A bank can tell you how many servers it runs, down to the last rack. Ask how many AI agents are running, and the answer is far less exact. This guide explains what an AI agent inventory for a bank is, why agents go uncounted, and how to build the inventory before an examiner asks for it.
TL;DR
- The problem: teams deploy AI agents faster than anyone records them, so the real number is often unknown.
- The gap: SR 26-2 puts agentic AI outside US model risk guidance, so agents may sit outside the model inventory.
- The risk: an agent with no named owner has no accountable human, and often holds standing credentials.
- The fix: a living inventory, with an owner, permissions and risk tier for every agent.
- The method: sweep, assign owners, tier by authority, then reconcile continuously.
What is an AI agent inventory for a bank?
An AI agent inventory is a single record of every AI agent that can read, write or act inside a bank. Each entry names an owner, a business purpose, the model behind it, the data it can reach, the tools it can call and the permissions it holds.

It differs from a model inventory. A model returns a score. An agent picks its own tools, chains steps and takes actions, so the inventory has to capture authority, not just logic.
Why do banks have agents nobody has counted?
Sprawl starts when each line of business deploys agents on its own. Support builds one, marketing builds another, and credit and compliance teams add theirs, often on different platforms, with no shared register.
Agents also hide in four places:
- Your own clusters: workloads that were never registered.
- Hyperscaler agent services: adopted by a single team.
- SaaS features: agents behind vendor URLs.
- Employee laptops: unsanctioned AI clients and tool configurations.

No conventional system sees all four, which is why the headcount is usually a guess. The scale of the concern is documented. An OutSystems survey of roughly 1,900 IT leaders across industries, fielded from December 2025 to January 2026, found that 94% were concerned that AI sprawl is raising complexity and security risk. Only 12% had a centralized platform to manage it. The same research reported financial services among the highest levels of production deployment.

Why does SR 26-2 make the inventory harder?
US banks used to land AI in the model inventory under SR 11-7. That guidance was replaced on April 17, 2026 by SR 26-2, issued with OCC Bulletin 2026-13. Footnote 3 of the new guidance places generative and agentic AI outside its scope, calls them novel and rapidly evolving, and points banks to their own risk management and governance practices instead.

The result is a gap that each bank has to close itself:
- Scope: the guidance is principles-based and most relevant to banks above $30 billion in assets.
- Agents: they may no longer appear in the model inventory by default.
- Other duties: third-party risk, cybersecurity, consumer protection and recordkeeping obligations still apply to any agent a bank runs.
Outside the US, the direction is the same. The Reserve Bank of India’s FREE-AI report, published in August 2025, recommends that regulated entities keep a comprehensive AI inventory, refreshed every six months. It is a committee report, so its recommendations are advisory until the RBI adopts them. For related context, see our overview of AI agents in banking.
Why are uncounted agents a risk to a bank?
An agent nobody has counted is an agent nobody governs. Four failure modes follow:
1. No accountable owner.
Audits assume a person or a fixed rule made the decision. When an agent chains actions across systems, the decision log may not trace back to a named human.
2. Conflicting actions.
Siloed agents lack a shared resolution layer. A hypothetical example: a customer-facing agent promises a retention rate while a risk agent restricts the same account.
3. Standing credentials.
To be useful, an agent hooks into core systems and customer data. If it keeps persistent credentials across several APIs, one misconfigured agent widens the attack surface.
4. Invisible spend.
Model keys can keep costing money after the agent that used them is gone. Our guide to agent lifecycle management covers retirement.
What should an AI agent inventory record?
| Field | Why it matters |
|---|---|
| Unique ID and name | One identifier that resolves everywhere, from audit lines to incident tickets |
| Named owner and team | The accountable human for every action the agent takes |
| Business purpose | Lets risk judge whether the agent still has a reason to exist |
| Model and provider | Shows concentration and third-party exposure |
| Data it can read | Defines privacy and confidentiality scope |
| Systems it can write to | Defines the real blast radius |
| Credentials and identity | Shows which standing access to rotate or remove |
| Hand-off rule | States when the agent must pass control to a person |
| Environments and live version | Ties behaviour to a specific release |
| Risk tier and approval status | Drives review frequency |
How do you build an AI agent inventory, step by step?

Step 1: Define what counts as an agentWrite one definition. A workable test: if software can choose a tool or take an action without a person approving each step, it belongs on the list. Include vendor-embedded agents, because the bank still answers for them.
Step 2: Sweep the four placesCombine interviews with technical discovery. Ask every line of business what it runs, then check clusters, cloud agent services, vendor integrations and endpoints for anything missing from the answers.
Step 3: Assign a named owner to every agentNo owner, no registration. An unowned agent cannot be reviewed, and it is the quickest route back to an inventory that nobody trusts.
Step 4: Tier agents by authorityRank each agent by what it can see, which systems it can write to and when it must hand off to a person. A read-only summariser and an agent that moves money should never share a review cadence.
Step 5: Reconcile continuouslyA spreadsheet is accurate on the day someone finishes it. Compare the registry with the running estate on a schedule, and treat every mismatch as a finding.
Spreadsheet or control plane: which should hold the inventory?
| Approach | What you get | Where it breaks |
|---|---|---|
| Spreadsheet | A starting list | Stale within weeks, no discovery, no enforcement |
| GRC or model inventory tool | Governance records and review workflows | Typically records only what teams declare |
| Agent control plane | Registry plus discovery plus enforcement in the call path | Needs deployment and read-only access to your environments |
Opencontroller by Lyzr is our implementation of the third row. Its agent registry is both the inventory and the identity store: each agent gets an immutable ID and a record carrying owner, team, framework, repository, environments and live version. Agents hosted elsewhere register as external entries and are governed without being moved.
Discovery then reconciles the registry against reality:
In your cluster: Unregistered workloads, orphaned runtimes, calls that bypass the gateway, and spend on keys with no live agent.
In other clouds: Read-only connectors to AWS Bedrock AgentCore, Google Vertex AI Agent Engine and Microsoft Foundry Agent Service.
On devices: An endpoint agent that finds unsanctioned AI clients and tool configurations.
Each finding records the creator, model, data reached, identity and cost, and one action registers it with an owner and an audit trail. Approvals use separation of duties, so a requester cannot approve their own change, and the whole platform runs inside your own cloud account. It complements, rather than replaces, your GRC and model risk tools. To see where your estate stands today, try the AI agent sprawl audit, and for the registry concept in depth read our AI agent registry guide.
Where does Madison fit, and where does Opencontroller step in?
The two solve different problems. Opencontroller by Lyzr is the system of record for the agent estate: it finds agents, registers them, assigns owners, and enforces budgets and approvals. Madison is the compliance layer: it maps a bank’s obligations to its policies and controls and shows where coverage has gaps.

| Question | Opencontroller by Lyzr | Madison |
|---|---|---|
| What is it? | Control plane for AI agents | Governance, risk and compliance for banks |
| What does it answer? | Which agents exist, who owns them, what they can reach | Which obligations apply, and which policies and controls cover them |
| Where does it work? | Across the agent estate | Across the bank’s compliance estate |
Put simply, the inventory tells you what agents exist. The compliance layer tells you which obligations and controls those agents must be governed against.
Frequently asked questions
What is an AI agent inventory?
It is a living record of every AI agent in an organization, with its owner, purpose, model, data access, tools and permissions. A bank uses it to prove what is running and who is accountable.
What is agent sprawl?
Agent sprawl is the uncontrolled growth of AI agents across teams and platforms without shared ownership, policy or visibility. It is the agentic version of shadow IT.
How is an AI agent inventory different from a model inventory?
A model inventory tracks models that produce scores or predictions. An agent inventory also tracks authority: the tools an agent can call, the systems it can write to and the credentials it holds.
Does SR 26-2 require banks to inventory AI agents?
No. SR 26-2 places generative and agentic AI outside its scope, so it sets no agent inventory expectation. Banks are pointed to their own risk management and governance practices, which is why an internal inventory is a governance decision.
How many AI agents does a typical bank have?
There is no reliable public figure, and any single number would be a guess. The only dependable answer comes from discovery across your own environments.
Who should own the AI agent inventory?
A sensible home is technology risk or AI governance, with each agent’s business owner accountable for their own entries. What matters is that one team owns the register itself.
How often should the inventory be updated?
Continuously where possible, and at least on every deployment and retirement. The RBI’s FREE-AI report recommends a half-yearly update.
What are shadow agents?
Shadow agents are AI agents running without registration or approval. They typically appear in clusters, cloud agent services, SaaS tools and employee devices.
Where should a bank start?
Start with a definition and a sweep. Ask each line of business what it runs, compare the answers with technical discovery, and give every agent a named owner.
Find the agents nobody counted
Run a working session with your technology risk team and leave with a first count of the agents in your estate.
Take the sprawl audit
Book A Demo: Click Here
Join our Slack: Click Here
Link to our GitHub: Click Here


