3 min read

The register that lies

The register that lies

 

We turned on Microsoft's agent control plane in our own tenant when it launched in May. I asked our CTO whether it was working. His answer was the most useful sentence anyone said in that meeting: "Define working. It's running, I'd say."

Then came the number. Four hundred and something agents sitting in the registry of a forty-person business. Almost none of them were ours. Nobody here had chosen them, briefed them, or written down what they were for.

And the one agent I most wanted to see — a pro-code agent our own engineers built, published into Teams, doing real work — was not listed at all. We have a ticket open about it.

 

Why this matters now

Agent governance stopped being a slide this year and became a line item. Microsoft's Agent 365 reached general availability on 1 May 2026 at fifteen US dollars per user per month, or inside the new E7 bundle. Every AI management standard, ISO 42001 included, opens with the same requirement: know which AI systems you are running and who owns each one. We have just been through that audit ourselves. The inventory is not an advanced control. It is the first one.

So the market has settled on a tidy consensus — you cannot govern what you cannot see — and has priced a product against it. What nobody selling that product will tell you is what the inventory actually looks like on the day you switch it on.

 

It is wrong in both directions

A noisy register is a nuisance. A register that is noisy and incomplete is worse than no register at all, because it produces a document you can take to a board.

Ours over-reports badly. Platform-supplied entries nobody in the business had asked for sit alongside the handful we deliberately built. And it under-reports, which is the half that should worry you: the agent written by our own team, running in the tool our staff use every day, does not appear. That is not a misconfiguration I can fix at my end.

Then there is the discovery nobody plans for. During a routine device clean-up we found machines in our management estate that nobody recognised: four virtual CPUs, sixteen gigabytes of memory, a quarter of a terabyte of disk, being swept up by a dynamic group as ordinary Windows devices. They turned out to be hosted agent machines. Compute we had created ourselves, by building agents, and had never once thought of as endpoints.

That is the real shape of agent sprawl in a mid-sized business. Not a rogue employee with a personal account. Infrastructure that arrives as a side effect of a product decision and lands in the one place nobody is reading.

 

What organisations get wrong

They treat the inventory as the control. It is not. It is the input to a control, and it needs a second thing no platform ships: a named human who can say what the agent is for, what it is allowed to touch, and what happens when it is wrong.

Our head of AI transformation put the sharper version of this to me last week. When one person builds an agent and a colleague then uses it, the second person inherits instructions, guardrails and context they have never read. Our control for that today is a recurring service ticket to review them. She asked the leadership team, plainly, whether that was enough. We said yes, for now. "For now" is carrying a great deal of weight in that sentence, and I would rather write it down than pretend otherwise.

 

And if you are a provider, as I am

We sell AI governance. Our own registry is noisy, our own hosted agent machines surprised us during a clean-up, and I learned both by asking a question in a meeting rather than from a report. That is not a confession, it is the state of the art, and the honest thing a provider can do is say so out loud before a client finds it in their own tenant.

The uncomfortable part is what it says about our reporting. If a monthly report tells a client their patch compliance but not how many entries in their agent registry have a named owner, it is measuring the thing that stopped being the risk. We are changing ours. It should not have taken switching on a register in our own tenant to notice.

 

Three questions before you buy the control plane

Who is the named owner of each agent in your registry — not the team, the person? If that column is empty, you are holding an asset list, not a governance position.

Which agent that you know is running does not appear? Ask the people who have built one. The gap between what is running and what is listed is your real exposure, and it will not show up in anyone's demo.

What compute have your agents created? Search your device estate for machines nobody recognises before you search your tenant for agents nobody approved.

A register tells you what a platform can see. Governance begins with what it cannot, and that part is still a person writing something down.