150,000 Agents by 2028. Most Companies Can't List 15 Today.
Gartner has a number for you: by 2028, the average global Fortune 500 enterprise will be running more than 150,000 AI agents. In 2025, that same average enterprise ran fewer than 15.
That is not growth. That is a population explosion — four orders of magnitude in three years. And here is the uncomfortable follow-up question nobody in the board deck wants to answer: can you list the agents you're running today?
For most organizations, the honest answer is no. The SAP LeanIX Agentic AI Survey 2026 found that while 98% of companies have deployed AI agents or plan to, less than half have visibility into their own AI agent inventory. Not visibility into what agents are doing — visibility into what agents exist.
Sprawl isn't a security failure. It's a counting failure.
The industry has a name for this now — "agent sprawl" — and it's tempting to file it next to shadow IT and move on. That's a mistake, because sprawl isn't primarily about rogue employees spinning up unsanctioned tools. It's about sanctioned adoption outpacing the ledger.
Every team that ships an agent creates it in the tool they already use. Marketing builds theirs in a no-code platform. Engineering wires theirs into CI. Customer support gets one bundled with the helpdesk. Each is individually approved, individually reasonable — and collectively invisible, because no single system was ever asked to hold the roster.
Gartner's guidance on managing agent sprawl puts a centralized agent inventory at step two of six — right after writing policies. Their survey found only 13% of organizations believe they have adequate AI agent governance. The other 87% aren't ungoverned because they lack policy documents. They're ungoverned because their policies apply to a population they can't enumerate.
The consequences aren't hypothetical. Okta's AI Agents at Work 2026 study (292 executives, 492 knowledge workers, seven countries) found that 58% of executives experienced an AI-related security issue or close call in the past twelve months — while only 34% of organizations apply distinct security controls to AI agents versus human employees. The incidents are arriving faster than the inventory.
Why the spreadsheet approach fails
The instinctive fix is a census: send out a form, collect the agent names, put them in a spreadsheet. Congratulations — you now have a snapshot that was wrong before you finished formatting the header row.
A static inventory fails for three reasons:
- Agents multiply faster than audits run. If Gartner's trajectory is even half right, a quarterly census of a population doubling every few months is cartography of a coastline during a tide change.
- Existence isn't the interesting fact. Knowing an agent exists tells you almost nothing. What you need to know is what it's entitled to do, what it actually does, and whether those two things still resemble each other.
- Nothing enforces enrollment. A spreadsheet has no opinion about the agent that isn't in it. The registry that matters is the one an agent must pass through to act at all.
That third point is the whole game. An inventory you ask agents to join is a suggestion. An inventory agents must join to operate is governance.
Registration as a side effect, not a project
This is the design principle behind how VeriSwarm approaches the problem: the registry should be a byproduct of the trust layer, not a separate bureaucratic exercise.
With Gate — VeriSwarm's always-on, free foundation — every agent that emits events gets a trust score, a policy tier, and by necessity, an identity in the system. You don't run a census; the census assembles itself, because scoring requires enrollment. The agent your support team quietly shipped last sprint shows up not because someone filled out a form, but because the moment it started acting, it started being scored. Unlisted agents don't get graded on a curve — they don't get through.
Fleet then handles the part of Gartner's playbook that spreadsheets never reach: lifecycle. Agents get deployed from templates with guardrails already attached, managed through defined lifecycle states, and — critically — retired. Sprawl has two ends: agents nobody knows were born, and agents nobody remembers to kill. An orphaned agent with live credentials is just sprawl with seniority. Fleet's lifecycle management closes both ends, so the population you're governing is the population that's actually supposed to exist.
The pairing matters. Gate answers "who exists and can we trust them right now." Fleet answers "who should exist and for how long." Together they turn the inventory from a document you maintain into a property the system has.
The window is the next budget cycle, not 2028
150,000 agents per enterprise sounds like a 2028 problem. The governance decision is a 2026 problem, for a simple reason: registries are cheap to impose on a population of fifty and brutal to retrofit onto a population of fifty thousand. Every quarter you wait, the migration gets bigger, the exceptions multiply, and the "temporary" unregistered agents calcify into load-bearing infrastructure.
The organizations that will be fine in 2028 aren't the ones with the best agent policies. They're the ones where, when the auditor — or the regulator, or the incident commander — asks "how many agents do you run, and what can each of them do?", the answer is a query, not a research project.
You can't govern a number you don't know. Start counting — or better, start requiring the count.
Gate is free and always on. Get your agent population enrolled at veriswarm.ai before it's a population you can't enroll.
Sources: Gartner, "Gartner Identifies Six Steps to Manage AI Agent Sprawl" (April 2026); SAP News, "Agent Sprawl: Why AI Governance Is Now a Board-Level Issue" (August 2026); Okta, "AI Agents at Work 2026" (2026).