AI agent governance starts with a simple question most IT teams cannot answer yet: which agents exist in your tenant, and who owns each one?
Somebody in your finance team built an agent last month. It reads a SharePoint site, drafts commentary on the monthly variance, and posts it into a Teams channel every Monday morning. It works well. Nobody in IT knows it exists. That is AI agent governance in one sentence, and the question is arriving faster than most Microsoft 365 tenants are ready for.
The pattern will feel familiar. Teams sprawl happened exactly this way: a genuinely useful thing, no friction to create one, no owner written down anywhere, and then a cleanup project two years later that nobody wanted to fund. Agents follow the same curve with one difference that matters. A stray Teams site is a container. It sits there. An agent acts. It reads on a schedule, calls connectors, and produces output that people start to trust without checking.
Agents multiply from more places than sites ever did
The scale is worth a moment. IDC projects roughly 1.3 billion agents in circulation by 2028. Microsoft's identity team reports that 80 percent of leaders say agent use in their organization increased over the past year. Treat both as direction rather than precision, but the direction is not in dispute.
What makes this harder than the sprawl problems you have already survived is the number of doors. A site got created one way. An agent can appear from half a dozen places, most of which are switched on by default in a standard Microsoft 365 tenant.
Every one of those paths is a reasonable feature on its own. Added together, with no record kept, they produce an estate that nobody in the building can describe.
Three questions decide whether you have a problem
Ask your team these, in this order, and see how far you get.
Which agents exist right now, across Copilot Studio, SharePoint, Teams, and anything a developer stood up in Azure? Who is accountable for each one by name, not by department? What data and which connectors can each of them reach, and would you be comfortable if that list were read aloud in a board meeting?
Most organizations we talk to answer the first question with an estimate, the second with a shrug, and the third with genuine surprise. That gap is the actual risk. It is not that agents are dangerous by nature. It is that an agent inherits the permissions of whoever built it, and in a tenant where permission hygiene was never great, that inheritance is the problem. This is the same underlying issue behind Copilot oversharing, which we have written about before. Agents just make it move faster and run unattended.
An orphaned agent is worse than an orphaned site
When the person who built an agent changes roles or leaves, the agent usually keeps going. It still runs on a schedule. It still holds whatever access it was given on day one. Six months later somebody adds a connector to widen what it can do, and there is no owner to notify and no review to trigger.
So the first governance rule is unglamorous and non negotiable: every agent has a named human owner, and that ownership is checked on a recurring basis rather than captured once at creation. If you have ever run a proper access review, you already know the shape of this work. It is the same discipline applied to a new kind of identity.
The second rule is that agents should be provisioned the way you provision anything else that touches company data. A template that attaches naming, a sensitivity label, an owner, and a scope at the moment of creation costs you nothing later. Retrofitting all four onto three hundred existing agents is a project.
What Microsoft gives you, and what it does not
Microsoft has moved quickly here. Agent 365 reached general availability on 1 May 2026 and acts as a control plane rather than a build tool: a registry of the agents in your estate, lifecycle controls, and policy enforcement. Alongside it, Microsoft Entra Agent ID treats agents as first class identities, which means Conditional Access, risk detection, and access reviews apply to them the way they apply to people. The GA release added discovery of unmanaged agents through Defender and Intune, which is how you find the ones nobody told you about.
It is a paid add-on rather than something that appears in your tenant for free, so check current pricing with your licensing partner before you plan around it. At the time of writing it is sold standalone at roughly 15 dollars per user per month and included in the Microsoft 365 E7 suite.
Here is the part worth being clear about. Tooling gives you visibility and enforcement. It does not decide who in your organization is allowed to build an agent, what data classifications an agent may touch, what happens when an owner leaves, or how you retire one. Those are policy questions, and buying a licence does not answer them. We have watched Microsoft 365 governance programs fail for exactly this reason: the platform was configured and the decisions were never made.
Where to start, if you are starting from nothing
You do not need a committee. You need ninety days and somebody accountable for the outcome.
The inventory nearly always produces at least one surprise, and that surprise is usually the thing that gets budget approved. After that, the work looks like ordinary Microsoft 365 governance: clear ownership, sensible defaults, permissions that reflect how the business actually works, and a review cadence that survives a busy quarter. If your OneDrive and library structure is still a sore point, fix that first, because agents will happily read whatever that structure exposes.
For most mid market teams this is not a headcount problem. It is a decision making problem, which is where an outside virtual CIO or CTO earns their keep: someone who has seen how this goes elsewhere, will write the policy in plain language, and will not let it become a fifty page document nobody reads.
If you are not sure where your tenant stands, that is a reasonable place to be. We run a free AI readiness call that covers exactly this ground: what exists, what it can reach, and the two or three changes worth making before agent use grows further. It usually takes half an hour and you will leave with a straight answer either way.
