Two-thirds of organisations in new research say they already use AI agents in production. They expect the number deployed to increase sixfold by early 2027.
Yet 79% say their tools for discovering unsanctioned agents are absent or ineffective.
The study, conducted by IDC and commissioned by Leah, points to a problem procurement leaders will recognise: adoption can move much faster than ownership, controls and commercial governance.
What the research found
The survey covered more than 400 enterprise decision-makers across legal and compliance, procurement and sourcing, finance and accounting, and supply chain and logistics.
Leah reports that:
Agentic-AI budgets are expected to double over the next 12 months.
Only 29% of deployed agents currently interact with one another.
79% of organisations report delays when contracts move between teams.
59% say those handoffs add four to seven days to contract cycle time.
68% say generic LLM chatbots are only partially sufficient or worse for legal and procurement work.
These are survey findings published by a vendor with an interest in enterprise agent orchestration. They are useful signals, not universal market facts.
Unsanctioned agents create an invisible supplier layer
Shadow SaaS was already difficult to control. Shadow agents introduce a more serious version of the problem because they can act across multiple systems, use company data and trigger downstream work.
A software register that records only the contracted application will miss:
Which models and sub-processors the application invokes.
Which internal agents have been built by business teams.
What data each agent can access.
Which tools it can call and which actions it can execute.
Who owns the output, risk and operating cost.
Procurement, IT and risk teams need an agent register that sits alongside the application and supplier records.
Interoperability is becoming a governance decision
It may sound inefficient that only 29% of agents interact. Connecting every agent to every other agent is not automatically desirable.
Each connection expands the permissions, data flows and potential failure path. The right objective is governed interoperability: explicit purpose, minimum necessary access, shared identity controls and a complete record of which system initiated each action.
That is particularly important in contracting. An agent that drafts a term, another that assesses supplier risk and a third that creates the purchase order must share enough context to avoid contradictory decisions without creating an uncontrolled network.
The bottom line
The agent-governance gap is no longer theoretical if enterprises are deploying production systems at the rate the survey suggests.
Counting agents is not an AI strategy. Enterprises need to know who owns each one, what it can touch, how it is monitored and which commercial outcome justifies its existence.
Sources
Leah and IDC research announcement, 22 September 2026.

