If you run a small business, “AI agent sprawl” probably sounds like someone else’s problem. It has the ring of a Fortune 500 headache, the sort of thing a company of fifty thousand people frets about while you get on with the actual work. And the numbers coming out of the big firms do nothing to dispel that. DaVita, the American kidney-care company, recently found that its staff had built more than ten thousand AI agents. FICO has 3,500 employees spinning up dozens of fresh ones every day, at every tier of the org chart. You haven’t got ten thousand of anything. So why would sprawl ever be your problem?

Because the thing that saves DaVita from its own mess is precisely the thing you don’t have.

DaVita has a CIO. It has an IT function whose whole job is to spot something multiplying out of control and put a fence round it. That’s why, when the Wall Street Journal ran the agent-sprawl story this spring, it could write it up as a CIO problem — by then it was a recognised management category, with whole teams pointed at corralling the swarm. The small business has none of that. What it has instead is an owner — you, probably — who set up three or four Claude projects himself, nudged the team to do the same, and now assumes that because he signed off on all of it, it must be in hand.

That assumption is the trap.

The sanctioned version is the dangerous one

A while ago I wrote about shadow agents — the unsanctioned kind, the ones an employee wires up to company systems on a personal laptop without telling anyone. That’s the version everybody worries about, because it sounds like a security breach waiting to happen, and it is. But the sanctioned version is sneakier, and for a small business it’s the bigger risk.

Shadow AI at least announces itself as a problem. Nobody thinks an unapproved agent running on someone’s home Wi-Fi is fine. The sanctioned agents are different. You built them on purpose. You’re a bit proud of them. The invoice-chaser, the inbox-triager, the little one that drafts your social posts — each was a good idea, each solved a real problem, and each is doing its job. The trouble isn’t any single agent. It’s that nobody ever decided how they’d behave as a group, because at the time there was no group. There was just a run of sensible decisions, each made on its own, that has added up to a system no one is actually managing.

Small doesn’t mean safe

Scale is where the intuition fails. Sprawl has surprisingly little to do with the number of agents you’re running. What matters is how many of them touch each other, and how few people are watching when they do.

Sarah Wooders, who co-founded the agent company Letta, describes wiring agents up to one another as being “like connecting two humans together via Slack”. It’s a lovely way to put it, and it should worry you slightly. Because the moment two agents can message each other, you’ve built an organisation. A tiny one, but a real one, with handoffs and dependencies and the capacity to fall into a loop where one agent triggers another that triggers the first, all night, running up a bill while you sleep. Ten thousand agents at DaVita are mostly isolated tools doing isolated jobs. Three agents in your business that all read and write to the same Slack channel are an org chart with nobody in charge of it.

Owners get this exactly backwards: they assume a handful of agents is self-evidently controllable. But a handful with no named owner, no off-switch and no record of what calls what isn’t more controllable than ten thousand. It’s just smaller, and unwatched. I don’t know exactly where the tipping point sits for a small team — three agents, ten, twenty — and I suspect it depends far more on how interconnected they are than on the raw count. It’s the wiring that gets you, not the headcount.

A containment protocol you can actually run

The good news is that the fix doesn’t need a platform or a CIO. It needs three decisions, and a small business can make all three in an afternoon — which is the one real advantage you hold over DaVita.

  1. Name the orchestration owner. One person — probably you, to start with — owns the question of how the agents behave as a system. Not how any single agent works, but how they fit together: who’s allowed to create a new one, what it’s permitted to touch, and where the list of them lives. The moment nobody owns that question is the moment sprawl begins.
  2. Give every agent a termination date. An agent with no end date is a standing liability, the same way a dormant login is. When you build one, write down the date you’ll review whether it’s still earning its keep. Most won’t be. The half-finished experiment from March is still running in June, still holding credentials, still costing you — not because anyone decided it should, but because nobody decided it shouldn’t.
  3. Audit the agent-to-agent calls quarterly. Once a quarter, sit down and map what talks to what. You’re hunting for the loops, the duplicates (two agents doing the same job and disagreeing about the answer), and anything reaching a system you’d forgotten it could reach. It takes an hour. It’s the hour that stops the org chart you never meant to build from running itself.

None of this is clever, and that’s the point. The enterprise version of this problem needs dedicated tooling and a six-step Gartner framework because the enterprise let it reach a hundred and fifty thousand agents first — which, Gartner reckons, is roughly where the average Fortune 500 will be by 2028, up from fewer than fifteen in 2025. You’re being handed the chance to do the boring discipline while your numbers are still small enough to hold in your head.

It’s the same overconfidence I’ve written about elsewhere: most owners are convinced their AI is further along, and better behaved, than it really is. Sprawl is what that conviction looks like a year later.

The advantage you’re being handed

Using agents was never the problem, and waiting until you feel completely ready isn’t a strategy — the productivity is real and your competitors aren’t pausing. What gets you is the quiet assumption that because the agents are yours, sanctioned and few, they must therefore be under control. Sprawl doesn’t arrive as one bad decision. It arrives as a dozen good ones that nobody ever looked at together. Do the boring hour of discipline now, while the whole thing still fits in your head, and you hold on to the advantage the big firms are spending millions to win back.