Agent Sprawl: The New Startup Ops Headache Nobody Budgeted For
The API token had one job: adding and removing custom domains for PocketOS, which makes booking software for car rental businesses. Nobody on the team realized it could do anything else.
In April 2026, a Cursor coding agent running Anthropic’s Claude Opus 4.6 found out. Hitting a credential mismatch in staging, the agent decided to fix it on its own, founder Jer Crane wrote in a post on X . It went looking for a key, found that token in an unrelated file, and used it to delete a storage volume on Railway, the company’s infrastructure provider. The volume was production. The token turned out to be scoped for every operation, and Crane said the team wouldn’t have stored it had they known. Railway kept backups on the same volume, so they went too. The whole thing took about nine seconds. Railway later helped restore the data, but not before an outage that rippled out to PocketOS’s rental-company customers.
Asked to explain itself, the agent admitted it had guessed instead of verifying. But the model’s judgment is only half the story. The other half is an overpowered credential sitting in a file any tool could read. That’s agent sprawl at startup scale. Not hundreds of rogue bots. One agent with more access than anyone knew it had.
Agent sprawl is the uncontrolled multiplication of AI agents across a company’s teams and tools, with no shared inventory of what exists, who owns it, or what it can touch. It sounds like an enterprise IT problem. It isn’t only one, and startups have the least staff to catch it.
At a big company, a security team eventually finds the agents nobody approved. At a startup, a typical version looks like this: the head of ops learns in a Monday standup that sales built a lead-qualification bot three months ago, support built a near-identical one for renewals, and nobody told finance either one has a paid API key attached. A 30-person company has no CISO , only a Slack channel where “we should probably track this” gets said a lot and acted on rarely.
Even IT teams are losing count. In a Morning Consult survey of 362 U.S. IT decision-makers for agent-management company Guild.ai, fielded in August 2026 , 96% said they were confident in their agent inventory. Yet two-thirds of companies running agents had an agent-related incident in the past year, only 36% require agents to be registered before deployment, and 61% think employees are likely launching agents without approval. The number founders should notice: companies with 20 to 199 engineers reported incidents at 78%, versus 43% for the smallest teams. That’s the stage where a startup stops fitting in one Slack channel. Other research agrees: in an SAP LeanIX survey this summer, fewer than half of companies could see an inventory of their agents.
Low-code tools mean building an agent no longer takes an engineer. Anyone with a Zapier login and a Saturday afternoon can wire one up. And unlike an unapproved app, the agent keeps running after its builder moves on.
Unmanaged AI spend ran 4% to 9% of enterprise software budgets by mid-2025, typically two to three times the official AI budget line, according to an August 2026 Redress Compliance report drawn from the firm’s own audits. At a five-person startup, subscriptions scattered across personal cards can quietly add up to a few hundred dollars a month, buried under “software” or “miscellaneous.”
The bigger cost is what agents can reach. Among 602 breached organizations in IBM’s 2026 Cost of a Data Breach Report, published in July, 68% had no policy to govern AI or detect shadow AI, and only 38% required IT approval before deploying AI, Security Management reported . Startups have the same gap at smaller scale. Just ask PocketOS.
Most of these figures come from vendors selling fixes, so treat them as directional.
Signs it’s already happening
- Two teams built near-identical agents and found out by accident. 61% of teams in the Guild.ai survey lose time to this.
- Nobody can list every agent, its owner, and what it touches.
- An agent has production or customer data access, and its builder has left or switched roles.
- AI charges show up under three or more expense categories.
- API keys sit in code or config files an AI coding agent could read.
If two of these sound familiar, you already have agent sprawl.
The fix is a list, not a platform
Enterprise advice assumes a security team and a budget. Startups need something smaller and uglier.
Start with one spreadsheet: name, owner, purpose, data access, and vendor for every agent. Assign each agent a real person, not a team, who’s on the hook if it misbehaves. Kill anything nobody will claim. Most sprawl isn’t malicious, it’s orphaned.
Give every agent its own credential, never a login borrowed from whoever built it. Scope each one to the narrowest job it needs, keep keys out of files an agent can read, and set credentials to expire every 90 days so a human has to renew them. Then spend 30 minutes a month reading the list out loud.
A 15-person startup with four agents doesn’t need an enterprise security platform. That changes once agents touch payment data, health information or anything regulated, or once the founder can no longer name every agent from memory. That’s when a dedicated agent identity or security tool starts earning its cost.
Agent sprawl doesn’t announce itself. You find out in a standup, on a card statement, or in nine seconds.
So pull the list together this week: every agent, every owner, every credential. Then ask one question of each: what’s the worst it could do with the access it has right now? PocketOS’s agent didn’t need bad intent. It just needed a key nobody knew could open that door.