Enterprise software vendors have spent the past few months converging on the same message, delivered independently by SAP, ServiceNow, and Microsoft: organizations have lost track of how many AI agents are actually running inside their environments, and that’s no longer an IT footnote. It’s a board-level risk.
What’s Happening
SAP laid out the problem plainly in an August briefing on its AI Agent Hub. Gartner analyst Max Goss, speaking at a London conference, described CIOs and IT leaders as increasingly confronting an unmanaged spread of agents across their organizations, one that opens the door to misinformation, unintended data exposure, and outright data loss. His warning included a pointed detail: organizations that respond by simply blocking or restricting agent use don’t solve the problem, they push employees toward unsanctioned shadow AI instead, which carries greater risk than the sanctioned tools they were trying to avoid.
This isn’t an isolated warning. It’s the third major vendor in 2026 to build a dedicated governance layer for exactly this problem. Microsoft shipped Agent 365, its “control plane for agents,” to general availability in May, priced at $15 per user per month, specifically to give IT and security teams a single place to inventory, observe, and govern agents regardless of which platform built them. ServiceNow used its own Knowledge 2026 conference to push its AI Control Tower deeper into Microsoft’s ecosystem and into infrastructure and security layers through recent acquisitions. SAP’s entry, AI Agent Hub, builds on the enterprise architecture foundation it gained through its 2023 acquisition of LeanIX, positioning agents, models, and connected systems within the organization’s existing architecture and business context rather than as a separate inventory.
Three different vendors, three different architectures, the same underlying diagnosis: nobody actually knows what their AI agents are doing, what they can access, or whether their outputs can be trusted.
Why This Is a Knowledge Management Problem, Not Just a Security One
It’s tempting to file this under security and compliance and move on. That would miss the more interesting part.
An AI agent doesn’t generate risk in a vacuum. It generates risk when it acts on information that’s outdated, contradictory, incorrectly scoped, or simply wrong, and does so with more confidence and less friction than a human would. Governance tools like Agent 365 or AI Agent Hub can tell you which agent touched which system and when. They cannot tell you whether the knowledge that agent retrieved was actually accurate, current, or authoritative. That’s a knowledge management problem wearing a security vendor’s badge.
This is the same diagnosis KM practitioners have been making about generative AI generally, now playing out at agent scale, where the stakes are higher because agents act rather than merely answer. A chatbot that retrieves a stale policy document produces a wrong answer a human can catch and correct. An agent that retrieves the same stale document and acts on it, updating a record, sending a communication, approving an exception, has already caused the damage before anyone notices.
The governance platforms being built right now handle the “who did what” layer. They largely assume the “was it right” layer is someone else’s problem. For most organizations, that someone else is, or should be, the knowledge management function, and most KM functions were not built with agent-scale consumption in mind.
What This Means for KM Teams
A few practical implications worth sitting with:
Governance platforms are necessary but not sufficient. If your organization adopts Agent 365, AI Control Tower, or AI Agent Hub, that solves visibility and access control. It does not solve whether the knowledge base those agents draw from is accurate, deduplicated, and current. Don’t let a governance rollout create false confidence that the knowledge quality problem is handled.
Content ownership and staleness detection matter more, not less. Every one of these platforms depends on structured, well-governed source content to be effective. An agent operating under perfect access controls can still confidently execute on wrong information if nobody owns the accuracy of that information.
This is a genuine opening for KM to claim a seat at the AI governance table. Security and IT are moving fast on agent governance right now, largely without KM in the room. Practitioners who can articulate the knowledge-quality half of this problem, not just the access-control half, have a real opportunity to shape how these programs get built rather than inheriting requirements after the fact.
The Broader Pattern
This fits the pattern that’s dominated enterprise AI coverage through 2026: initiatives that were framed as AI problems keep turning out to be knowledge problems underneath. Gartner has separately predicted that a substantial share of agentic AI projects launched this year will be abandoned within roughly a year of launch, cost overruns and unclear ROI cited alongside governance gaps as the reasons. The vendors racing to ship agent governance platforms are responding to a real and urgent problem. Whether that problem gets solved depends on whether the knowledge underneath those agents gets the same level of investment as the control plane sitting on top of it.