When a whitepaper opens with a confession, you pay attention. 

The Zycus and Hackett Group research on Shadow Agent Estates doesn’t begin with a customer success story or a market opportunity framing. It begins with Zycus admitting that by early 2024, its own marketing team could not produce an accurate list of every AI agent running in the company’s name. Couldn’t tell you what each one did, who owned it, what it could access, or what it cost to keep running. A company whose entire value proposition is helping enterprises govern autonomous procurement had, in its own words, accumulated a Shadow Agent Estate inside its own walls. 

That admission is doing a lot of work. It’s saying: this doesn’t happen to careless organisations. It happens to organisations that move fast in an environment where the technology makes deployment easier than governance by design. 

Following Zycus Horizon events in Europe and ANZ last year, it was discovered that agent debt is real, it’s growing, and the procurement community hasn’t yet developed the vocabulary to name it clearly enough to fix it. 

What agent debt actually is 

Agent debt is the liability side of the Shadow Agent Estate ledger. 

The Shadow Agent Estate is the asset: the full population of AI agents running across your enterprise that nobody has inventoried, owned, or governed. Not because anyone was reckless. Because every route to building or acquiring agents defaults to isolation unless someone deliberately fights against it. Teams build agents without connecting them to outcome flows. Vendors ship agents natively inside tools you already pay for. Orchestration layers get assembled from scripts owned by one person. Agent builders put agent creation in the hands of anyone, at any time, with no governance attached. 

The Shadow Agent Estate is what accumulates. Agent debt is what that accumulation generates. 

The Zycus–Hackett research maps agent debt across four ledgers. Ownership debt is what you carry when no one can name the human accountable for what an agent does. Access debt is what you carry when agents have permissions broader than any task they currently perform. Entanglement debt is what you carry when agents depend silently on each other in ways that nobody has documented. Operational debt is what you carry when you cannot state what your agents cost last month, and have no audit trail to reconstruct what any specific agent did on a specific day. 

The numbers from Hackett make the case 

This isn’t an abstract risk. The Hackett Group’s 2026 research quantified where the exposure sits. 

It was found that 69% of companies expected additional material risk from agentic AI deployment versus traditional automation, according to the 2026 Future-Ready Purchase-to-Pay Quick Poll. That is not a fringe concern. It is the majority view. 

Amy Hillcox, Senior Research Director, Procurement Applied Intelligence at The Hackett Group®, outlined in the research the specific risks most weighing on procurement leaders. Internal adoption and trust risk was cited by 84% of respondents. Incorrect or inappropriate autonomous decisions by 74%. Data quality risk by 72%. These are not technology risks in the narrow sense. They are governance risks. 

The mechanism that produces these risks is captured in a data point from the 2026 North American Procurement Applied Intelligence Leadership Forum: only 17% of attendees reported having moderate or advanced experience building AI agents. (Note: this polling was conducted at a Zycus Horizon event, a self-selected audience of procurement professionals who attended a vendor conference, and should be read in that context rather than as a representative sample of the broader procurement market.) 83% are configuring agents with limited expertise, using tools that produce standalone task executors by default. 

And then there is the governance gap at the provider level. The Hackett Group’s 2026 AI Solution Providers Study found that 50% of procurement technology providers do not fully support the governance requirements needed for effective AI. The market for agent tooling outpaced the market for agent governance before either had a clear vocabulary. 

What was heard at Horizon Europe and Horizon ANZ 

The Zycus Horizon events in 2025 were where the practical dimension of this became concrete. 

At Horizon ANZ, Seqwater presented their experience implementing Zycus’s Merlin Agentic Platform. What came through clearly wasn’t a story about technology deployment. It was a story about what it meant to have agents operating inside governed flows rather than alongside processes. When agents are embedded in the flow, the outcome has a structure. Someone owns it. The cost is visible. There is a record of what happened. 

BOLT’s presentation at Horizon Europe told a similar story from a different starting point. The distinction they kept coming back to was between having AI capability and having AI that produces procurement outcomes. Point agents, in their experience, produced capability. Governed agentic flows produced outcomes that procurement could stand behind in front of the CFO. 

That last phrase matters. Standing behind an outcome in front of the CFO is the test Agent Debt fails structurally. You cannot make that case with isolated agents. You can only make it with governed flows that have auditable results, named owners, and measurable outputs tied to procurement’s core accountabilities. 

The four failure modes most likely to surface first 

The Accountability Gap is when an agent can send a communication, approve a transaction, or publish content with no named human answerable for the outcome. It tends to produce an incident: something gets sent or approved that shouldn’t have been, and when the question of who is responsible is asked, there is no answer. 

Credential Sprawl shows up in security reviews and offboarding processes. API keys and tokens scatter across scripts and automations, unrotated, uncounted. When someone with significant agent-building history leaves an organisation, the credential audit that follows is frequently the first time the access footprint of the agent population becomes visible. 

The Pipeline Jungle becomes apparent when something upstream breaks. An agent that silently depends on the output of another agent creates a fragile dependency that nobody has mapped. When the upstream agent changes, updates, or is retired, the downstream failure is often a surprise. 

Unmetered Spend surfaces in budget conversations. Finance asks what the AI programme cost last month. Procurement cannot produce a single number. This failure mode most directly undermines the board-level ROI case. 

The research is precise on why these failure modes accumulate structurally. Isolation is not a risk of the point agent model. It is the default output of the point agent model. Creation is easy. Governance never arrives. 

The urgency argument that changes the calculus 

The case for addressing agent debt now rather than later rests on a dynamic that Zycus and The Hackett Group describe as ‘the inversion’. 

Procurement’s day-to-day work is shifting. Today, agentic flows cover intake and tail spend. Zycus and The Hackett Group project that over the next 12 to 18 months, they expand into sourcing, contracts, supplier onboarding, and AP. The end state is end-to-end procurement running in flows, with the S2P suite as the system of record underneath. Organisations like BOLT and Seqwater are already in it. 

The reason this matters for agent debt is that shadow estates do not shrink as flows expand. They compound. Every new flow layered on top of an ungoverned point-agent population makes the estate harder and more expensive to unwind. Organisations that govern their estates before the inversion completes enter the flow era with an architecture. Those that don’t enter with an accumulation. 

Richard Gardner, Senior Director of Market Intelligence at The Hackett Group®  observed in the research that organisations have always struggled to manage IT complexity as they scale, through redundant software, acquired legacy systems, and customisations that outlive the problems they solved. The same complexity pattern, he argued, is highly likely to emerge for companies building agent populations without the data maturity, governance structures, and talent to manage what accumulates. 

We named this pattern when it was technical debt. We named it when it was data debt. The procurement community needs to name it now, while the estates are still small enough to inventory by hand. 

What closing the ledger requires 

The research identifies five things that need to be attached to every agent at the moment it is created. 

An owner: a named person who answers for what the agent does. A scope: least-privilege access granted for the task at hand, not extended by default. A meter: cost attribution visible to finance. A log: a record complete enough to reconstruct what the agent did on any given day. A kill switch: one place to stop it immediately when something goes wrong. 

These five disciplines are not technically complex. The question is whether the platform architecture enforces them at creation or leaves them to whoever happens to be building the agent. Most platforms leave it to the builder. That is the gap the Shadow Agent Estate grows through. 

Platforms that embed governance architecturally rather than optionally (Zycus’s Merlin Agentic Platform being the primary example cited in the research) operate on a different premise: every agent in every flow carries all five disciplines from the moment it exists. The governance is embedded in the architecture, not added after the fact. The presentations at Horizon Europe and Horizon ANZ demonstrated what that architectural difference produces in practice: procurement functions that can stand behind their AI investment in front of the CFO. 

The diagnostic question for any CPO reading this is direct. Can you produce, right now, a complete list of every agent running in your name, who owns it, what it costs, and whether it sits inside a governed outcome flow? If the answer is no, you have a Shadow Agent Estate. What you have accumulated in it is Agent Debt. And it is growing. 

The ledger is open. The question is when you look at it. 

Agent debt will not appear on any balance sheet until something goes wrong. An autonomous decision that nobody can attribute. A compliance event with no audit trail. A board question about AI ROI that procurement cannot answer. A security review that reveals an access footprint nobody mapped. 

By that point, the debt is visible because it has already been called in. 

The research ends with a line worth taking seriously: the move from a Shadow Agent Estate to a governed one is not the move from many agents to fewer. It is the move from isolated agents executing tasks to orchestrated agents delivering outcomes. That is the only move that closes the ledger. 

The organisations that make that move now, before the inversion forces the question, are the ones who will be presenting success stories at the next Horizon. The ones that wait will be presenting something else. 

The full Zycus–Hackett Group research paper on the Shadow Agent Estate is publicly available.  https://www.zycus.com/knowledge-hub/whitepapers/shadow-agent-estate-hackett-group

TL;DR 

Editorial note: The reporting here draws on The Shadow Agent Estate (2026), a point of view paper published by Zycus in collaboration with The Hackett Group’s research. The research draws on the 2026 North American Procurement Applied Intelligence Leadership Forum, the 2026 Future-Ready Purchase-to-Pay Quick Poll, and the 2026 AI Solution Providers Study. Case material comes from presentations at Zycus Horizon Europe and Horizon ANZ 2025. 

We believe in a personal approach

By working closely with our customers at every step of the way we ensure that we capture the dedication, enthusiasm and passion which has driven change within their organisations and inspire others with motivational real-life stories.