Notícia

Agent sprawl: when the speed of AI threatens governance; understand

Por Equipe Editorial CifraNET · 29/06/2026
Agent sprawl: when the speed of AI threatens governance; understand
Publicidade

Consolidated in the IT universe since 2010, the term sprawl is used to designate the disorderly expansion of tools - from VMs (virtual machines) to cloud resources. Now, under the name "agent sprawl", the phenomenon has reached autonomous artificial intelligence agents.

What distinguishes agent sprawl from other tools is its nature. While VMs and containers only execute what they are instructed to do, autonomous agents can make decisions, access systems, trigger actions and operate at all times without needing human approval for each task.

This governance deficit becomes qualitatively more risky as agents multiply - and is especially worrying for Brazil, which leads global agentic adoption. In a survey by systems integration company Jitterbit, 501 IT managers reported operating, on average, 32 autonomous agents.

Interviewed by CNN Brasil, Marcos Oliveira, Global Software Engineering Manager at Jitterbit, explains that the central problem is not the volume, but the lack of control: "the challenge is not just the number of agents, but the lack of visibility into how they operate, what data they access and what value they effectively deliver to the business."

What makes this scenario even more worrying is the speed of adoption. In the Jitterbit survey, 99% of Brazilian companies plan at least one result with AI in the next 12 months - a pace that leaves little room for governance to keep up.

In addition, 9% of these companies operate with more than 100 agents - compared to 2% in the US and 3.4% in the UK. The consultancy Gartner estimates that only 13% of organizations have adequate governance for this volume, which leaves 87% of them exposed to structural risk.

Security risks in environments with multiple autonomous agents

Without centralized visibility, security flaws in autonomous agents can go unnoticed until it is too late - Freepik
The chaotic growth of AI agents creates a scenario where there is no way to ensure control, security and compliance. In practice, they are agents created by different teams, without standards and without central supervision of those who create, those who use or those who audit. "Risks are no longer concentrated in a single application and start to spread throughout the corporate environment", warns Oliveira.

In this way, security and compliance - which should be the foundations of sustained agent growth - become, in the presence of agent sprawl, the main obstacle to end-to-end automation. Not by chance, it was by far the most cited reason by Brazilian managers: 42.1%, according to Jitterbit.

With the multiplication of "siloed agents" - isolated, without centralized visibility - the attack surface grows and audits become almost impossible. According to consultancy McKinsey (2025), 80% of organizations have recorded problematic behavior with agents, but only 21% of executives know what they actually do.

Responsible for corporate AI architectures for 14 years, Oliveira highlights the relevance of ISO/IEC 42001 - the first international standard focused on the management of artificial intelligence systems, with guidelines for governance, risk management and responsible use of AI.

Legacy systems - old software, often without documentation or active support - are another point of weakness: 36.1% of Brazilian companies point to this incompatibility as a barrier to end-to-end automation, according to Jitterbit. Each new agent requires its own connections, rules and flows, creating an additional layer of complexity on top of an infrastructure that is already complex by nature", says Oliveira.

How to balance accelerated agentic deployment and corporate responsibility?

Treating agents as corporate assets requires constant monitoring - DC Studio/Magnific
Containing agent sprawl does not require slowing adoption, but prioritizing governance before complexity escalates. This means mapping existing agents, defining access policies by role and risk level, and centralizing their monitoring.

For Oliveira, there is a clear limit between innovation and lack of control. He recommends treating agents "like corporate assets rather than isolated experiments" - defining creation criteria and performance metrics for each.

A common approach in the market is to separate the model, integration and data layers - a solution sold by iPaaS companies (platforms that connect different systems to each other), a category to which Jitterbit itself, author of the aforementioned survey, belongs.

This does not invalidate the data, but it calls for caution: according to Jitterbit, 59.3% of respondents point to the responsibility of AI as the most important factor in choosing tools, surpassing even the speed of implementation (time to value), mentioned by 49.7%.

Brazil leads the adoption of AI agents and also optimism regarding returns: 43.1% of companies project high returns within 12 months. But the big challenge now is to resist the pressure of hype and operate with criteria, because, at this accelerated pace, what is at stake is the very survival of the business.

"Companies that invest first in integration, orchestration and governance are able to transform agents into productivity accelerators" - highlights Oliveira. And he concludes: "those that adopt agents without an integration strategy end up running the risk of increasing the complexity they intended to solve."

Brazil is among the countries that most use artificial intelligence

Source: CNN

Publicidade