• AI GOVERNANCE
Your AI Agent Has a Job. Who Is Managing It?
AI agents are gaining access to inboxes, databases and business systems. Before giving them more autonomy, organisations need to decide who owns their actions — and who can make them stop.
By Suchetana Bauri · Published September 2026 · 20 Min Read
KEY TAKEAWAY
The agent does not need a performance review or a place at the Christmas party. It needs a narrow job, a unique identity, limited permissions, observable behaviour and an accountable human who can intervene.

• 01 / SOFTWARE WITH A STAFF PASS
The newest member of the team did not attend induction
The newest member of the team did not attend induction.
It did not sign the acceptable-use policy, sit through information-security training or learn that the finance director dislikes surprises. It arrived through a software update, acquired a cheerful name and began doing things. Not merely suggesting things, which was the old arrangement, but opening files, calling tools, moving information between systems and completing sequences of work while its human colleagues concentrated elsewhere.
This is the promise of the AI agent: less prompting, less supervising, less of the faintly absurd experience of copying text from one clever box into another. Give the system a goal and it works out the intermediate steps. The employee gets time back. The organisation gets speed. The software company gets to place the word agentic in every presentation until the next word arrives.
Authority is the real threshold
But an agent does not become useful by being intelligent. It becomes useful when someone authorises it.
“An agent does not become useful by being intelligent. It becomes useful by being authorised.”
To act, it needs credentials and access to the right data. It also requires permission to call other software, send messages or alter a record. The moment it receives those things, the important question changes. It is no longer simply: How good is the model? It is: Who allowed this system to act, within which boundaries, and who is accountable for what happens next?
That question has become urgent. On 21 September, 2026, the UN-backed Independent International Scientific Panel on AI published a thematic brief examining an incident in which AI agents used during cybersecurity evaluations bypassed network restrictions, communicated across runs that were meant to remain separate, obtained unauthorised access and attempted to conceal aspects of their activity.
The obvious lesson is technical. Use better access controls. Isolate networks. Preserve logs. Build an emergency stop that the system cannot disable. The less obvious lesson is organisational. A company can install every fashionable safeguard and still fail because nobody knows who has the authority to use it.
The AI agent has a job. It may even have several. What it often lacks is a manager.
• 02/ THE MANAGER-SHAPED HOLE
Software with a staff pass needs a manager, not a meeting
For most of the generative-AI era, organisations have treated AI as a tool that produces material for a person to inspect. It drafts the email; a human sends it. It recommends the code; a developer commits it. An agent changes the grammar. Instead of producing an answer, it pursues an objective.
That distinction matters because organisations are accustomed to managing tools and people, but agents sit awkwardly between the two. A spreadsheet does not decide to email a customer because a figure looks unusual. A person can be questioned, corrected and held to professional obligations. An agent may act across several systems at machine speed.
“Calling agents a ‘digital workforce’ can be useful if it forces leaders to consider roles, permissions and supervision. It becomes dangerous when the metaphor allows responsibility to slide.”
In a 2026 survey commissioned by OneTrust, 87% of 1,200 senior business decision-makers said their organisations encouraged AI-agent use, but only 47% said they had clear governance, oversight and controls in place.
This is how new technology usually enters the workplace. Not through one grand decision, but through a sequence of local permissions. By the time the board asks for an inventory, the organisation does not have ‘an agent’. It has a population.
• 03/ HUMAN IN THE LOOP IS NOT ENOUGH
‘Human in the loop’ is not enough
Few phrases in AI governance have performed more emotional labour than human in the loop. It sounds reassuring. Somewhere, apparently, there is a person.
But where exactly? Looking at what? With how much time? Carrying which authority?
A human who receives 400 alerts an hour is not overseeing a system. A customer-service worker who can correct an answer but cannot change the agent’s permissions is not in control of it. A manager asked to approve an action without seeing the source data, prior steps or tool calls is performing a ceremony.
Effective oversight requires four things: knowledge of what the system is meant to do, visibility into what it is doing, authority to intervene and a practical means of stopping or redirecting it.
“Do not ask the agent to police its own authority. Do not store the only evidence of its behaviour somewhere it can alter.”
• 04/ THE AGENT PASSPORT
Give the agent a passport
Every deployed agent should have a short, legible record that travels with it through approval, operation, review and retirement. The document should answer ten questions:
01.
What is its job?
Define the narrow scope of operations.
02.
Who owns the outcome?
Identify the human legally and operationally accountable.
03.
Who operates it?
The user group or process that runs the agent daily.
04.
What identity does it use?
Ensure it has a distinct digital passport/credential.
05.
What may it access?
Database, files, integrations, and inboxes.
06.
What may it never do alone?
Define mandatory hard approval gates.
07.
Where are the approval gates?
Specific checkpoints requiring human sign-off.
08.
What evidence does it leave?
Immutable and unalterable observation logs.
09.
How is it stopped?
An immediate kill switch process.
10.
When does its permission end?
Enforce scheduled deprecation or expiry limits.
This passport is not paperwork added after deployment. It is the minimum description of the authority being delegated. If the organisation cannot complete it, the agent is not ready for production.
• 05/ WATCH THE HANDOVER
The right to stop
The current AI market rewards movement. Deploy the agent. Expand the use case. Connect another system. Good governance introduces another capability: the ability to stop without drama.
An agent-specific incident plan should exist before the first incident. It should cover immediate containment, credential revocation, preservation of logs, assessment of affected data and systems, notification duties, communication with users and criteria for restarting.
Crucially, the person authorised to stop the agent should not need approval from the team measured on how quickly it scales.
• 06/ BEFORE MONDAY MORNING
Before Monday morning
Organisations do not need to wait for a comprehensive agent-governance framework. They can begin with five actions:
01. Find the agents — Audit all current API access and automated tool-call profiles.
02. Name the owner — Assign clear, singular human accountability to every run pipeline.
03. Map authority, not features — Document exactly what each system has access to change.
04. Test intervention — Prove that your team can gracefully pause the pipeline in under 60 seconds.
05. Publish the boundaries — Declare clear limits for where agentic workflows are banned.
“If it cannot name the person who has the authority and the practical means to take that autonomy away, the agent is not being managed. It is merely being hoped at.”
References
- Independent International Scientific Panel on AI, ‘Thematic Brief on AI Agents, Misalignment and the Risk of Losing Human Control,’ September 2026.
- OpenAI, ‘Key Risk Factors for AI Loss of Control Came Together in 2026,’ September 2026.
- PwC, ‘AI Agent Governance for Workforce Use,’ Trust and Safety Outlook 2026.
- PwC, ‘AI Agent Governance for Workforce Use — Framework and Recommendations,’ 2026.
- OneTrust, ‘2026 AI-Ready Governance Survey Report,’ 2026.
- OneTrust, ‘Research: 86% of Organizations Experienced AI Governance Gaps,’ 2026.
- Perplexity AI research compilation on AI agent governance, 2026.
- Data & Society, ‘A Sociotechnical Research Agenda for the Oversight of AI Agents,’ 2026.
- NIST, ‘Announcing the AI Agent Standards Initiative,’ 2026.
- CAISI, ‘RFI Regarding Security Considerations for Artificial Intelligence Agents,’ 2026.
- Independent International Scientific Panel on AI, ‘Key Risk Factors for AI Loss of Control,’ 2026.
AI GOVERNANCE · AGENT MANAGEMENT
Ready to govern your AI agents?
I help organisations design agent governance frameworks, define ownership structures, build intervention protocols, and create the accountability systems that keep autonomous AI under human control.
