You already have agents you cannot see.
23 September 2026
Salesforce research puts the average Australian enterprise at 11 deployed agents, half of them isolated from each other. Agent Fabric is not new agent capability. It is the control panel that makes the next wave survivable.
The question that stops the programme
A board asks a question that sounds simple. How many agents do we have, what can they reach, and how much are they costing us.
Nobody in the room can answer it. Not because anyone was careless, but because the answer is spread across four teams, two clouds, and a product somebody bought in March that shipped an agent nobody mentioned. The AI programme then stops for a quarter while somebody goes and finds out.
Agent sprawl never arrives as a decision. It arrives as five sensible decisions made by five different teams in the same year. Someone in service stands an agent up on Bedrock. Someone in marketing runs one on Vertex. A team in finance builds an MCP server for a reporting job and tells nobody, because it was a reporting job. Each one was the right call. Nobody owns the set.
Salesforce research with 100 Australian IT leaders, surveyed late last year, puts the average at 11 agents deployed per organisation, about half of them operating in isolation from each other, roughly a fifth of APIs ungoverned, and only 54 per cent of organisations running centralised governance with formal oversight. Small sample, vendor study, so read it as direction. It matches what I find when I ask the question in the room.
What Agent Fabric actually is
Agent Fabric is a MuleSoft product that lets you discover, govern, orchestrate, and observe agents and MCP servers across your organisation. In practice that means one control panel showing every agent you run, including the ones nobody registered, what each is doing, and one place to apply policy to all of them.
It does not make your agents smarter. It tells you what you have, which is the layer nearly everyone skipped on the way in.
Strip away the product names and it answers four questions a board is entitled to ask.
Governance is what lets you have more agents, not fewer
The usual objection is that governance slows the programme down. The opposite has been true on every engagement I have run, and the reason is arithmetic rather than philosophy.
An organisation with no control plane can safely run a handful of agents, because a person is the control plane. Every new agent adds risk that somebody has to personally carry, so sensible executives cap the number. The ceiling is not technical. It is how much unmonitored autonomy one human being is willing to sign for.
Put a control plane underneath and the tenth agent costs no more oversight than the third, because the oversight is a system rather than a person.
The piece Australian clients consistently underestimate is identity. Most agent deployments authenticate through a shared service account, because that was the fastest way to get the first one working. It means every agent looks identical in the audit log, so when something goes wrong you can see that it happened without being able to see which agent did it. Giving each agent its own authenticated identity is unglamorous, it is usually a fortnight of work, and it is the difference between an incident you can explain to a regulator and one you cannot.
There is a harder point underneath that, and it is the same one I made in July about data. Point an agent at three conflicting definitions of a customer and it does not pick the correct one. It confidently acts on all three. A control plane will tell you which agent did that, when, and at what it cost. It will not tell you the definition was wrong. The data foundation still has to be right, and no amount of governance substitutes for it.
What we have been doing
We started demonstrating Agent Fabric to Australian customers in August, before Dreamforce made it a headline. Those conversations are live now in utilities, financial services, and media.
The pattern is the same every time. We do not open with the product. We open by asking how many agents are running and who owns them, and most of the time, the room goes quiet.
What the discovery pass then turns up is rarely dramatic. It is usually three or four agents somebody built for a good reason and never decommissioned, one MCP server pointed at a production object with permissions nobody has reviewed since it was stood up, and a model bill nobody has reconciled, because two agents are calling the same thing twice. None of that is a crisis. All of it is the sort of thing that becomes a crisis at the exact moment you scale from 11 agents to 40.
Part of our own MuleSoft delivery is executed by agent crews, which means we are governing an agent estate of our own before we advise anyone on theirs. That is also how I know how quickly a register goes out of date.
If you cannot currently answer how many agents your organisation is running, start there. A discovery pass is weeks rather than months, and it is the cheapest piece of work on the whole roadmap.

Written by
Carlos Langle
Director of Data & Integration
Carlos designs the data foundations ANZ enterprises run their AI on: governed pipelines, trusted context, and architecture built to hold up under scrutiny. Having worked both sides of the table, in sales at Salesforce and MuleSoft and in delivery, he treats data quality as a commercial issue, not just a technical one.
More from Carlos LangleSources
- • Salesforce Australia, Multi-Agent Adoption to Surge 73% by 2027 in Australian Enterprises, Connectivity Benchmark Report announcement, 6 February 2026. Australian sample of 100 IT leaders, fieldwork October to November 2025, run with Vanson Bourne and Deloitte Digital. Primary. Verified 23 September 2026: all four figures match exactly.
- MuleSoft, Agent Fabric product page, mulesoft.com/ai/agent-fabric. Marketing page, not a release note. Verified 23 September 2026: scanners cover Amazon Bedrock, Google Vertex AI, Microsoft, Claude, Databricks and Kong; no pricing published. Single vendor, directional.
- MuleSoft, '26 Mid-Year Release: Govern & Secure AI, 12 August 2026. Source for Trusted Agent Identity, Universal Policy Catalog and Rogue Agent Detection. Single vendor.
- MuleSoft, Stop a Rogue Agent in Seconds: Agent Kill Switch is Now GA, 2 September 2026. Verified: GA 2 September 2026, four intervention scopes, reversible with a restore function, tamper-evident hash-chained audit record. Single vendor.
- Carlos Langle, data foundation insight article, 28 July 2026 (N2-A1). Primary, subject's own prior published position.
- All other claims in this article are the author’s own first-hand observation.
Want to talk it through?
Bring us the AI project you are about to fund. We will pressure-test the foundation before you commit the sprint.