Acuity AI Advisory
← Insights
·5 min read

Nobody Offboards an AI Agent: The Inventory Problem Irish Boards Haven't Asked About

G

Ger Perdisatt

Founder, Acuity AI Advisory

SAP found 98% of companies have deployed or plan to deploy AI agents, and fewer than half can produce an inventory of them. Every agent that exists holds credentials nobody has revoked.

SAP published its LeanIX Agentic AI Survey on 3 August. Ninety-eight per cent of the companies surveyed have deployed AI agents or plan to. Fewer than half can produce an inventory of the ones they already run. Gartner's projection in the same piece is that the average Fortune 500 enterprise will operate more than 150,000 agents by 2028, and that 13% of organisations currently believe their governance is adequate for that.

The interesting number is not 150,000. It is the gap between deployment and enumeration. An organisation that cannot list its agents has already lost the ability to switch one off.

An agent is a user account with a job description

Every agent your organisation runs has credentials. It has an API key, a service account, an OAuth token, a set of permissions against SharePoint or your finance system or your CRM. Somebody created those credentials so the agent could do the work it was built for, and in most cases they granted more access than the task required, because scoping permissions tightly is slow and the pilot was due on Friday.

Your organisation has a mature process for the human equivalent. Someone joins, IT provisions them. Someone changes role, access is adjusted. Someone leaves, HR triggers a leaver process and the account is disabled within a day. That process is audited, and in a regulated firm it is tested.

There is no leaver process for an agent. The analyst who built the invoice-matching agent moves to another team. The agent keeps running with her credentials attached to it. The consultancy that stood up the document-triage pilot finishes the engagement and invoices you. The service account they created still has read access to the matter files. The project was cancelled in March and the token issued for it is still valid in August.

This is not a hypothetical failure mode. GitGuardian's State of Secrets Sprawl 2026 found that 64% of the valid secrets it detected in 2022 were still unrevoked in 2026. Four years. The same report recorded 29 million hardcoded secrets on public GitHub commits during 2025, a 34% year-on-year rise, and an 81% surge in leaked AI-service credentials specifically. Machine identities now outnumber human ones by roughly 80 to 1 in the environments they measure.

Eighty machine accounts for every person, governed by a process built for the one person.

The Irish scale problem is the opposite of what people assume

A 400-person Irish professional services firm or a mid-sized credit union does not have 150,000 agents. It has somewhere between four and forty, spread across a Copilot deployment, two departmental automations, a vendor's embedded assistant that arrived in a software update, and whatever the finance team built themselves after a good week with a low-code tool.

Forty is a governable number. That is the point. The window in which an Irish organisation can build a complete agent register by asking people is open right now and it closes as soon as agents start creating agents. Once your automations are provisioning their own sub-tasks, enumeration stops being an afternoon's work and becomes a discovery project with a licence fee attached.

The firms that will struggle in 2028 are not the ones with the most agents. They are the ones who never wrote anything down while it was still easy.

Four regulatory obligations that assume you have the list

None of the following are new. All of them quietly presume enumeration.

EU AI Act, Article 26. Deployers of high-risk systems must assign competent human oversight, monitor operation, and retain automatically generated logs. The Digital Omnibus deferred most Annex III high-risk obligations to December 2027, which is time to prepare rather than time off. You cannot demonstrate oversight of a system you cannot name, and you cannot retain logs from an agent nobody knew was running.

EU AI Act, Article 50. Transparency duties for AI systems interacting with people have applied since 2 August 2026 and national market surveillance authorities are enforcing them now. If an agent is answering customer email, somebody has to know it exists in order to disclose it.

DORA. Financial entities have been required since January 2025 to maintain a register of information on ICT third-party arrangements. An agent operating inside a vendor's platform, holding your data, is an ICT arrangement whether or not it was procured through the ICT process.

GDPR, Articles 30 and 32. Records of processing and appropriate technical measures. A service account with standing access to personal data and no owner fails both.

The common failure is not that a firm decides against compliance. It is that the register was compiled by the IT function from the systems IT procured, and the agents were procured by everyone else.

What to do in the next quarter

Ask the executive team for four things, with a date on each.

One register, one owner. Every agent, what it does, what systems it touches, which credential it uses, who is accountable for it by name. A spreadsheet is acceptable. No register is not.

An expiry date on every credential. If nothing else changes, this one control converts a permanent exposure into a temporary one. Agents that matter get renewed. Agents nobody remembers die quietly.

Agents in the leaver process. When a person leaves, HR should be asking what they built, not only what they had access to. Add the question to the exit checklist this month.

A kill switch that has been tested. Not a plan to disable an agent. A recorded instance of someone disabling one and the business continuing to function.

The Acuity AI position

Agent governance is being sold as a platform problem, and there is a growing category of discovery tooling ready to price it that way. For most Irish organisations that is premature. At forty agents the constraint is not detection technology, it is that nobody has been asked to write the list.

Our position is unchanged: diagnose before prescribe. Before any organisation buys an agent governance platform, it should be able to answer what it runs, what those systems can reach, and who owns each one. That evidence takes days to assemble, not months, and it usually reveals that two of the agents are doing valuable work, one duplicates a process the firm already pays a vendor for, and one has access nobody would approve if asked today.

Firms that build the register while the number is small will spend the next two years governing agents. The rest will spend it looking for them.

agentic aiai governanceirelandboard advisoryoperational risk