recurring calendar reminder rather than an annual audit cycle. CSA survey data shows 41% of organizations that found an unknown agent found more than one, which points to a recurring gap rather than a single missed agent.
Usually not, since an agent with no assigned owner and no documented business purpose is, by definition, not something anyone has flagged as depended-upon. Disable first and let the owner, if one exists, request reactivation. That is a lower-risk default than leaving an unreviewed agent with live data access running indefinitely.
Our AI readiness assessment includes a full agent and connector inventory across ServiceNow and Microsoft 365, so you know what is live before you decide what to automate next.
Start Your AssessmentFree 2-minute assessment. Get an industry-specific score and action plan — no call required.