AI Agent Sprawl: Govern the Lifecycle Before You Backtrack

Episode Summary

Anyone can build an AI agent now, and that is the problem. Tim Crawford, founder and CIO Strategic Advisor at AVOA, coined the term AI agent sprawl. Low-code tools have democratized agent building, so an average user can stand one up in minutes where that once took a pro developer and a team. He names the upside first: agents reach the whole employee base, not only IT. The downside is that people build agents, forget about agents, and move on to the next, and the forgotten ones keep consuming resources until consumption passes the value returned. His answer is governance decided before the agents exist: how each is evaluated, prioritized, managed and sunsetted, because the alternative is backtracking. He drops the premise of a single model and asks for the right smallest number of policies, then separates agents from chatbots and ends on a caution that the path is not all roses.

Key takeaways

  • The vendor landscape is his starting point rather than his argument. Salesforce Agentforce, Gemini from Google and Copilot from Microsoft are the examples he reaches for first, and he says there was a huge uptick in interest in agents and agentic AI since they last spoke

  • He extends the list to the larger platform vendors and then states the point himself. After naming Q from Amazon, watsonx from IBM and Joule from SAP, he says everybody is looking at how they can leverage agents into their solutions to increase the value for customers

  • The caution he attaches to that acceleration is AI washing, which he says there is still a phenomenal amount of. His example is a toaster now improved with AI, and the work he wants done is distinguishing what is agentic from what is not

  • AI agent sprawl is his own term, and he had just published on it. He says it is becoming an issue for organizations starting down that path, and that he penned a blog post on this very issue earlier that month

  • The change he identifies is who gets to build. Low-code and no-code tools, GUIs and drag and drop have put very low hurdles in front of building powerful agents, which he describes as democratizing access to AI agents

  • He names the upside before the downside, and does not treat the trend as a mistake. The gain is exposing this technology and this power to your entire employee base rather than restricting it to IT

  • What he says is missing is governance shaped around the whole life of an agent. Agents need to be evaluated, prioritized, managed and sunsetted through their life cycle, and it is the absence of that, not the building, that turns volume into sprawl

  • His description of how sprawl actually accumulates is behavioral rather than technical: everybody has their own set of agents, they build agents and forget about agents, or stop using them and move on to the next agent

  • The cost is that abandonment is not free. Those agents are still consuming resources: minimal in some cases, he says, and in others it could be something significant. The end state he names is more resources consumed than value being returned

  • His prescription is about sequence, not tooling. Because demand for building agents will keep rising as the agentic era arrives, the thinking has to happen upfront, so that nobody has to backtrack and work out how to back away from it later

  • On governance his first instruction is to abandon a premise: you are not going to have just one model, and it is not the same problem as a data warehouse with one common schema

  • What replaces the single schema is a fluid workspace where data arrives in different shapes, sizes, volumes and velocities and is protected in different ways, and layering state, federal and sovereignty requirements on top gets complicated fast enough that humans cannot effectively manage it

  • The number he uses to make that concrete is that there are 20 different state privacy laws on the books in the US alone, and that some of them conflict with one another

  • His resolution is a count rather than a document. You cannot come up with just one, he says, and the target is the right smallest number of policies needed to manage the different work streams and data streams being exposed to agents

  • The myth he names as probably the biggest is that an agent and a chatbot are the same thing. The chat interface may look the same, but a chatbot requires you to think ahead and build the set of questions and the answers those questions tie to

  • An agent is set up to do one very specific task, and he is blunt that this makes a single agent limited: an individual agent is not super useful. The power arrives with an orchestration layer that calls other agents, each also doing one specific thing

  • Working through what it would take to reroute a package, he puts the number at eight or 10 different agents. He counts one doing nothing but validating that Tim Crawford is Tim Crawford and that there is a package, and then immediately corrects himself, calling that probably the second agent

  • Culture is the first of the three changes he expects within one to three years, and he calls it one of the leading challenges people have in working with agents today

  • The survey he runs makes culture a measurable barrier rather than an impression. He asked the CIO Think Tank he leads about the biggest challenges with AI agents, and internal culture came back second highest

  • The top challenge was data: location, strategy and access. He adds that a separate CIO Think Tank survey found AI to be one of the leading factors driving organizations to rethink their data strategy

  • The second change is greater comfort with automation, because moving into agentic means agents calling other agents and automating some of these processes, and the third is the concept he calls digital agents

  • The illustration he gives for digital agents is a demo he attributes to Salesforce, at one of their events the previous year. Someone called in and interacted with what sounded like a person, and it was actually a digital agent, which was able to order a product and make some changes to it

  • He closes on the thorns rather than the roses. There are some along the way that have to be navigated carefully, and what CIOs are contending with today is which steps to take to embrace the technology while staying focused on the value opportunities that lead toward business objectives, without introducing undue risk and governance problems into the fold

About Tim Crawford

Tim Crawford is the founder and CIO Strategic Advisor at AVOA, which he started in 2009 and through which he advises Global 2000 executives and boards on technology strategy. He came to it from more than thirty years inside enterprise IT, including Director of IT Operations at the Stanford Graduate School of Business, CIO and Vice President of Information Technology at All Covered, a division of Konica Minolta, and IT management at Philips Semiconductors. He founded and leads the CIO Think Tank, a peer group of forward-thinking CIOs whose survey findings he cites in this conversation, and he hosts the CIO In The Know and CXO In The Know podcasts. He writes on agentic AI at AVOA, where he published AI Agent Sprawl: Managing Opportunity and Risk in the Enterprise in March 2025. The term is his own. He spoke on the Overcoming Operations and Infrastructure Challenges When Deploying AI to Production panel at the AI Realized Summit in San Francisco.

 

In this episode

00:42 Welcome, and why David is hosting this week
01:07 Tim Crawford’s background, AVOA, and the two podcasts he hosts
02:25 A year of uptick in agents, and the first wave of vendor tools
02:56 Q, watsonx and Joule: the platform vendors all move at once
03:24 AI washing, and the toaster now improved with AI
04:06 The first signs that an organization has AI agent sprawl
04:30 Where the sprawl problem comes from, and the blog post behind it
04:55 Low-code, no-code and drag and drop democratize agent building
05:36 An average user can build an agent in a matter of minutes
05:36 The missing piece: evaluated, prioritized, managed, sunsetted
05:36 Build agents, forget agents, move on to the next agent
06:35 Forgotten agents still consume resources
06:57 The overhead: policy, regulatory, compliance, security, data privacy
07:24 Think about it upfront, or backtrack out of it later
07:56 What governance frameworks multiple agents need
08:16 You are not going to have just one model
08:35 A fluid workspace: shapes, sizes, volumes, velocities, sovereignty
09:02 20 state privacy laws in the US, some conflicting with each other
09:02 Not one policy, the right smallest number of policies
10:07 The biggest myth: that an agent and a chatbot are the same thing
10:07 What a chatbot requires you to build ahead of time
11:03 One agent, one task, and why a single agent is not super useful
11:03 The orchestration layer, and where the power actually comes from
11:41 Rerouting a package, worked through step by step
12:00 Eight or 10 agents for one request
12:40 Why the orchestration layer is what makes agentic powerful
13:06 A tectonic degree of sophistication that chatbots do not have
13:26 Where humans and AI agents are heading in one to three years
13:52 Cultural acceptance as the first thing to change
14:19 The CIO Think Tank survey: internal culture is the second challenge
14:46 Data location, strategy and access is the first
15:34 Greater comfort with automation as agents call other agents
15:57 Digital agents, and the Salesforce demo that sounded like a person
16:27 Not a path that is just all roses
16:48 The thorns along the way, and what CIOs are contending with today
18:11 Sending an agent as the guest next time

In Tim’s words

“an average user can build an agent within a matter of minutes”

Tim Crawford   (05:36)

“everybody’s got their set of agents and they build agents and they forget about agents, or they stop using agents and they’re onto the next agent”

Tim Crawford   (05:36)

“you’re gonna end up with more resources consumed than what you’re actually getting value from, and that inherently is why sprawl becomes a problem”

Tim Crawford   (06:35)

“you need to be thinking about that upfront so that you don’t end up with this situation and then have to try and backtrack and figure out how to back away from it”

Tim Crawford   (07:24)

“you’re not gonna have just one model, so just put it out of your head”

Tim Crawford   (08:16)

“You can’t come up with just one policy.”

Tim Crawford   (09:02)

“an individual agent is not super useful. It is useful, but it’s not super useful.”

Tim Crawford   (11:03)

“There’s a complete tectonic degree of sophistication that comes with agents that you don’t have with chatbots.”

Tim Crawford   (13:06)

“this is not a situation of, great, it’s a path and it’s just all roses”

Tim Crawford   (16:27)


 

Tim Crawford

The two posts he refers to on air

Ideas and terms discussed

Named on air

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Previous
Previous

Detect Intent, Then Tailor Every Screen to the Person

Next
Next

From Clicks to Conversions: Pay Only for Measured Outcomes