Nobody needs convincing to build AI agents in India anymore. That decision has already been made. The harder question is whether enterprises can actually manage what they are building.Over 80% of Indian organisations are already actively experimenting with agentic AI; but only29% have gotten even one agent past pilot and into real production. That gap isn’t a technology problem; it’s what happens when every department builds their own agents in isolation, without anyone coordinating what they are doing.
Sales teams deploy agents to engage customers. Support desks use them to triage tickets. Finance automates reconciliations. HR uses agents in recruitment. Developers use coding agents to write and test software. Each may be solving a legitimate business problem. But without coordination, enterprises can quickly end up with dozens or hundreds of agents operating as disconnected point solutions.
The same pattern as Shadow IT, except riskier
This isn’t new. A decade ago, it was Shadow IT, where employees signed up for cloud apps faster than IT could track them. Agentic AI is following a similar trajectory, but with a critical difference. Shadow IT largely introduced new places for information to live. Agents introduce new actors into the business. An agent doesn’t simply store data or surface information for a person to act on. It can make decisions and take action itself, approving a refund, updating a customer record, triggering a workflow, or deploying code. That autonomy is what makes agents so powerful. It is also what makes unmanaged agent sprawl fundamentally different from unmanaged software.
The risk increases further when agents begin working with other agents. A coding agent might write software, a second agent might test it, and a third might deploy it. Each may perform exactly as intended in isolation. But whether the three agents, working together, are producing the outcome the business actually wants is a much harder question.
The challenge is no longer simply knowing what tools exist. It is knowing what is acting on the business, how those actions connect, and whether the overall process is working as intended.
The sprawl is already costing India
This isn’t hypothetical. A recent report found that 63% of Indian organisations have already had an AI-related security incident. At the same time, 57% report gaps in visibility into AI or agent activity, highlighting a growing challenge as AI becomes embedded across more functions and systems.
That makes agent sprawl more than a future governance concern. It can translate into security exposure, duplicated investment, and an inability to understand whether the growing number of AI initiatives are actually delivering business value.
India’s AI Governance Guidelines, also underscore the importance of human oversight when AI systems take consequential actions, including the ability to review and override outcomes. But that expectation becomes difficult to meet if an organisation cannot answer basic questions: Which agents exist? What are they doing? What data and systems can they access? Who owns them? And where is human oversight required?
After all, an enterprise cannot govern or orchestrate what they cannot see.
Why this is an orchestration problem
Businesses don’t operate through isolated tasks. An insurance claim, for example, might move through document processing, policy verification, fraud detection, human review, and payment. If those handoffs aren’t coordinated, the process can stall even when every individual step works as designed.
This is where business orchestration and automation become critical. Orchestration connects agents, people, automations, and enterprise systems into one coordinated process, aligning independently built capabilities to a common business outcome.
Governance sets the boundaries, including what agents can access, what they can do, and where human intervention is required. Orchestration ensures those governed agents work together rather than operate in silos.
Governance makes agents trustworthy. Orchestration makes them useful at enterprise scale. Together, they are two halves of the same job.
Agentic testing has to become continuous
As agents take on more business-critical work, a third capability becomes just as necessary: agentic testing.
Traditional software testing was designed around deterministic systems; the same input should produce the same output. Agents operate differently. Their behaviour can change as models, data, instructions, and surrounding workflows change.
Testing therefore cannot be a one-time checkpoint before deployment. As agents interact with other agents, people, and enterprise systems, enterprises need continuous validation of both individual agents and the larger workflows they operate within.
Making agent adoption work at scale
The lesson from Shadow IT was never that employees should stop adopting new technology. It was that adoption without visibility eventually creates a problem bigger than the one the technology was meant to solve.
Agentic AI is at a similar inflection point. The organisations that get this right will not be the ones that put the brakes on experimentation, but those that build the visibility, governance, orchestration, and continuous testing needed to let agents operate safely and effectively at scale.
The author is Karl Crowther, Area Vice President, Middle East & Africa and South Asia.
Disclaimer: The views expressed are solely of the author and ETCIO does not necessarily subscribe to it. ETCIO shall not be responsible for any damage caused to any person/organization directly or indirectly.