
If your teams have access to the Microsoft 365 Agent Builder, Copilot Studio or the Agents Toolkit, you can pretty much guarantee that enterprising staff have created a whole host of handy agents to help them do their jobs.
This is a good thing. Letting people build agents makes them more productive and helps solve problems.
But this is powerful technology. And many organizations have deployed it across their environments without enough checks and balances which creates major governance and security headaches. Thousands of organizations are exposing themselves to serious risks, without even knowing it.
The good news is that addressing this issue might be easier than it first looks.
The workforce you never interviewed
AI agents are, effectively, a hidden workforce at your business. You might not bump into them at the coffee machine on a rainy Tuesday afternoon, but they are definitely there, working hard.
Agents are carrying out tasks across your IT estate, working as secretaries, analysts, customer service reps and much more. They’re interacting with your company’s data, records, apps and spreadsheets. They can send emails, visit websites and gather information, review financial data and, some make autonomous decisions.
The number of agents at businesses is growing at an astonishing rate. In May 2026, Microsoft used its own data to report that there has been a 15x year-on-year growth in active agents in the M365 ecosystem over the previous year. And in large organizations, the growth was 18x.
A Microsoft-sponsored IDC study published in February 2026 found that 80% of Fortune 500 companies are using active AI agents (agents that do things like draft proposals, analyze data or surface information). It’s unclear how many agents an average organization has running, although one December 2025 survey with 750 CISOs found a mean of 37 agents.
It is also very easy for employees to create agents – many organizations are actively encouraging them to do so. As people see the value of these tools, and get more confident building them, more and more agents are being spun up and put into production. Organizations will have swarms of them in future. Indeed, the IDC study predicted that there will be 1.3 billion agents at businesses worldwide by 2028.
This is a different class of risk
The arrival of agentic AI is undeniably a net positive for individual workers, as well as wider businesses. But it also introduces a new class of security, governance and regulatory risk that many organizations are struggling to grapple with.
Unlike earlier automation technologies (such as workflow automation tools), agents can make decisions and take actions autonomously. They read, write, send, modify and delete at machine speed, often with minimal human input. This introduces some major risks. To illustrate this, consider the following example.
Permissions problems
An HR admin builds an agent to answer a common question people email the HR department about: “How many days’ leave do I have left this year?”
Due to a lack of awareness, the admin gives the agent access to the entire HR SharePoint library as its ‘knowledge base’ – rather than a specific spreadsheet that tracks staff annual leave. That library also holds everyone in the company’s contracts and salaries.
An employee is interacting with the bot and asks if it can tell him whether taking extra leave might affect his bonus. The annual leave spreadsheet doesn’t contain this information, but the bot helpfully reviews the employee’s own contract and comes back with an answer. He realizes the bot might be able to answer similar questions about his colleagues’ salaries.
It’s just too tempting.
In no time at all, he’s accessing a trove of private information.
Traditional security tooling and processes aren’t built for agentic risks
For many years, security operation center (SOC) tools and processes were built on a reasonable assumption: the actors that generate telemetry are human (with the exception of DDoS attacks).
Security staff would spend their time looking for signs of suspicious behavior that suggest a human is up to no good, things like:
- Multiple failed login attempts
- Logging on from unusual locations or at unusual times
- People trying to access folders they don’t usually open
- Large downloads
- Opening links to visit unusual websites.
Agentic AI undermines this approach. When organizations have tens, hundreds, or even thousands of agents autonomously carrying out tasks, monitoring for suspicious behavior becomes much harder.
Take our simple example of an over-provisioned HR bot.
In the past, if a non-HR person was trying to find out what their colleagues earned, the telemetry would show up some obviously suspicious activity (trying to open SharePoint sites they don’t have permissions for, or – if they’d stolen a password – downloading files they don’t usually look at).
But with a poorly permissioned HR bot (as in our example above), the breach runs through the agent and would not be flagged as suspicious.
The second major challenge is that managed detection and response tools do not ingest agent-specific telemetry.
They collect endpoint signals, identity sign-in events, email threats, and cloud configuration data. What they are not collecting is the audit record of what an agent accessed, what it sent, what it modified, and what instruction it acted on.
Without that telemetry, an agent can be compromised, misdirected, or operate outside its defined scope and the security team will see nothing unusual because they are not looking at the right data source.
Should we ban AI agents then?
Of course not.
These tools are simply too helpful, too valuable to do without. Teams that use AI agents often notice significant improvements in productivity, save lots of time and create high performing workplaces.
Rather than block their teams from setting up agents, SOCs need a sensible, proportionate way to govern them. At present, too many businesses have simply opened the floodgates without a coherent plan to manage the risks.
It starts with visibility. You need to know what your agents are doing, and what permissions and access they have. You then need a baseline of controls that makes your agent deployment defensible.
There isn’t one individual security point solution that will ‘fix’ this issue.
Rather, it’s about putting in place a coherent strategy. Fortunately, any organizations with a Microsoft 365 E5 or E7 license already has the tools to do this. With Microsoft’s products, it’s possible to adapt your security posture to ensure your organization is ready and adapted for the agentic era.
AI agents can improve productivity, but without visibility, scoped permissions and agent-specific telemetry, they can create serious security, governance and compliance risks. Start by identifying the agents operating across your environment, who owns them, what they can access and which actions they can take. Then establish a proportionate baseline of controls and ongoing monitoring. SoftwareOne can help you assess your current position and build a practical governance approach for AI agents across Microsoft 365.

Solve your AI agent problem
In our new eBook, we explain just how you can begin doing that. Access the free guide now and learn how to solve your AI agent problem.
Solve your AI agent problem
In our new eBook, we explain just how you can begin doing that. Access the free guide now and learn how to solve your AI agent problem.



