Agent 365: governance before scale
We ask the same question in every meeting: how many agents are active in your Microsoft 365 tenant right now? The answer is almost always some variation of “we do not know exactly”. That is not carelessness. It is a consequence of agent creation being made so easy that any user with Copilot Studio rights can build one in an afternoon, without anyone else in the organization hearing about it.
A number worth pausing on: the count of active agents in Microsoft 365 environments has grown fifteen-fold over the past year. At the same time, the cost of an AI interaction has risen from about $0.04 to as much as $1.20 per task in more complex agent chains. And 57 percent of organizations report a rise in AI-related security incidents. These three numbers tell the same story from three directions: agents appear faster than anyone can govern them.
Shadow agents are shadow IT again, only faster
Many IT leaders have seen this movie before. Shadow IT, employees adopting their own cloud services without IT’s knowledge, was the risk of the 2010s. Agents are the same phenomenon, accelerated. A single employee can build an agent in Copilot Studio that reads emails, pulls information from documents or writes to customers, and do it without anyone validating what it has access to or what it does with that information.
The problem is not that someone builds a useful agent. The problem is that no one else knows the agent exists until either an audit reveals it or something goes wrong. Neither is a good moment to notice for the first time.
Costs run away as quietly as risks
The other thing that surprises almost every organization is the cost structure. Cowork and other agents consume Copilot Credit tokens per executed task, and the consumption is not linear. A multi-step agent chain that pulls information from several sources and makes several decisions along the way can cost a multiple of a single Copilot prompt. Without budget limits and monitoring, the monthly invoice can be significantly larger than forecast, and this is usually noticed on the invoice, not before it.
This does not mean agents should go unbuilt. It means cost control needs to be designed before wide use, not after the first surprise invoice has already arrived.
Why the governance model comes first, not after scaling
The most common mistake we see: the organization decides to “try” agents with a few pilot projects, notices they work, and scales use fast, without anyone having decided who owns the agent registry, who approves new agents into production, or how consumption is budgeted per role. When the governance model is built only after the problems appear, it is always reactive and always more expensive than if it had been built in from the start.
The working order is the opposite: first visibility, then rules, only then scale.
Visibility means a tenant assessment: what agents already exist, who owns them, what they have access to. This alone usually reveals more than the organization expects.
Rules mean a written Agent Governance Policy: who may build agents, what access they get by default, how they are reviewed before production, and how token budgets are divided by team. This is not bureaucracy for its own sake. It is the same logic as access management in general: the default is restricted, not open.
Scale comes only once the first pilot agent has been taken to production under governance, its consumption and impact have genuinely been followed for a few weeks, and the organization has a roadmap for the next twelve months. At that point expanding is predictable, not guesswork.
What this means in practice
We are not suggesting agents should be slowed down. The opposite: the competitive edge comes from being able to adopt agents faster than competitors, because the governance model already exists and does not need to be built in the middle of a crisis. A ninety-day program that takes the organization from a current-state review to a governance model and one pilot agent in production is not dawdling. It is the fastest way to a place where agents can genuinely be scaled without every new agent being a new risk no one has seen yet.
The question is no longer whether agents should be adopted. That is already happening, whether the organization notices or not. The question is whether it happens visibly and under governance, or whether it gets discovered in an audit.