150,000 AI Agents Per Company by 2028

The Scale Problem Coming

Gartner projects that by 2028, the average Fortune 500 company could run 150,000 AI agents across its enterprise tech stack. That scale changes what governance actually needs to cover. As Jack Nelson, CISO deputy general counsel at Ivanti, puts it, when a generative AI tool outputs a flawed summary, a human editor can catch it, but when an agentic system changes a system configuration, alters permissions, or executes code, a bad decision happens at machine speed with instant, real-world consequences. The risk has shifted from content being wrong to actions being wrong, and most governance frameworks were built for the former.

Why This Matters for BFSI and Collections

Ivanti’s research found that while 85% of organizations believe someone owns every AI workflow, only 42% say accountability is clearly defined, and just 24% say AI policies are consistently followed day to day. That gap between believed and actual ownership is where a collections deployment runs into trouble. An agent updating account status, triggering a payment workflow, or modifying case permissions is closer to what Nelson calls a privileged employee than a content tool. It needs the same activity logging, execution boundaries, and fail-safe mechanisms a bank would expect of any staff member with access to customer financial systems.

What the Numbers Do Not Say Out Loud

The more overlooked risk here is not the agents an organization deliberately deploys; it is the ones it does not realize it has. Nelson describes an unintentional form of shadow AI: a routine software update to an approved platform can quietly introduce a new AI-powered feature that accesses enterprise data or automates a workflow, without going through the risk review a formal deployment receives. For a collections operation running CRM, dialer, and case-management systems from multiple vendors, an agentic capability could start touching customer financial data through a feature update nobody explicitly approved. Kelsey Brazil of PO Security adds a second risk: authority creep, where an agent introduced for one narrow task gradually accumulates access to more data sources and permissions as new use cases get layered on. As she puts it, the risk is not autonomy itself; it is an agent quietly accumulating more authority than anyone realizes.

The Practical Read

For collections and BFSI operations, this points to two concrete practices worth adopting now. First, evaluate every agent’s autonomy against reversibility and blast radius, not convenience. Routine data entry and log triage are reasonable candidates for full autonomy, while financial transactions, permission changes, and identity-related actions need human review built in. Second, treat every SaaS platform update as a potential new agent deployment. That means requiring vendors to disclose new AI capabilities in release notes and subjecting those features to risk assessments. As Nelson notes, you do not give a new hire admin access on day one. The same discipline needs to apply to every agent running inside your systems.

[Read the full report]

Related Post

When 66% of Enterprises Deploy AI Agents Without Human Review

A June 2026 VB Pulse survey of 157 enterprise respondents found that half of organizations have shipped an AI agent or LLM feature that passed internal evaluation and still caused a customer-facing failure. One in four experienced this more than once. Despite that, 66% already permit production deployment without human review or are building toward […]

When AI Agents Take Action, Mistakes Stop Being Content Errors and Start Being Consequences

The Announcements Google Cloud Summit London 2026 brought a wave of partnership news signaling a shift from AI experimentation to production deployment. HSBC and Google Cloud announced a partnership to deploy more than 200 new AI use cases over the next two years, focused on hyper-personalized wealth management and financial crime detection. Deloitte and Google […]

A Credit Union Saved $1.6M by Making AI Listen

The Deployment Agentforce, Salesforce’s agentic AI platform, has crossed $1 billion in annual recurring revenue, with revenue up 205% year over year. But the more instructive story sits inside one specific deployment: PenFed Credit Union now runs its entire operation (call center, mobile, web, and branches) on Salesforce, with 76 AI agents working alongside human […]