🎧 ▶ Listen: 5-minute briefing
▶ Play audiobook (Google Drive)
Locally synthesized AI audiobook (Qwen3-TTS)

There is nothing scarier for an HR team than not knowing who is in the building. An employee who left long ago still carries a badge. A contractor’s access rights survive the end of the contract. A permission group outlives the department it was made for. A large share of security incidents begins with one line: we thought that was already over. This week, Maeil Business Newspaper asked a question that first sounds exaggerated: “Does our company have 150,000 AI employees?” It is not a joke about scale. As generative AI work adoption accelerates, agents are entering organizations like employees, not like servers or apps. For the organizations that adopted them, no question is more realistic. And the cost of producing an answer to that question is quietly accumulating. As the company grows, the question stops being an HR problem and becomes a security problem, and then stops being a security problem and becomes an executive problem.

Image visualizing the concept of 150,000 people who never quit: the day agents became the new technical debt An image visualizing the core concept of the article.

A Roster That Grew 10,000-Fold in Three Years

The numbers point the same way. Gartner projects that Fortune 500 companies ran fewer than 15 AI agents each in 2025 and will operate more than 150,000 by 2028. That is 10,000 times in three years. The IBM Institute for Business Value also sees companies running an average of 1,661 agents by 2027, a 38% increase over today.

For Korean companies, this forecast may sound conservative. As agent development becomes low-cost and low-barrier, the era has arrived when a single team runs its own “secretary.” Every department is building and using only as many agents as it needs. This is the so-called agent sprawl. When the sales team raises a contract summarizing secretary, the customer center raises a response drafting tool, and R&D raises a literature research assistant, the roster keeps thickening as a layer invisible above the org chart. It is a different order from buying a server and plugging it in. An agent, from the moment it is born, requests permissions and asks which systems to connect to.

The bigger problem is that agents accumulate as individuals. Adding a few more servers only grows the management target by that amount, but each agent carries its own permissions and scope of work, and the name and purpose set at creation blur over time. So the first question to disappear is “who is managing it?” According to Gartner, only 13% of organizations have a management system in place. Even at today’s scale, at least 8 out of 10 agents operate outside any management, and when the era of 150,000 arrives, that gap will only widen.

The Problem Is Not Building Them; It Is What Remains

In HR, retirement is the most tedious and the most important procedure. It is the moment when badges, entry cards, and system access rights are all invalidated at once. When a human employee retires, the organization’s risk goes down. Agents are the exact opposite. The more they are used, the wider the permissions grow, and even when the work ends, those permissions remain as they are. Maeil Business Newspaper called this situation zombie agents. These are agents that keep their data access rights and credentials even after their work is over. The job ended long ago, but the “employee ID” is still valid and the server room door is unlocked. Leaving “finished work” in a place that holds permissions is like handing a safe key to a retired employee.

Zombies are dangerous because they are slow and persistent. At the level of a few requests per day, they do not get caught as an anomaly. The data they can reach is still current, and the person who granted the permissions no longer remembers whether that agent is a finished job. IBM’s damage tally shows this picture in numbers. Companies experienced an average of 54 agent incidents in the past year, and 37% of high-risk incidents were data exposure and security breaches. What one agent that never retires quietly does is keep “looking at” data that is no longer needed.

The Cloud Security Alliance survey explains the background. 82% of companies have discovered agents that the security and IT departments were not aware of, and 65% have experienced agent incidents. In a structure where agents the organization does not know are looking at the organization’s data, an incident is not an exception but a matter of time. And the most striking number is the last one. Only 21% of companies have a formal decommissioning procedure for agents. Four out of five are running agents without deciding “how to end them.”

The Day the Cost of Building Stopped Being the Cost

For decades, the cost of IT systems sat in “making them.” Design, development, deployment. Budget flowed to the side that got things running, and operating cost was a story for later. Agents have reversed this curve. Making is nearly free, and what has become expensive is leaving behind. When an agent built by a department stops being used, that agent does not disappear. It remains in the server room, still gripping its permissions.

In June, Gartner warned in a report titled “AI Agents Are Technical Debt” that the agents being built now may soon become the technical debt of the future. And it added that agent expansion must first become a governance pilot led by the CFO. If the procedure that asks why it was built, who is responsible, whether it actually creates value, and what it costs to operate is skipped, the agent remains as debt.

The market is already moving. Snowflake unveiled an AI gateway and agent security features at Black Hat 2026, and Databricks is strengthening large-scale agent governance on top of the Unity Catalog. Anthropic has followed up with an agent security whitepaper and zero-trust adoption. The IDC survey reported by The New Stack on August 25 is the same picture. Most companies are deploying agents, but their control, governance, and oversight capabilities are lagging. As investment in agent governance infrastructure accelerates worldwide, the center of gravity is moving from “how to build agents” to “how to handle agents,” and agent operations, an independent layer that manages agents like employees all the way from the roster and permissions to retirement, is emerging as a new market.

Why “Retirement Procedures” Weigh Heaviest in Korea

This question is heaviest in Korea. In a country where finance, the public sector, and manufacturing run on closed networks and on-premises, a zombie agent that stays while holding its permissions has a structure where, once an incident breaks out, the damage snowballs as it passes through several systems.

In Korea, this problem is no longer a hypothesis. eBase, the largest domestic BPO company, has commercialized a customer service AI in which agents directly handle tasks such as automatic transfers, instant payments, and lost card reports. In a structure that reads intent from customer utterances and executes the actual work through to the end, the permissions granted to a single agent are real transactions.

The security domain is, in a word, a stress test. Right now, as security AI that only raised alarms moves into the agentic stage where it itself performs account suspension, communication blocking, and system isolation, a single false positive can block normal work. In fact, the agents the government is raising must also pass through the same question. The public call for the Ministry of Science and ICT and NIPA project “Specialized AI Foundation Model Development (Cybersecurity)” closes today. Selected projects will be supported with 256 NVIDIA B200 GPUs. SK Telecom, Naver Cloud, and LG CNS are competing, each with its own consortium, and the design the industry is asking for is clear. Automate log summarization and alert triage, but for measures like account suspension and server isolation, put approval procedures and recovery and tracking systems in place, and grant permissions by risk level. The moment AI holds real system control permissions, a single false positive that blocks a normal service can escalate into a legal and trust issue, so there is also a forecast that in regulated industries such as finance, the public sector, and manufacturing, human-in-the-loop, audit, and rollback requirements will expand into a standard clause for all agent adoption. That is why one abandoned permission becomes not a hygiene issue but a legal and trust issue.

The implication for domestic companies is clear. In the review of agent adoption, audit, permission lifecycle, and lifecycle management become not an option but a prerequisite. The 21% with decommissioning procedures is the global average, and it is hard to expect Korean finance and the public sector to be higher. In the reviews ahead, “a structure that can end” rather than “the speed of adoption” is very likely to become the criterion that separates companies.

How to Treat Agents Like HR

So what does it mean for an organization to treat agents like HR? The minimum answer is four things. Whether it knows who exists, what permissions each has, whether it can track every action, and whether the scope of autonomy is defined. Only in organizations that have these four things is “firing” possible. Whether it is a customer service agent that handles a customer’s automatic transfer request through to the end, or an agent that triages alarms in the control room, the organizations that control risk are the ones that decide “what can be done automatically” and “what requires a human signature” by policy, not by judgment.

There is a platform where these four things become the starting point of the design. ThakiCloud’s agent-native cloud Paxis, a product already officially released as v1.1. In Paxis, the skills, tools, policies, and audit logs that agents use are not attachments bolted on after the fact but first-class resources, registered and recorded on the platform. It is a structure where, each time an agent is born, the information of who, for what purpose, and with what permissions is left alongside.

The autonomy granted to agents is staged from L0 to L3. Routine measures proceed autonomously, and actions that go beyond the scope must pass a policy gate that gets human approval. The execution itself happens inside an isolated sandbox, so bad behavior is less likely to spread to the main system. What each agent did when is left in the audit log, and CostRouter decides which model to use per task, so the operating cost question of “how much does it cost” is answered from the same ledger. MCP connectors and the skill marketplace support external system integration and skill reuse, and Paxis can also be installed on-premises on the customer’s own K8s, where data does not go outside.

The roster of 150,000 will keep growing. While the roster that is 1,661 today balloons to 150,000, what organizations must prepare is not the agents but “how to end them.” Even beyond the number Gartner predicted, the companies that can answer “how can they be retired” will still be only a few. In HR, there is a saying to look at the “retirement list” before the “onboarding list.” The time has come for the same order to apply to agent operations too. If someone in next quarter’s check asks for “the list of finished agents,” that organization is ready. For organizations that are about to start agent operations, the first question is now not “how many can we build” but “can we fire them.” And as of 2026, the answer to this question is not a matter of policy but a matter of platform.

References

This article was written by synthesizing the news below.

Tags: agent-sprawl, ai-agent-governance, audit-log, enterprise-ai, permission-lifecycle, technical-debt, zombie-agents

Categories:

Updated: