Gartner estimates that by 2028, the average Fortune 500 enterprise will have more than 150,000 AI agents in use β up from fewer than 15 in 2025. Yet only 13% of organizations believe they have the governance in place to manage them. That gap β between agent proliferation and agent governance β is the defining operational risk of the agentic AI era, and it is the problem SAP AI Agent Hub was built to solve.
- What Is Agent Sprawl and Why Should You Care?
- SAP AI Agent Hub: Architecture and Capabilities
- How SAP AI Agent Hub Fits Into the Broader Joule Ecosystem
- Joule: The Agentic Foundation
- Joule Studio: The Builder
- Joule Work: The Agentic Harness
- The Architecture Stack
- Gartnerβs Six-Step Framework for Managing Agent Sprawl
- Practical Implications for Agentic AI Architects
- 1. Governance Is Now a Design Requirement, Not an Afterthought
- 2. Multi-Vendor Governance Will Become Table Stakes
- 3. The MCP and A2A Standards Enable Governance at Scale
- 4. Forresterβs Caution: Concentration Risk Is Real
- 5. The RPA-to-Agent Governance Continuity
- SAP AI Agent Hub vs. Competing Approaches
- Getting Started: A Practical Checklist
- Frequently Asked Questions
- What is SAP AI Agent Hub?
- What is AI agent sprawl?
- Does SAP AI Agent Hub work with non-SAP agents?
- How does SAP AI Agent Hub differ from Microsoft Copilot Studio governance?
- Is SAP AI Agent Hub free?
- Key Takeaways
- References
The SAP LeanIX Agentic AI Survey 2026 puts the adoption numbers into sharper focus: 98% of companies have either deployed AI agents or plan to. But fewer than half have visibility into a basic inventory of what agents exist, who owns them, and what they can access. Teams deploy agents independently β a marketing automation agent here, a supply chain monitoring agent there, an HR onboarding bot somewhere else β and each works in isolation. Without a centralized governance framework, the organization accumulates a fragmented landscape of agents that cannot be audited consistently, do not interoperate, and generate technical debt faster than they generate value.
This pattern has a name: agent sprawl. And SAP, through its 2023 acquisition of LeanIX and the broader Joule agentic platform, is making a deliberate play to become the governance layer of record for the enterprise agent ecosystem.
This guide breaks down what SAP AI Agent Hub actually does, how it fits into SAPβs broader agentic architecture (Joule, Joule Studio, Joule Work, MCP, A2A), what the Gartner framework for agent governance looks like in practice, and what every agentic AI architect should consider when evaluating governance platforms in 2026.
What Is Agent Sprawl and Why Should You Care?
Agent sprawl occurs when AI agents are created, deployed, or connected across systems faster than the enterprise can inventory them, assign ownership, control permissions, monitor behavior, and retire them when they are no longer fit for purpose. It is the agentic equivalent of shadow IT β except agents do not just store data or run reports. They take actions: calling tools, accessing systems, initiating business processes, and making decisions with real financial and operational consequences.
The mechanics are familiar to anyone who has navigated a wave of SaaS adoption. Individual teams, motivated by genuine productivity goals, deploy agents independently. Each agent is designed for a specific task. Each works in isolation. The organization accumulates a fragmented landscape without centralized oversight.
What makes agent sprawl more dangerous than SaaS sprawl is the difference in blast radius. As SAPβs August 2026 analysis frames it: with chatbots and early generative AI, a security failure typically meant bad output β an inaccurate response that could be corrected after the fact. In the agentic era, the consequences of an agent failure or security breach are far more damaging because agents can execute transactions, delete records, and trigger irreversible workflows.
Publicly reported incidents already illustrate the risk: malicious prompt injections causing agents to bypass guardrails, agents leaking sensitive data through over-permissioned tool access, and rogue agents triggering unintended financial transactions. These are not theoretical scenarios β they are documented failure modes that governance frameworks are specifically designed to prevent.
The Numbers Behind the Sprawl
| Metric | Value | Source |
|---|---|---|
| Projected agents per Fortune 500 enterprise by 2028 | 150,000+ | Gartner (April 2026) |
| Agents per Fortune 500 enterprise in 2025 | Fewer than 15 | Gartner (April 2026) |
| Organizations with deployed or planned AI agents | 98% | SAP LeanIX Agentic AI Survey 2026 |
| Organizations with agent inventory visibility | Less than 50% | SAP LeanIX Agentic AI Survey 2026 |
| Organizations with adequate agent governance | 13% | Gartner (April 2026) |
| Enterprise apps with task-specific AI agents by end of 2026 | 40% | Gartner forecast |
The message is clear: agent deployment is outrunning governance by an order of magnitude. The organizations that solve this gap first will scale AI as a durable competitive advantage. Those that defer will spend 2027 cleaning up β and with agents, the cost of speed without structure arrives faster and at greater scale than anything that has come before.
SAP AI Agent Hub: Architecture and Capabilities
SAP AI Agent Hub is a vendor-agnostic command center built on top of SAP LeanIX Application Portfolio Management. It provides a single entry point for discovering, governing, and managing AI agents, large language models (LLMs), and Model Context Protocol (MCP) servers across the entire enterprise landscape β regardless of which vendor built or hosts them.
This is not a marketplace for buying agents. It is not a development platform for building them. It is a governance layer that sits above all of those things and answers the questions that matter most to CIOs, compliance officers, and enterprise architects: What agents exist in our organization? What can they access? Who owns them? Are they compliant? Are they performing?
Auto-Discovery Across Vendors
The Agent Hub automatically discovers AI agents, LLMs, and MCP servers from SAP, Microsoft, Google, AWS, Databricks, and ServiceNow. Built-in integrations with these major AI agent repositories provide an overview of available agents, while a dedicated API using the Agent-to-Agent (A2A) protocol allows organizations to import in-house or custom-built agents into the same governed registry.
This cross-vendor discovery is the critical differentiator. Most agent platforms β Microsoft Copilot Studio, Salesforce Agentforce, Oracle AI Agent Studio β are excellent at governing their own agents within their own ecosystem. But real enterprises run agents from five or six different vendors simultaneously. The governance gap is not within any single platform; it is across all of them. SAP AI Agent Hub is designed to close exactly that gap.
Six Core Capabilities
SAP AI Agent Hub is structured around six capabilities, two of which reached general availability in early 2026, with the remaining four rolling out in Q3 2026:
1. Agent Discovery (GA). Auto-discovers agents across SAP and non-SAP environments. The discovery inbox lets teams select which agents to add to their governed inventory and relate them to existing applications, business capabilities, and IT landscape context within LeanIX.
2. Agent Inventory and Classification (GA). Organizes discovered agents into a searchable registry with classification, status, and a fact sheet for each agent. Teams can inventory available agents, track ownership, and map agents to the business processes they support.
3. Governance Assessment (Q3 2026). Structured workflows that capture risk ratings and compliance mappings for each agent. Nothing ships into production without a verified governance record. This is where the EU AI Act compliance requirements get operationalized β each agentβs risk classification, data access scope, and decision authority are documented and auditable.
4. Agent Identity and Access Control (Q3 2026). Each agent receives a unique identity through SAP Cloud Identity Services. This addresses one of the most common governance failures: agents operating with shared credentials or overly broad permissions. With individual identities, organizations can apply the same access control rigor to agents that they apply to human users.
5. AI Observability (Q3 2026). Session-level monitoring that provides visibility into what agents are actually doing in production β not just what they were designed to do. This includes detecting anomalous behavior, policy violations, and scope creep.
6. Performance Monitoring (Q3 2026). Ties agent performance to business KPIs, enabling organizations to measure ROI at the agent level and retire underperforming agents before they accumulate technical debt.
Pricing: Bundled at No Additional Charge
SAP CTO Philipp Herzig confirmed at SAP Sapphire 2026 that AI Agent Hub will be included in the SAP Business AI Platform at no additional charge. This is a significant pricing signal. By removing the cost barrier, SAP is positioning the Agent Hub not as a premium governance add-on, but as the default governance layer for any organization already running SAP β and, critically, as an attractive option for governing non-SAP agents as well.
The strategic intent is clear: if you are already an SAP customer, the marginal cost of using SAP as your cross-vendor agent governance layer is zero. That is a powerful argument in a market where competing governance tools are either nascent, siloed, or expensive.
How SAP AI Agent Hub Fits Into the Broader Joule Ecosystem
Agent Hub does not exist in isolation. It is one layer in SAPβs multi-layered agentic AI architecture. Understanding where it sits relative to Joule, Joule Studio, and Joule Work is essential for architects evaluating the platform.
Joule: The Agentic Foundation
Joule is SAPβs AI copilot and agent runtime, embedded across SAPβs cloud portfolio. As of mid-2026, Joule includes more than 40 specialized agents with over 2,400 skills spanning finance, HR, supply chain, procurement, and customer experience. These are pre-built agents that execute within SAPβs transactional systems β they are not external add-ons bolted on after the fact.
Joule Studio: The Builder
Joule Studio reached general availability in 2026. It is SAPβs no-code and low-code agent builder, enabling business users and developers to create custom agents with support for Model Context Protocol (MCP) and the Agent-to-Agent (A2A) protocol. This means custom-built Joule agents can interoperate with agents from Microsoft, Google, and other A2A-compliant platforms.
Joule Studio 2.0 added managed agent builder capabilities for citizen developers, lowering the barrier to agent creation. This is both an opportunity and a governance risk β more builders means more agents, which means more sprawl potential, which is exactly why Agent Hub exists as a complementary layer.
Joule Work: The Agentic Harness
Joule Work adds the agentic execution harness β computer and file access, MCP connectivity, and A2A orchestration for multi-agent workflows across heterogeneous environments. General availability for Joule Work and Joule A2A capabilities is planned for Q4 2026.
From Joule Work, customers can access Joule Studio to build custom agents that use MCP and A2A to draw on tools and third-party agents. The A2A protocol specifically standardizes direct, bidirectional communication between agents across vendor boundaries, enabling agents from different ecosystems to collaborate in shared business processes.
The Architecture Stack
| Layer | Component | Function | Status |
|---|---|---|---|
| Governance | SAP AI Agent Hub (LeanIX) | Discover, inventory, govern, monitor agents across all vendors | GA (partial); full Q3 2026 |
| Orchestration | Joule Work | Multi-agent workflows, A2A orchestration, agentic harness | Q4 2026 GA |
| Building | Joule Studio | No-code/low-code agent creation, MCP + A2A support | GA |
| Runtime | Joule | 40+ pre-built agents, 2,400+ skills, SAP-native execution | GA |
| Infrastructure | SAP BTP AI Foundation | Model hosting, SAP-ABAP-1 model, AI Core runtime | GA |
Gartnerβs Six-Step Framework for Managing Agent Sprawl
In April 2026, Gartner published a six-step framework for managing AI agent sprawl. It is vendor-neutral but maps remarkably well to what SAP AI Agent Hub delivers. Here is how each step translates to practice.
Step 1: Establish agent governance and policies. Set clear rules for when and how agents are built, who can create and share them, and what connectors are permitted. This is the βconstitutionβ layer β without it, every subsequent step is ad hoc. SAP AI Agent Hub operationalizes this through governance assessments with risk ratings and compliance mappings.
Step 2: Build a centralized agent inventory. Use AI trust, risk, and security management (AI TRiSM) tools to discover and categorize agents across applications β including agents from sanctioned tools and shadow AI. Agent Hubβs auto-discovery across six major vendors addresses this directly.
Step 3: Define agent identity, permissions, and lifecycle. Manage agent identity, permission models, and access controls. Review and retire redundant agents. Agent Hubβs Q3 2026 identity management via SAP Cloud Identity Services gives each agent a unique, governable identity.
Step 4: Develop AI information governance. Govern what information each agent can access. Ensure processes exist to keep data current, manage permissions to prevent oversharing, and archive data when obsolete. This is where the EU AI Actβs high-risk classification requirements intersect with operational governance.
Step 5: Monitor and remediate agent behavior. Establish ongoing visibility into agent usage, ensure policy compliance, detect anomalous behavior, and correct agents that exceed their intended scope. Agent Hubβs observability layer (Q3 2026) provides session-level monitoring for exactly this purpose.
Step 6: Measure and optimize. Tie agent performance to business outcomes and continuously optimize the agent portfolio. Agent Hubβs performance monitoring capability connects agent activity to business KPIs, enabling data-driven retirement and investment decisions.
Max Goss, senior director analyst at Gartner, captured the urgency at a London conference in April: βMany organizations resort to blocking or restricting the use of AI agents, but this is not a long-term solution. If employees are unable to work in the sanctioned tools, they will likely go around the organizationβs controls and start using shadow AI, which presents far greater risks.β
Practical Implications for Agentic AI Architects
If you are building or managing agentic AI systems in an enterprise, here is what the agent governance landscape means for your work in 2026.
1. Governance Is Now a Design Requirement, Not an Afterthought
The days of building an agent, deploying it, and figuring out governance later are ending. With the EU AI Act enforcement now live and Gartner flagging agent sprawl as a board-level risk, governance requirements need to be baked into agent architecture from the design phase. This means defining agent identity, data access scope, decision boundaries, audit trail requirements, and retirement criteria before the first line of agent code is written.
For RPA professionals transitioning into agentic AI, this is a familiar discipline. RPA centers of excellence have always managed bot inventories, access controls, and lifecycle governance. The difference is scale and autonomy β agents make decisions that bots never did, which means the governance surface area is larger and the consequences of failure are more severe.
2. Multi-Vendor Governance Will Become Table Stakes
No enterprise runs a single-vendor agent stack. The typical 2026 enterprise has Copilot Studio agents handling Microsoft 365 workflows, Agentforce agents in Salesforce CRM, custom LangGraph or CrewAI agents for specialized tasks, and possibly Joule agents in SAP ERP. Governing each platform in isolation creates the same fragmentation that agent sprawl describes.
Cross-vendor governance platforms β of which SAP AI Agent Hub is currently the most ambitious β will become essential infrastructure. The question is not whether you need one, but which one becomes your system of record.
3. The MCP and A2A Standards Enable Governance at Scale
The Model Context Protocol (MCP) and Agent-to-Agent (A2A) protocol are not just interoperability standards β they are governance enablers. MCP standardizes how agents connect to tools and data sources, making it possible to audit and control those connections centrally. A2A standardizes how agents communicate with each other, enabling governance layers to intercept, log, and validate inter-agent interactions.
SAPβs support for both protocols in Joule Studio, Joule Work, and Agent Hub means that agents built on MCP and A2A-compliant frameworks can be discovered, inventoried, and governed through a single pane of glass β even if they were built by different teams using different frameworks.
4. Forresterβs Caution: Concentration Risk Is Real
Not everyone is celebrating SAPβs governance play. Forrester has explicitly warned about concentration risk β the danger of giving a single vendor (SAP, in this case) governance authority over your entire multi-vendor agent estate. Their argument: if SAP becomes the governance gatekeeper, it has disproportionate influence over which agents are sanctioned, which are flagged, and how non-SAP agents are treated relative to SAP-native ones.
This is a legitimate architectural concern. Agentic AI architects should evaluate whether SAP AI Agent Hubβs vendor-agnostic claims hold up in practice β particularly around the depth of integration with non-SAP agent platforms versus SAP-native ones. A governance layer that subtly favors its own ecosystem is not truly vendor-agnostic.
5. The RPA-to-Agent Governance Continuity
For organizations with mature RPA programs, the transition to agent governance is less of a leap than it might appear. The core disciplines β bot inventory management, access control, credential vaulting, audit logging, exception handling, and lifecycle management β transfer directly. The difference is that agents are more autonomous, operate across more systems, and make higher-stakes decisions.
The practical move is to extend your existing RPA governance framework to cover AI agents rather than building agent governance from scratch. If your center of excellence already maintains a bot registry with ownership, access scope, and retirement criteria, you have the organizational muscle to do the same for agents. SAP AI Agent Hub β or whichever governance platform you select β is the tooling layer that scales that discipline across hundreds or thousands of agents.
SAP AI Agent Hub vs. Competing Approaches
| Capability | SAP AI Agent Hub | Microsoft Copilot Studio | Salesforce Agentforce | Standalone AI TRiSM Tools |
|---|---|---|---|---|
| Cross-vendor agent discovery | Yes (SAP, Microsoft, Google, AWS, ServiceNow, Databricks) | Microsoft ecosystem primarily | Salesforce ecosystem primarily | Varies by vendor |
| Agent inventory and classification | Yes (LeanIX-based) | Within Copilot Studio | Within Agentforce | Yes |
| Governance assessments and compliance | Yes (Q3 2026) | Limited to Microsoft governance | Trust Layer within Salesforce | Yes (primary focus) |
| Agent identity management | Yes (Q3 2026, SAP Cloud Identity) | Azure AD / Entra ID | Salesforce Identity | Varies |
| MCP and A2A support | Yes | MCP support; A2A in Agent Framework | A2A support announced | Generally no |
| Business KPI-linked monitoring | Yes (Q3 2026) | Limited | Limited | Varies |
| Pricing | Included in SAP Business AI | Included in Copilot Studio licensing | Agentforce pricing | Separate purchase |
The fundamental difference is scope. Microsoft and Salesforce govern their own ecosystems well. SAP AI Agent Hub is designed to govern agents across all ecosystems from a single platform. Whether it delivers on that promise in practice β particularly for non-SAP agents β is the question architects need to validate through proof-of-concept before committing.
Getting Started: A Practical Checklist
For agentic AI architects evaluating agent governance in 2026, here is a practical starting point:
Audit your current agent landscape. Before evaluating any governance tool, know what you have. Count every agent, bot, copilot, and AI automation running in your organization. Note which vendor platform each runs on, who owns it, what data it accesses, and when it was last reviewed. If this inventory does not exist, that is your first governance deliverable.
Map agents to business processes. An agent inventory is only useful if it is contextualized. For each agent, document which business process it supports, which systems it connects to, and what decisions it is authorized to make. This mapping is what transforms a list into a governance artifact.
Define your governance framework first, then select tooling. Gartnerβs six-step framework is a solid starting template. Decide on your policies for agent creation approval, identity management, data access governance, behavioral monitoring, and retirement criteria before you evaluate whether SAP AI Agent Hub, a competing platform, or a combination fits your needs.
Run a cross-vendor proof of concept. If SAP AI Agent Hubβs cross-vendor discovery is a key value proposition for your evaluation, test it against your actual agent landscape. Deploy agents from at least three different vendors and validate that Agent Hub discovers, inventories, and monitors all of them with equal depth. Pay particular attention to non-SAP agent visibility.
Integrate governance into your CI/CD pipeline. Agent governance should not be a manual checkpoint. It should be an automated gate in your deployment pipeline β no agent reaches production without a governance record, risk assessment, and compliance mapping. This is the same discipline that mature DevOps organizations apply to code deployments, extended to agent deployments.
Frequently Asked Questions
What is SAP AI Agent Hub?
SAP AI Agent Hub is a vendor-agnostic command center built on SAP LeanIX that provides a single entry point for discovering, inventorying, governing, and monitoring AI agents, LLMs, and MCP servers across an enterprise β regardless of which vendor built or hosts them. It reaches general availability in Q3 2026 and is included in the SAP Business AI Platform at no additional charge.
What is AI agent sprawl?
Agent sprawl occurs when AI agents are created and deployed across systems faster than the organization can inventory them, assign ownership, control permissions, monitor behavior, and retire them when they are no longer needed. Gartner estimates the average Fortune 500 enterprise will have over 150,000 agents by 2028, but only 13% of organizations currently have adequate governance in place.
Does SAP AI Agent Hub work with non-SAP agents?
Yes. Agent Hub auto-discovers agents from Microsoft, Google, AWS, Databricks, ServiceNow, and SAP. It also supports importing custom-built agents via a dedicated API using the Agent-to-Agent (A2A) protocol. However, the depth of integration with non-SAP agents should be validated through proof-of-concept, as Forrester has flagged potential concentration risk concerns.
How does SAP AI Agent Hub differ from Microsoft Copilot Studio governance?
Microsoft Copilot Studio provides strong governance within the Microsoft ecosystem. SAP AI Agent Hub is designed to govern agents across all vendor ecosystems from a single platform, including agents running on Microsoft, Google, AWS, Salesforce, and SAP. The key differentiator is cross-vendor discovery and governance rather than single-ecosystem depth.
Is SAP AI Agent Hub free?
SAP AI Agent Hub is included in the SAP Business AI Platform at no additional charge. SAP CTO Philipp Herzig confirmed this pricing at SAP Sapphire 2026, positioning Agent Hub as the default governance layer for SAP customers rather than a premium add-on.
Key Takeaways
- Agent sprawl is the governance crisis of 2026. 98% of enterprises are deploying AI agents, but fewer than half have inventory visibility and only 13% have adequate governance. The gap between adoption and control is widening.
- SAP AI Agent Hub is the most ambitious cross-vendor agent governance platform on the market. It auto-discovers agents from six major vendors and provides a single control plane for inventory, compliance, identity management, observability, and performance monitoring.
- The platform is free for SAP customers. Included in SAP Business AI at no additional charge, which positions it as the low-friction default for any organization already running SAP.
- Gartnerβs six-step framework provides the blueprint. Establish policies, build inventory, define identity and lifecycle, govern data access, monitor behavior, and measure outcomes. SAP AI Agent Hub maps to all six steps.
- Cross-vendor governance claims need validation. Forresterβs concentration risk warning is legitimate. Architects should test Agent Hubβs non-SAP agent discovery depth before committing it as their enterprise governance platform.
- RPA governance disciplines transfer directly. Bot registries, access controls, audit logging, and lifecycle management are the organizational foundation for agent governance. Extend them β do not rebuild from scratch.
References
- SAP News Center, βAI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue,β August 3, 2026.
- Gartner, βGartner Identifies Six Steps to Manage AI Agent Sprawl,β April 28, 2026.
- SAP LeanIX, βAgentic AI Survey 2026.β
- SAP LeanIX, βSAP AI Agent Hub.β
- The New Stack, βSAP Launches AI Agent Hub at Sapphire 2026 to Tame Vendor Agent Sprawl.β
- Forrester, βSAP Sapphire 2026: The Autonomous Enterprise Is Credible, But It Comes With Concentration Risk.β
- IgniteSAP, βSAP AI Agent Hub and Agent Governance.β
- SAP, βJoule Studio: Build AI Agents, Apps, and Workflows.β
- SAP Sapphire 2026, βInnovation News Guide 2026.β
- Forrester, βSAP Is Attempting To Become The Gatekeeper Of Enterprise AI β CIOs Should Push Back.β
For more on the agentic AI landscape, see our guides on Copilot Studioβs rebuilt agent platform, Salesforce Agentforce multi-agent orchestration, and the top trending open-source agentic AI repos in 2026.



