As autonomous AI agents start acting on behalf of employees across CRM, ERP and collaboration platforms, enterprises are finding that their license models, cost controls and compliance frameworks were never built for software that behaves like a user. Flexera outlines five questions IT teams can no longer postpone.
Agentic AI is no longer a pilot project. According to a KPMG study, 53 percent of surveyed large US enterprises already deploy AI agents that access services and applications, retrieve data, and trigger workflows and transactions on their own initiative. Yet as organizations scale their AI initiatives and adapt to new requirements under the EU AI Act, operational governance is falling behind — partly for lack of resources and clear ownership, but mainly because existing control models were built for human users and clearly bounded software deployments, according to Flexera.
NIST defines AI agents as systems that decide and act independently with limited human oversight. That autonomy is reshaping IT asset management (ITAM) at its core. The traditional question — who uses which software, on which device, under which license — is giving way to a harder one: which applications, data and budgets may an agent access, what may it trigger on its own, and who is accountable? Flexera has identified five areas where AI agents test the limits of established ITAM practice.
- Licensing. An agent can act for multiple employees across CRM, ERP or collaboration systems at once, which does not fit neatly into per-user or per-device licenses. Whether it needs its own account or a technical license depends on the contract and license metric — named user, service account, or process- and consumption-based models. Microsoft and Salesforce show how inconsistent the field still is: Copilot Studio bills agent activity through credits, while multiplexing rules can still apply for connected applications; Agentforce combines user licenses with usage-based billing by conversation or action. For ITAM teams, the whole access chain matters — who initiates an action, which technical account executes it, which system is reached, and which license metric applies there.
- Cost control. A single agent run can trigger multiple model calls, API requests, database queries and actions, so costs accrue along an unpredictable execution chain rather than per license. Automated workflows can quickly become automated cost traps. FinOps for AI already offers useful tools, but the FinOps Foundation points out that differing pricing models and distributed execution chains complicate cost allocation and forecasting — and dashboards or budget alerts alone are not always enough to stop runaway spend. In practice, FinOps needs technical guardrails such as quotas, usage limits and deliberate model routing. The balance is delicate: stricter controls also risk blunting the value autonomous agents are meant to deliver.
- Discovery. Flexera distinguishes shadow AI from shadow IT: an unknown application is a visibility problem, while an unknown agent actively reaches into data and systems, connects tools, and triggers actions on its own. A one-off discovery exercise is not enough, since agents evolve continuously and often appear not as a distinct asset but inside existing platforms, APIs or tools. ITAM must look beneath the application layer — at which models, data sources, accounts and systems an agent touches, and how that access chain shifts during live operation. The deeper ITAM must look, the more it depends on data it frequently does not own — data scattered across platforms, identity management and security tools, in silos that need breaking down.
- Compliance. License compliance has always been fragile around indirect access, and agents raise that to a new level, routinely connecting applications, data and actions across vendor boundaries. A sales agent, for instance, might initiate a quote in the CRM, pull data from the ERP, and file the result in a collaboration platform — one workflow touching multiple contracts and license logics, with no single login to anchor usage to. Classic compliance models struggle here, lacking both standards for autonomous, cross-vendor workflows and a central view of the full usage chain. Until that changes, license compliance is likely to become more risk-based, with the most critical agent workflows mapped transparently enough to produce evidence, assign responsibility, and respond to audits.
- Organization. Who is responsible? Agents blur boundaries between ITAM, FinOps, identity management, security, procurement and legal, and none of these teams sees the full chain. Whether that calls for a centralized AI governance function or tighter integration of existing teams remains open. What is clear is that as long as each team controls only a slice, gaps persist between license, budget, access and risk — gaps where uncontrolled agent use can spread. The shift has already begun: Flexera’s State of ITAM Report finds 51 percent of ITAM teams now support visibility into AI spending, while 92 percent of surveyed ITAM professionals are expanding their FinOps skills — evidence less of a new specialist team than of a gradual merging of previously separate responsibilities.
“Companies are now deep in the AI stack, wrestling with exploding costs, tool and model sprawl, a lack of accountability, and growing dependencies. The question every CIO is asking is where measurable value is actually being created — and how long the current AI environment remains economically, operationally and securely sustainable,” said Conal Gallagher, CIO of Flexera. “Agentic AI forces us to answer that question now. Companies that fail to consolidate and bring transparency to their own AI landscape will lose control of their IT management, their business and their competitiveness.”

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
My local system struggles with legacy data structures.