Skip to main content

Your Business Probably Runs Agents It Cannot Name. SAP's New Hub Is Built to Fix That.

Monday 31 August 2026|SAP|
Secure AI BrainAI Growth EngineEmployee Amplification Systems

SAP published research in August 2026 showing that fewer than half of enterprises can inventory the AI agents running across their systems, and only 13 percent believe they have the governance infrastructure to manage them. In response, SAP released the AI Agent Hub, a unified control panel that discovers, inventories, and governs every AI agent across AWS, Google, Microsoft, and SAP environments. Gartner estimates the average Fortune 500 company will run more than 150,000 agents by 2028.

Operator Insight

The governance problem with AI agents is not philosophical. It is immediate. Every department that deployed a coding assistant, a meeting summariser, or a data connector in the past eighteen months created an agent that can access systems, call APIs, and take actions on behalf of your business. Most organisations do not know what those agents are doing right now. The organisations that govern this estate from a single place will have a material advantage over those that discover the gaps after an incident. SAP's data makes the case plainly: the majority of enterprises cannot even list what is running.

30-Second Summary

SAP published data in August 2026 showing most enterprises cannot list the AI agents operating across their systems, and less than one in seven has governance infrastructure it considers adequate. SAP's response is the AI Agent Hub, which connects to AWS, Google, Microsoft, and SAP AI Core to discover and govern every agent from a single interface. The data is the story: agent sprawl has already happened, and most organisations are managing it retrospectively or not at all.

At a Glance

  • Topic: Enterprise AI Governance
  • Company: SAP
  • Date: August 2026
  • Announcement: SAP published research on AI agent sprawl and released updated AI Agent Hub capabilities including automated cross-cloud agent discovery, structured governance assessments, agent identity management, and AI observability with session-level monitoring.
  • What Changed: For the first time, enterprises have a practical tool to inventory and govern AI agents across multiple cloud environments without building custom monitoring from scratch.
  • Why It Matters: The majority of enterprises are already running agents they have not formally inventoried, permissioned, or governed. SAP is quantifying the gap and providing the first major enterprise software platform-level response.
  • Who Should Care: CEOs, COOs, CIOs, IT leaders, and compliance teams at any organisation that has deployed AI tools in the past two years. Also relevant for operators whose teams have added AI tools without a formal procurement or governance process.

Key Facts

  • Fewer than 50% of enterprises surveyed by SAP have visibility into an inventory of their AI agents (SAP, August 2026).
  • Only 13% of organisations believe they have the right governance in place to manage their agent estate (SAP, August 2026).
  • Gartner estimates that by 2028, the average Fortune 500 enterprise will run more than 150,000 AI agents across its systems (Gartner, 2026 forecast).
  • SAP's AI Agent Hub now integrates with AWS, Google Cloud, Microsoft Azure, and SAP AI Core, providing automated agent discovery across major cloud platforms.
  • The Q3 2026 additions to the hub include agent identity management via SAP Cloud Identity Services, AI observability with session-level monitoring, and performance metrics tied to business KPIs.

What Happened

SAP released research and an updated set of capabilities for its AI Agent Hub in August 2026, framing AI agent governance as a board-level risk for the first time. The company published data from enterprise surveys showing a significant governance gap: the majority of organisations lack a basic inventory of the agents running across their technology estate, and only a small fraction believe their governance infrastructure is adequate.

The AI Agent Hub was first introduced at SAP Sapphire 2026 in Orlando. The August 2026 update adds cross-cloud agent discovery that spans AWS, Google Cloud, and Microsoft Azure alongside SAP's own AI Core environment. The discovery layer is automated, meaning organisations do not need to manually catalogue what is running, which is where most prior governance efforts collapsed.

The product's governance layer includes structured assessments against SAP's own governance framework, a verification system for compliant agents, and agent identity management built on SAP Cloud Identity Services. The observability features added in Q3 2026 capture session-level monitoring and connect performance data to business KPIs, giving leadership a way to measure what agents are actually delivering rather than relying on vendor claims.

SAP coined the term "agent sprawl" to describe the pattern it observed: AI agents are being created, connected to business systems, and put to work faster than organisations can inventory them, assign accountability, control permissions, or monitor behaviour. The company's own research found this is not an emerging risk but a present one. Most enterprises SAP surveyed had already crossed the threshold into unmanaged sprawl.

Why It Matters

The governance gap is already open. SAP's data makes explicit what most technology leaders suspect but have not measured: the majority of organisations do not know what AI agents they are running, what those agents can access, or what they have done. This is not a future risk to plan for. It exists today in the majority of enterprises surveyed.

Agent sprawl follows predictable patterns. AI tools get adopted at the department level, often on a credit card or free tier, before procurement or IT has been involved. Each tool that takes automated actions on behalf of the organisation is an agent. The sales team's meeting summariser, the finance team's invoice processor, the operations team's data connector, each represents a permission, a data access point, and a potential control failure if not governed.

The board is the right level for this conversation. SAP's framing is deliberate. Governance of AI agents is not an IT issue in isolation. When an agent acts on behalf of your organisation, including signing communications, processing data, or triggering business workflows, the accountability sits at the executive level. A board that is not asking about AI agent governance is not asking a question it will be able to ignore for much longer.

Third-party vendor agents are part of the estate. Gartner's 150,000 agent forecast for the average Fortune 500 company is not driven by internal development. It includes vendor-supplied agents embedded in software platforms, marketplace integrations, and partner systems. A complete governance picture must account for third-party agent activity, not just internally built tools.

Retrofitting governance is significantly harder than establishing it first. Every week of unmanaged agent growth adds to the remediation cost. Permissions accumulate. Audit logs go uncaptured. Agents gain access to new systems. SAP's message, supported by its data, is that the organisations getting governance right are the ones building it before the need becomes urgent.

Compliance requirements are arriving fast. Across the European Union, the United States, and Australia, regulators are moving toward requirements for AI system transparency, auditability, and governance. An organisation that cannot list its agents today will be structurally unable to meet incoming disclosure requirements without significant remediation work.

The David and Goliath View

SAP is a company that runs the operational backbone of a significant portion of global enterprise. When SAP says fewer than half of its customers can inventory their AI agents, that statement carries weight. This is not a startup making projections. It is one of the largest enterprise software companies in the world describing what it observes inside its own customer base.

The AI Agent Hub is a reasonable product response, though it is worth noting that its value is directly proportional to the quality of its cross-cloud discovery. The promise of automated agent discovery across AWS, Google, and Microsoft is the right architectural bet, and the identity management and observability layers added in Q3 2026 move it meaningfully beyond a static inventory list.

For operators running ten to two hundred person businesses, the SAP platform is not the immediate answer: it is built for enterprise-scale complexity. The lesson is the governance framework, not the specific tool. The minimum viable approach is an audit, an ownership assignment, a permission review, and a deployment policy. Any organisation that has not done those four things in the past six months is already in the same position SAP's data describes: running agents it cannot fully account for.

At David and Goliath, this is exactly what the Secure AI Brain implementation is built to address. Before any organisation scales its agent footprint, the governance architecture needs to be in place, including what agents can access, who is accountable for each one, how they are monitored, and what happens when one behaves unexpectedly. The organisations that build this infrastructure first will not just avoid the downside. They will be the ones that can scale without stopping.

Where This Fits in the AI Stack

AI agent governance sits at the intersection of AI infrastructure and enterprise security. SAP's AI Agent Hub operates as a layer above the individual AI tools and model providers, acting as the control plane that connects agent activity to business accountability. This is a distinct layer from the models themselves (Claude, GPT, Gemini), the platforms those models run on (AWS Bedrock, Google Vertex AI, Azure AI), and the applications that surface agent outputs. The governance layer is what makes all of those investable at scale for risk-sensitive organisations.

Questions Operators Are Asking

How many AI agents is our organisation actually running? If you have to guess, that is the data point. A meaningful governance programme starts with a full inventory: every AI tool that takes automated actions, whether purchased through IT, adopted by an individual team member, or embedded in third-party software. Most organisations that run this audit find between two and five times more agents than their IT teams were aware of.

Who is accountable if an AI agent makes a costly mistake? Without a named owner, the accountability is diffuse and practically unenforceable. The governance answer is straightforward: every agent gets a named business owner who understands what the agent does, what it can access, and what it cannot do. The agent does not get deployed until an owner is assigned.

Do we need enterprise software like SAP's AI Agent Hub to govern agents? No, at least not initially. A spreadsheet with agent name, owner, access permissions, deployed date, and next review date is a functional governance register for organisations running fewer than twenty agents. The case for dedicated tooling grows as the number of agents and the complexity of their integrations increases. The governance framework matters more than the specific tool.

What does "agent sprawl" actually cost? Direct costs include duplicate tool subscriptions, redundant model API bills, and overlapping integrations. Indirect costs include the time spent debugging unexpected agent behaviour, the compliance exposure from agents accessing data they should not, and the reputational risk of an agent taking an action on behalf of the business that was not intended or authorised.

How do we set a minimum governance standard before the next agent gets deployed? Four requirements are a practical starting point: a named owner, documented permissions covering what systems and data the agent can access, audit logging so every action is captured, and a review date within six months. Any agent that cannot meet these four requirements before deployment should not be deployed.

Citable Summary

SAP published research in August 2026 showing that fewer than 50% of enterprises can inventory the AI agents running across their systems, and only 13% believe they have adequate governance infrastructure. SAP responded with the AI Agent Hub, which provides automated cross-cloud agent discovery across AWS, Google Cloud, Microsoft Azure, and SAP AI Core environments. Gartner forecasts the average Fortune 500 company will operate more than 150,000 AI agents by 2028. SAP frames AI agent governance as a board-level risk, not an IT issue, citing the speed at which agents are being deployed ahead of any formal governance process.

Why This Matters for Operators

  • Conduct an AI agent audit this quarter. Ask every department head to list every AI tool their team uses that can take automated actions. The number will be higher than expected.

  • Assign ownership for each agent. An agent without a named owner is an uncontrolled liability. Someone must be accountable for what it can access and what it does.

  • Inventory agent permissions before adding new ones. Every new agent granted access to your systems expands your attack surface. Review what existing agents can access before expanding their scope.

  • Establish a minimum governance standard for new agent deployments. At minimum: named owner, documented permissions, audit logging, and a review date. Deploy this as a template, not a one-off.

  • If you are on AWS, Google Cloud, or Microsoft Azure, ask your vendor account team what agent governance tooling they offer. SAP's AI Agent Hub now integrates with all three, which means a single pane of glass is technically achievable regardless of your cloud environment.

Related Intelligence

Related Comparisons

Apply This to Your Business

Want to see what this means for your team?

Tell us a little about your business and we will map the specific opportunity for your sector and team size.

No sales pitch. We will review your details and follow up within 24 hours.