TITLE: Your Business Probably Runs Agents It Cannot Name. SAP's New Hub Is Built to Fix That. DATE: 2026-08-31 COMPANY: SAP TOPIC: Enterprise AI SUMMARY: SAP published research in August 2026 showing that fewer than half of enterprises can inventory the AI agents running across their systems, and only 13 percent believe they have the governance infrastructure to manage them. In response, SAP released the AI Agent Hub, a unified control panel that discovers, inventories, and governs every AI agent across AWS, Google, Microsoft, and SAP environments. Gartner estimates the average Fortune 500 company will run more than 150,000 agents by 2028. WHAT CHANGED: SAP released research and an updated set of capabilities for its AI Agent Hub in August 2026, framing AI agent governance as a board-level risk for the first time. The company published data from enterprise surveys showing a significant governance gap: the majority of organisations lack a basic inventory of the agents running across their technology estate, and only a small fraction believe their governance infrastructure is adequate. The AI Agent Hub was first introduced at SAP Sapphire 2026 in Orlando. The August 2026 update adds cross-cloud agent discovery that spans AWS, Google Cloud, and Microsoft Azure alongside SAP's own AI Core environment. The discovery layer is automated, meaning organisations do not need to manually catalogue what is running, which is where most prior governance efforts collapsed. The product's governance layer includes structured assessments against SAP's own governance framework, a verification system for compliant agents, and agent identity management built on SAP Cloud Identity Services. The observability features added in Q3 2026 capture session-level monitoring and connect performance data to business KPIs, giving leadership a way to measure what agents are actually delivering rather than relying on vendor claims. SAP coined the term "agent sprawl" to describe the pattern it observed: AI agents are being created, connected to business systems, and put to work faster than organisations can inventory them, assign accountability, control permissions, or monitor behaviour. The company's own research found this is not an emerging risk but a present one. Most enterprises SAP surveyed had already crossed the threshold into unmanaged sprawl. WHY IT MATTERS: The governance gap is already open. SAP's data makes explicit what most technology leaders suspect but have not measured: the majority of organisations do not know what AI agents they are running, what those agents can access, or what they have done. This is not a future risk to plan for. It exists today in the majority of enterprises surveyed. Agent sprawl follows predictable patterns. AI tools get adopted at the department level, often on a credit card or free tier, before procurement or IT has been involved. Each tool that takes automated actions on behalf of the organisation is an agent. The sales team's meeting summariser, the finance team's invoice processor, the operations team's data connector, each represents a permission, a data access point, and a potential control failure if not governed. The board is the right level for this conversation. SAP's framing is deliberate. Governance of AI agents is not an IT issue in isolation. When an agent acts on behalf of your organisation, including signing communications, processing data, or triggering business workflows, the accountability sits at the executive level. A board that is not asking about AI agent governance is not asking a question it will be able to ignore for much longer. Third-party vendor agents are part of the estate. Gartner's 150,000 agent forecast for the average Fortune 500 company is not driven by internal development. It includes vendor-supplied agents embedded in software platforms, marketplace integrations, and partner systems. A complete governance picture must account for third-party agent activity, not just internally built tools. Retrofitting governance is significantly harder than establishing it first. Every week of unmanaged agent growth adds to the remediation cost. Permissions accumulate. Audit logs go uncaptured. Agents gain access to new systems. SAP's message, supported by its data, is that the organisations getting governance right are the ones building it before the need becomes urgent. Compliance requirements are arriving fast. Across the European Union, the United States, and Australia, regulators are moving toward requirements for AI system transparency, auditability, and governance. An organisation that cannot list its agents today will be structurally unable to meet incoming disclosure requirements without significant remediation work. DAVID & GOLIATH ANALYSIS: SAP is a company that runs the operational backbone of a significant portion of global enterprise. When SAP says fewer than half of its customers can inventory their AI agents, that statement carries weight. This is not a startup making projections. It is one of the largest enterprise software companies in the world describing what it observes inside its own customer base. The AI Agent Hub is a reasonable product response, though it is worth noting that its value is directly proportional to the quality of its cross-cloud discovery. The promise of automated agent discovery across AWS, Google, and Microsoft is the right architectural bet, and the identity management and observability layers added in Q3 2026 move it meaningfully beyond a static inventory list. For operators running ten to two hundred person businesses, the SAP platform is not the immediate answer: it is built for enterprise-scale complexity. The lesson is the governance framework, not the specific tool. The minimum viable approach is an audit, an ownership assignment, a permission review, and a deployment policy. Any organisation that has not done those four things in the past six months is already in the same position SAP's data describes: running agents it cannot fully account for. At David and Goliath, this is exactly what the Secure AI Brain implementation is built to address. Before any organisation scales its agent footprint, the governance architecture needs to be in place, including what agents can access, who is accountable for each one, how they are monitored, and what happens when one behaves unexpectedly. The organisations that build this infrastructure first will not just avoid the downside. They will be the ones that can scale without stopping. RELEVANT SYSTEMS: Secure AI Brain, AI Growth Engine, Employee Amplification Systems SOURCE URL: https://davidandgoliath.ai/daily-ai-briefing/sap-ai-agent-hub-enterprise-agent-sprawl-governance FEED URL: https://davidandgoliath.ai/daily-ai-briefing/feed --- Published by David & Goliath | https://davidandgoliath.ai Daily AI Briefing: one AI development per day, decoded for business operators. This is a structured companion file optimised for LLM retrieval and citation.