shrugging emoji
Editorial

Nobody Agrees on Who Owns an AI Agent

5 MINUTE READ|Digital WorkplaceDigital Workplace|Jul 23, 2026
David Barry avatar
By
SAVED
HR, security and IT all claim ownership of enterprise AI agents. None can govern all the risks. The bigger problem? Companies can't see the agents they have.

AI agents are spreading across HR, finance, IT and customer service, and enterprise vendors are racing to own the same job: governing them. HR platforms treat agents like employees, who are onboarded, assigned roles and tracked for performance. Security vendors treat them as infrastructure risk requiring independent attestation. ITSM and orchestration vendors treat them as a systems problem.

Three vendor categories and three governance products suggests there's no consensus on what an AI agent is, organizationally, and who has standing to control it.

A harder problem sits underneath: Employees are building their own agents faster than anyone can track them.

Whose Agent Is It?

An agent spanning HR, finance and customer systems needs one identity with permissions across all of them, which points toward whichever function controls identity and access: in most organizations, the CISO.

"HR can determine the roles and the organization can determine the intentions of such an agent, but the ultimate responsibility to decide what the agent can and cannot do rests on the one and only function," said Jose Lejin P J, principal member of technical staff at Salesforce.

The CISO can own the keys, but not the judgment about what each agent should be allowed to do with them. In other words, while identity control is necessary, it's not enough.

That distributed view goes further. An agent that uses HR, finance, security and customer systems creates a different category of risk in each domain: employment law in one, fraud controls in another, data exfiltration in a third and liability in a fourth.

No one function has the authority, expertise or incentive to govern all four well, said Mumtaz Kynaston-Pearson, principal legal counsel at Mimecast. "The vendors arguing otherwise are mostly describing the part of the problem they happen to sell into," she said.

A workable middle sits closer to shared risk ownership: escalation defaults to whichever domain carries the largest downside risk for the specific action. Money moves to finance, data moves to security, employment decisions to HR. Whichever team owns the risk of a specific action approves that action, under a shared set of rules that applies across the board, "like a school where the principal sets the overall rules, but each teacher still decides what happens in their own classroom," said Alice Sesay Pope, a former Amazon global vice president who ran a 10,000-person organization across Devices, Alexa and Prime Video.

Companies should build on governance structures that already exist, with the business owner accountable for outcomes, security governing identity and access and legal and compliance setting regulatory boundaries, agreed Pablo Gomez, an AI and agentic AI adoption consultant at FTI Consulting.

The variety of opinions suggest it will be a while before the issue of ownership is settled. It also assumes the company knows the agent exists — which, as it turns out, is a generous assumption.

AI-as-Employee Only Gets You So Far

One reason ownership is contested is that vendors and buyers keep reaching for the wrong analogy — treating agents like employees. The idea of managing agents like employees, who are onboarded, role-defined and monitored, is a useful starting point, but dangerous once it meets anything financial or security-sensitive.

A human employee carries an accountability infrastructure: legal liability, professional duties, the ability to be disciplined and judgment. An agent has none of that, and when it makes an unauthorized transaction, accountability points back to whoever configured its permissions and signed off on them, not to the agent itself.

It’s a bigger problem once money or production systems are involved. There is no performance improvement plan for an agent; only access control, and if the behavior is bad, the response is to terminate the agent, not coach it, Lejin P J said.

Onboarding an AI system the way a company onboards a new hire "doesn't tell you what it's allowed to click, spend or access in real time, which is exactly what matters once money or sensitive data is involved," Pope said.

The Fixes That Aren't Really Fixes

All of this assumes an agent was commissioned in the first place. In many companies, it wasn't. All you have to do is ask who's allowed to build one.

"In most companies we work with, the honest answer is that it's open by default," said Vinay Thakker, co-founder and CTO of cloud modernization firm KloudStax. Platforms such as Copilot and Gemini turn agent creation into something nobody explicitly grants, because it happens inside a workspace a team already pays for.

Capability, not creator, may be the more useful line to draw. There is a meaningful difference between an agent that only searches internal information and one that can change code, access customer data or trigger workflows, said Adam Dalloul, founder of EmpirioLabs, which runs fully managed hosted agents.

The trouble is that this principle assumes companies can classify agent capability before something breaks, which brings us back to the visibility problem.

Most companies are stuck choosing between "the Wild West, where anyone can spin up an agent and the enterprise has zero visibility and control," or approval processes so slow that "innovation goes underground anyway," said Dave Trier, CEO of AI governance firm ModelOp, who advises Google, AWS and Microsoft Azure.

A related problem is what happens to an agent when the person who built it leaves. Agents built inside sanctioned platforms usually inherit the creator's identity and get caught by standard leaver processes. The risk concentrates in two places: agents running on shared service accounts that no individual owns, and agents built outside IT's line of sight in the first place. In both cases, the audit lag is the real damage — access nobody intended, discovered "as a record changed somewhere it shouldn't have been, two quarters later," Trier said.

Unsolved Ownership Problem

There are proposed fixes, but none of them solves the ownership problem and each is worth reading against the interest of the person proposing it.

Learning OpportunitiesView All

One option is to make dependency the trigger: Once other parts of the business rely on an agent, it should be formalized and anchored to a per-agent identity, using tools such as Google Cloud's Agent Gateway, Thakker said. But while that answers when an agent should get an owner, it doesn't say who that owner is, and it happens to be an argument for the infrastructure Thakker's firm sells.

Trier rejects the organic approach. Waiting for dependency to force the issue "usually means you find out about the agent after something's already gone wrong." His alternative, "industrialized AI delivery," is a formal, automated lifecycle covering discovery, risk tiering, testing and change management. It's a more rigorous answer, and also the kind of managed process ModelOp sells.

A middle position comes closest to an ownership answer: Teams own the budget while an agent is experimental, but once others depend on it, "it should become an official company tool and go into one central inventory," Dalloul said. That doesn’t say who runs the inventory, or who is supposed to notice when dependency crosses the line.

The Agent Nobody Sees

Sanctioned and shadow agents are the same problem expressed differently. With sanctioned agents, people dispute who should control them. With shadow agents, control isn't contested, because nobody knows they exist.

Governance frameworks answer who's in charge once an agent is known to exist. None answer how an organization finds out it exists. That makes discovery the missing governance function: continuous, automated and owned by someone whose job is to find agents, not approve them. Until a company has that, every ownership framework it adopts is really a framework for the agents it happens to be aware of.

fa-solid fa-hand-paper Learn how you can join our contributor community.

Main image: adobe stock

About the Author

David is a European-based journalist of 35 years who has spent the last 15 following the development of workplace technologies, from the early days of document management, enterprise content management and content services. Now, with the development of new remote and hybrid work models, he covers the evolution of technologies that enable collaboration, communications and work and has recently spent a great deal of time exploring the far reaches of AI, generative AI and General AI.

Featured Research