
A CIO at a regional insurer walked through the evolution of how an agent in his claims operation had quietly grown up. It started as a summarizer. It read first-notice-of-loss submissions and produced a clean brief for the intake team. Useful, low risk, nobody objected.
Then it started drafting the adjuster assignment, because the summaries were good and the team was already making that call the same way every time. Then someone on the engineering side noticed that the manual click to accept the draft was pure friction, since the recommendation was accepted 94 percent of the time. So they removed the click. It shipped in a sprint, as a configuration change, and nobody wrote a memo about it.
Eleven weeks later a claim involving a fatality was routed into the standard auto queue and sat there for four days. The review meeting opened with the only question that mattered: who approved letting it assign? Nobody had. There was no decision to point to, no owner, no threshold, no document that said how far this thing was allowed to go. The boundary had moved by itself, one reasonable convenience at a time.
That is the real state of agentic AI in most enterprises right now. The technology conversation is loud and the authority conversation has barely started.
Agentic AI Is an Org Design Problem Wearing a Technology Costume
Every organization already has a system for deciding who can commit the company to what. It is called delegation of authority. A buyer can approve a purchase order to a dollar threshold. A regional director can settle a claim up to a limit, and above it the matter escalates to someone with a bigger signature. None of this is glamorous, and all of it is load-bearing.
An agent placed into a workflow is a new actor in that system. It executes work, it makes calls, and its output has consequences the company owns. But almost nobody runs it through the process they would run a human hire through. We would never onboard a claims analyst without a job description, a manager, an authority limit, and a rule for when to raise a hand. We are deploying agents with none of those things and calling the gap a technology risk.
The numbers say this is close to universal. EY’s 2026 AI Risk and Governance Survey of 202 senior AI executives at companies above one billion dollars in revenue found that 91 percent are using agentic AI, while 49 percent say their governance framework has not been updated to address agentic requirements at all. Eighty-five percent acknowledge that at least some of their agentic systems execute actions with no real-time human involvement, and 26 percent admit their organization cannot detect unauthorized agents operating inside it.1
Read those together. Most large enterprises have agents taking action, governed by a framework written for something that only produced text, and a quarter cannot reliably tell you what agents are running.
Ability to Act Is Not the Same as Scope of Access
The most useful distinction I have seen on this comes from Gartner, which predicts that by 2027, 40 percent of enterprises will demote or decommission autonomous agents because of governance gaps discovered only after a production incident. Their diagnosis is precise: failures cluster where organizations conflate an agent’s ability to act with the scope of access it has been granted.2
Those are two different permissions and they get bundled together constantly. Ability to act is whether the agent can write, send, commit, or change something. Scope of access is the territory in which it may do so. An agent that can send email is one thing. An agent that can send email to your top fifty customers is a different thing with the same technical capability.
Gartner sorts agents into four autonomy levels, each needing different governance. Observe agents are read-only and produce output for the requester. Advise agents generate recommendations a human reviews and executes. Act-with-approval agents write, send, or modify only after explicit sign-off on each action. Act-autonomously agents execute inside guardrails, with humans reviewing exceptions and aggregate outcomes rather than individual decisions.
Applying the same controls across all four is the failure mode. Lock down the Level 1 agents and you slow delivery to a crawl and push teams into shadow development. Apply Level 1 comfort to a Level 4 agent and you have handed real authority to something with no owner. The insurance agent crossed from Level 2 to Level 3 in a sprint, then from Level 3 to Level 4 when the approval click was deleted. Nobody noticed because no one was tracking the level.
A Governance Agent Watching an Agent Is Still an Agent
There is a shortcut being sold right now that deserves a flat answer. When leaders ask how to supervise agents at scale, the vendor response is increasingly a supervisory agent: a second system that monitors the first, flags anomalies, and enforces policy.
That is a fine control. It is not accountability. An agent watching an agent is still an agent, and no board will accept a monitoring layer as the answer to who was responsible. Accountability requires a person with a name, a budget, and a job affected by the outcome. Automation can extend a human’s reach. It cannot be the terminal point of a chain of responsibility, because it cannot be held to anything.
McKinsey’s 2025 survey of nearly 2,000 respondents found this is what separates the organizations getting value from the ones generating incidents. High performers are distinguished by human-in-the-loop rules, rigorous output validation, centralized oversight, and senior leaders visibly involved in governance rather than delegating it downward.3 The differentiator is human, and it is specifically executive.
Five Things a Decision Right Has to Specify
If an agent is a new actor in your authority system, it needs the same five elements you would define for any role with real consequences. This is the checklist I put in front of clients before an agent moves past pilot.
Scope. What decisions is this agent permitted to make, stated as decisions rather than capabilities? “Assign standard auto claims under a severity threshold” is a scope. “Claims triage” is a job title.
Authority ceiling. The limit, expressed in the units your delegation of authority already uses. Dollars, severity tier, customer segment, record count, irreversibility. If your human thresholds are in dollars and your agent thresholds are in API permissions, the two systems cannot be reconciled and nobody can audit either one.
Named owner. One person, not a committee and not a function. The person who would be asked to explain the decision if it appeared in a regulator’s letter. Ownership that lands on “IT” lands on nobody.
Escalation trigger. The specific, testable conditions under which the agent stops and hands the decision to a human. Confidence below a threshold, a value above a line, a customer on a list. Write the trigger before deployment, because writing it afterward means writing it during an incident.
Change control on the boundary itself. Everybody skips this one, and it is what failed at the insurer. Moving an agent from advise to act is a governance decision, not a configuration change. It requires the same approval as expanding a human’s signing authority, and it should leave the same paper trail.
Who Owns the Boundary
Someone has to be accountable for how far agents may go, and in most organizations that role does not currently exist. It is not the CIO, who owns the platform rather than the business consequence of a claims decision. It is not the CISO, whose remit is protecting the enterprise rather than setting commercial authority. It is not model risk in isolation, which was built to validate models, not to grant operating authority to actors.
The workable answer I keep landing on is that the business owner of the process owns the boundary, with a central function setting the classification standard and holding the register. The head of claims decides how far a claims agent may go, because the head of claims owns the outcome. A central AI governance function defines the autonomy levels, maintains the inventory of what is running at what level, and requires that every level change be approved by the accountable business owner. That mirrors how delegation of authority already works, which is the point. You are not inventing a new system. You are extending the one you have to a new kind of actor.
Start With the Decisions, Not the Agents
The instinct when a leadership team finally takes this seriously is to inventory the agents. Start one step earlier. Inventory the decisions in the process, and for each one, name who holds the authority today and what the limit is. Then decide, deliberately and on the record, which of those decisions an agent may hold and to what ceiling. Do that and the technology questions become tractable, because you finally know what you are configuring toward. Skip it and you get what the insurer got: a series of individually sensible optimizations that added up to an authority transfer nobody chose.
Autonomy will keep scaling whether or not your governance catches up. The only real question is whether the boundary gets set on purpose, by someone whose name is on it, or whether it keeps drifting outward one removed click at a time.
Look at the agents running in your organization this quarter. For each one, can you name the person who decides how far it may go? If the answer takes longer than a few seconds, the boundary is already moving without you.
References
- Ernst & Young LLP, “EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap,” September 15, 2026. A survey of 202 US senior AI decision-makers at publicly traded companies with at least one billion dollars in annual revenue found that 91 percent use agentic AI, 49 percent had not updated their governance framework for agentic requirements, 85 percent reported agentic systems executing actions without real-time human involvement, and 26 percent could not detect unauthorized AI agents operating internally.
- Gartner, Inc., “Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure,” May 26, 2026. Gartner predicts that by 2027, 40 percent of enterprises will demote or decommission autonomous AI agents due to governance gaps identified only after production incidents, and recommends proportional governance across four autonomy levels: observe, advise, act with approval, and act autonomously.
- McKinsey & Company, “The state of AI in 2025: Agents, innovation, and transformation.” Based on responses from 1,993 participants across approximately 105 countries, the survey found that 62 percent of organizations are at least experimenting with AI agents, and that high performers are distinguished by human-in-the-loop rules, rigorous output validation, centralized AI governance, and visible senior leadership involvement in oversight.







