150,000 AI Agents Per Company by 2028

The Scale Problem Coming

Gartner projects that by 2028, the average Fortune 500 company could run 150,000 AI agents across its enterprise tech stack. That scale changes what governance actually needs to cover. As Jack Nelson, CISO deputy general counsel at Ivanti, puts it, when a generative AI tool outputs a flawed summary, a human editor can catch it, but when an agentic system changes a system configuration, alters permissions, or executes code, a bad decision happens at machine speed with instant, real-world consequences. The risk has shifted from content being wrong to actions being wrong, and most governance frameworks were built for the former.

Why This Matters for BFSI and Collections

Ivanti’s research found that while 85% of organizations believe someone owns every AI workflow, only 42% say accountability is clearly defined, and just 24% say AI policies are consistently followed day to day. That gap between believed and actual ownership is where a collections deployment runs into trouble. An agent updating account status, triggering a payment workflow, or modifying case permissions is closer to what Nelson calls a privileged employee than a content tool. It needs the same activity logging, execution boundaries, and fail-safe mechanisms a bank would expect of any staff member with access to customer financial systems.

What the Numbers Do Not Say Out Loud

The more overlooked risk here is not the agents an organization deliberately deploys; it is the ones it does not realize it has. Nelson describes an unintentional form of shadow AI: a routine software update to an approved platform can quietly introduce a new AI-powered feature that accesses enterprise data or automates a workflow, without going through the risk review a formal deployment receives. For a collections operation running CRM, dialer, and case-management systems from multiple vendors, an agentic capability could start touching customer financial data through a feature update nobody explicitly approved. Kelsey Brazil of PO Security adds a second risk: authority creep, where an agent introduced for one narrow task gradually accumulates access to more data sources and permissions as new use cases get layered on. As she puts it, the risk is not autonomy itself; it is an agent quietly accumulating more authority than anyone realizes.

The Practical Read

For collections and BFSI operations, this points to two concrete practices worth adopting now. First, evaluate every agent’s autonomy against reversibility and blast radius, not convenience. Routine data entry and log triage are reasonable candidates for full autonomy, while financial transactions, permission changes, and identity-related actions need human review built in. Second, treat every SaaS platform update as a potential new agent deployment. That means requiring vendors to disclose new AI capabilities in release notes and subjecting those features to risk assessments. As Nelson notes, you do not give a new hire admin access on day one. The same discipline needs to apply to every agent running inside your systems.

[Read the full report]

Related Post

Two-Thirds of Enterprises Are Scaling AI Without Any Way to Measure If It Is Working

The Finding New research from TELUS Digital’s Enterprise CX AI: 2026 Global Survey, polling 815 enterprise decision-makers across 12 countries, finds that 61% of organizations now spend over $10 million annually on CX delivery. Yet only 32% have the automated QA infrastructure needed to actually measure how that AI is performing. As Peter Ryan, President […]

64% of Customers Want an Escape Hatch From AI, and the Data Shows Why

The Market Is Moving Faster Than Enterprises Can Integrate It Global AI market spend is projected to grow from 189 billion dollars in 2023 to 4.8 trillion dollars by 2033, according to UN Trade and Development, and businesses are inserting voice AI into customer journeys faster than most can properly integrate it. The stakes of […]

McKinsey’s 2026 AI Trust Survey Discovery

The Maturity Gap Behind the Headlines McKinsey’s 2026 AI Trust Maturity Survey, based on responses from roughly 500 organizations collected between December 2025 and January 2026, found the average responsible AI maturity score rose from 2.0 to 2.3 year over year. But that improvement masks an uneven picture: only about 30% of organizations reached a […]