The Agent Sprawl Problem Is an IRM Problem

FICO’s chief information officer told The Wall Street Journal this week that his company’s 3,500 employees are creating dozens of new AI agents every single day. DaVita’s employees have created more than 10,000. GitLab’s CIO says their existing governance guardrails are “holding the line” — which is another way of saying the pressure is real and building. The Wall Street Journal is calling this “AI agent sprawl.” Risk professionals should recognize it by a different name: a governance failure in progress.

The mechanism is not complicated. Platforms like Claude Cowork and open-source orchestration tools have made it trivially easy for nontechnical employees to spin up independent AI agents. That accessibility is, by design, a feature. The problem is that features do not come with governance structures. When every employee at every tier of an organization can create an agent that writes briefs, manages data sets, or executes workflows, the organization does not have an AI strategy. It has an AI population.

Conflicting Agents Are a Data Integrity Problem

FICO’s CIO named the core issue directly: multiple agents performing the same tasks can produce conflicting results for the same problem. That is not a productivity concern. That is a data integrity and decision-quality concern. In any organization where AI agents are touching risk data, compliance records, or operational reporting, conflicting agent outputs are not noise. They are a signal failure that can propagate upstream into risk positions that leadership believes are reliable.

This is precisely what the Integration Trap looks like at the agent layer. Organizations that deployed point solutions across their IRM landscape already know how conflicting data sources degrade the value of their risk programs. Agent sprawl replicates that pattern at speed and at scale, except now the conflicting sources are not legacy systems — they are autonomous processes that no one chartered and that no one is actively monitoring.

The Three-System Problem

In the IRM Navigator Model, effective risk management requires three distinct system types operating in coordination: Systems of Record that maintain authoritative data, Systems of Engagement that surface and translate that data to decision-makers, and Systems of Action that execute based on it. AI agents, as currently deployed in most enterprises, do not map cleanly to any of these categories. They operate across boundaries, often without awareness that those boundaries exist.

An agent that a compliance analyst created to summarize regulatory filings may be pulling from sources that contradict what the risk team’s System of Record holds as authoritative. An agent that a finance team member built to monitor vendor contracts may be producing outputs that conflict with what procurement entered into the system of record. Without a coherent agent governance architecture that maps each agent to a defined role within the three-system structure, organizations are building automation on top of ambiguity.

Cybersecurity and Cost Are the Visible Problems. Governance Is the Real One.

The WSJ article leads with cybersecurity risk and rising compute bills as the primary consequences of agent sprawl. Both are real. But the governance failure underneath them is more consequential for IRM leaders. When an organization cannot answer basic questions about which agents have access to which data, which outputs are being acted upon, and who chartered a given agent for a given purpose, that organization does not have AI risk management. It has AI exposure.

The CIOs quoted in the article describe trying to “tamp down” on the problem without discouraging AI use. That is a reasonable near-term posture. But it is not a risk management strategy. The organizations that will navigate the agentic era without accumulating silent governance debt are the ones treating agent proliferation as an IRM design problem from the start — not a cleanup exercise after the fact.

GitLab’s CIO acknowledged that agent sprawl is acceptable in the short term “because of the opportunity that AI presents.” That framing reflects the tension every enterprise faces right now. The opportunity is real. So is the risk that short-term tolerance becomes long-term exposure.

The IRM function has a clear role here. Agent governance is not a technology problem that IT departments will eventually solve. It is a risk design problem that requires the same rigor applied to any other process that touches authoritative data, operational decisions, or regulatory obligations. The organizations that treat it as such now are the ones that will not be building their autonomous risk architecture on top of a brittle foundation.

The deeper analysis of agentic IRM architecture and the governance design principles that distinguish a System of Action from an unsupervised agent population is available exclusively on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge.

-----

The RiskTech Journal is published by Wheelhouse Advisors. Free subscriptions are available at wheelhouseadvisors.com/risktech-journal.

Ori Wellington

Orion “Ori” Wellington is the lead editor for The RiskTech Journal and The RTJ Bridge, where he helps shape editorial direction, guide strategic narratives, and support media relations across Wheelhouse Advisors. As a digital editorial advisor, Ori synthesizes trends in risk, technology, and governance, drawing from roles modeled on information security, risk analytics, and IT leadership.

Part of Wheelhouse’s AI-augmented research team, Ori works to distill complex signals into actionable intelligence—bridging expertise across domains and elevating the voice of integrated risk thinking.

https://wheelhouseadvisors.com
Previous
Previous

Cyber Regret at the Gartner Security & Risk Management Summit: From Risk Dysfunction to Risk Agency

Next
Next

The NC State ERM Summit Just Proved the COSO Survey Right