Back to news
AI agent governance
agentic AI
AI governance
AI Act

Who is responsible for AI agents? 10 questions every company should ask in the agentic era

The rise of AI agents marks a new stage in the digital transformation of businesses. Following conversational assistants, organizations are seeing the emergence of agents capable of acting, automating processes, interacting with applications, and making certain decisions. But a critical question emerges: who is responsible for these agents? The article explains that the real challenge is no longer creating AI agents, but governing them. According to Deloitte's State of AI in the Enterprise 2026 study, only 21% of organizations claim to have a mature governance model for AI agents, even as their adoption accelerates sharply. To avoid risks, every company should ask ten fundamental questions: Who is responsible for an agent when it makes a mistake? How can the proliferation of redundant agents be avoided? How should agent ownership be managed when its creator leaves the company? How can hundreds or even thousands of agents be administered? How can their access to sensitive data be controlled? How can their real value and contribution to performance be measured? How can their regulatory compliance be guaranteed? How should their level of autonomy be supervised? How can they be integrated into existing business processes? How can it be ensured that their operation reflects the company's values?

Who is responsible for AI agents? 10 questions every company should ask in the agentic era

La gouvernance des agents IA est le cadre organisationnel qui définit les responsabilités, les périmètres d'action et les contrôles pour les agents autonomes. Un modèle de gouvernance mature permet aux entreprises de déployer des agents IA en toute sécurité, réduisant les risques d'erreurs et d'incohérences tout en assurant une conformité réglementaire essentielle à 79% des entreprises qui avancent plus vite sur le déploiement que sur le pilotage.

Who is responsible for AI agents?

10 questions every company should ask itself in the agentic era

For several years, companies focused on a relatively simple question:

How to use artificial intelligence?

This question is not disappearing. But its nature is changing.

With generative AI, organizations first deployed assistants capable of answering, drafting, searching, or summarizing. They are now entering a new phase: that of AI agents, capable of executing tasks, interacting with applications, coordinating processes, and, in some cases, collaborating with each other.

An assistant produces a response. An agent can trigger an action.

This difference is essential. It transforms AI into a subject of governance, in the same way as applications, data, or access to information systems.

The question is therefore no longer just:

How to use AI?

It becomes:

How to govern a growing population of digital agents acting within the enterprise?

Adoption is moving faster than governance

According to a global study published by Deloitte in 2026 among 3,235 business and IT leaders in 24 countries:

  • 74% of organizations plan to use AI agents significantly by 2027;
  • only 21% report having a mature governance model in place to manage them today.

The gap is considerable:

Nearly eight out of ten companies are moving faster on deployment than on steering.

Source: Deloitte, State of AI in the Enterprise 2026.

The situation is reminiscent of the early years of cloud and Shadow IT. Usage is developing rapidly, while rules, responsibilities, and control mechanisms remain unclear.

However, a poorly governed agent is not just an imperfect tool. It can access sensitive data, modify a process, make a decision, or trigger an action without the company clearly knowing who is accountable for it.

The 10 questions to settle

AI agent governance is not just about choosing a platform or strengthening cybersecurity. It primarily consists of making a series of organizational decisions.

1. Who is responsible for an agent?

When an agent triggers an action, makes a decision, transmits erroneous information, or acts outside its scope, who bears the responsibility?

The creator? The business team? The IT department? The process owner? The management that authorized its deployment?

The answer cannot be "the agent."

As with a critical application or an outsourced activity, every agent should have:

  • a clearly identified owner;
  • a documented mission;
  • a scope of action;
  • a defined level of autonomy;
  • an escalation process;
  • a team capable of taking over responsibility for it.

Without an owner, the agent quickly becomes an orphaned asset.

2. What exactly is its scope of action?

An agent should not have access to everything that is technically available.

Its scope must specify:

  • the tasks it can execute;
  • the decisions it can make;
  • the actions that require human validation;
  • the situations in which it must stop or ask for help.

This clarification helps avoid a frequent confusion: giving an agent a general mission while its access rights allow it to act far beyond that mission.

3. Who validates its production release?

Creating an agent is becoming increasingly simple. Publishing it in a live environment should not be.

Before its production release, the company should be able to verify:

  • the relevance of the use case;
  • the quality of the data used;
  • the associated risks;
  • the granted rights;
  • the supervision mechanisms;
  • the ability to roll back.

Governance must therefore define who can create, test, approve, and publish an agent. These roles do not necessarily have to be assigned to the same person.

4. What level of autonomy can be granted to it?

Not all agents need the same level of freedom.

An agent that reformulates a document does not present the same risk as an agent that modifies an order, responds to a customer, grants a discount, or updates a sensitive file.

The organization must be able to define several levels of autonomy, for example:

  1. the agent observes and recommends;
  2. the agent prepares an action that must be validated;
  3. the agent acts within a predefined scope;
  4. the agent acts autonomously, with post-hoc control.

As the potential impact increases, human supervision must become more explicit.

5. What data can it use?

An agent is often only as powerful as the data it accesses.

Governance must specify:

  • which data is authorized;
  • which data is prohibited;
  • which permissions are inherited from the user;
  • which data can be retained;
  • how exchanges and access are audited.

An agent should never receive general rights simply because they are easy to configure. Its access must be proportionate to its mission and regularly reassessed.

Microsoft notably positions agent governance around three dimensions: security, administration, and impact measurement.

Source: Microsoft Learn, Copilot Controls Overview.

6. How to avoid overlapping agents?

In many companies, several teams are already creating similar assistants or agents:

  • HR agent;
  • support agent;
  • training agent;
  • quality agent;
  • sales agent.

A few months later, three or four different versions sometimes perform the same task, using different rules, data, and quality levels.

The result can be costly:

  • redundant investments;
  • inconsistent responses;
  • diverging data models;
  • degraded user experience;
  • difficulty identifying the correct version.

Governance must therefore rely on a centralized agent catalog, naming conventions, and a pooling logic.

7. What happens to an agent when its creator leaves the company?

This is one of the most underestimated questions.

What happens when:

  • an agent's creator changes positions;
  • a team is reorganized;
  • a service provider completes their mission;
  • an employee leaves the company permanently?

An agent must never depend on a single individual.

Like any critical application, it must be able to:

  • change ownership;
  • be documented;
  • be audited;
  • be taken over by another team;
  • be decommissioned in a controlled manner.

Continuity of responsibility must be planned from the design stage, not at the time of the creator's departure.

8. How to administer hundreds or thousands of agents?

A few dozen agents still seem easy to manage manually. The situation changes as soon as the organization has several hundred, or even several thousand.

The question then becomes:

  • Who can create an agent?
  • Who can publish it?
  • Who can modify it?
  • Who can delete it?
  • Who can connect it to sensitive data?
  • How to know which agents are still in use?

Modern platforms are evolving toward inventory, lifecycle management, access control, and audit capabilities. But these features only generate value if the organization defines the rules that govern them.

9. How to measure performance and created value?

The number of deployed agents is not an indicator of success.

The company must be able to measure:

  • frequency of use;
  • quality of results;
  • time saved;
  • errors avoided;
  • risks introduced;
  • operating cost;
  • value created for teams and customers.

An agent that is no longer used, that generates more corrections than it saves time, or whose cost exceeds the value created must be improved or retired.

10. When should an agent be stopped?

Governance should not only organize creation and deployment. It must also allow for decommissioning.

An agent should be retired when it:

  • is no longer used;
  • presents a level of risk that has become unacceptable;
  • duplicates an existing solution;
  • relies on obsolete data;
  • no longer creates sufficient value;
  • can no longer be properly supervised.

Knowing when to stop an agent is a sign of maturity. In the agentic age, the portfolio must constantly evolve: some agents are created, others are merged, replaced, or deleted.

Governance is not just a matter of tools

Faced with these challenges, many companies look for the right platform. This is necessary, but insufficient.

Tools allow for:

  • administration;
  • supervision;
  • auditing;
  • security;
  • measurement.

They do not, on their own, determine who is responsible, which decisions must remain human, or what risks the organization is willing to accept.

Governance therefore rests on three complementary pillars.

The three pillars of AI agent governance

1. Management platforms

The company must have the capacity to:

  • inventory agents;
  • track their usage;
  • control their access;
  • assign owners;
  • manage their lifecycle;
  • measure their value.

Without visibility, no sustainable governance is possible.

2. Organizational rules

Every organization should define:

  • creation rules;
  • publication rights;
  • approval criteria;
  • levels of autonomy;
  • human supervision mechanisms;
  • conditions for retirement or replacement.

The subject becomes comparable to application governance, with one major difference: agents can act, adapt, and interact with multiple systems.

3. Company values

The governance framework must reflect the organization's principles.

For example:

  • which decisions remain human;
  • which risks are acceptable;
  • which data is protected;
  • what transparency obligations apply to agents;
  • what level of explainability is expected.

This approach is consistent with the philosophy of the European AI Act, which is based notably on responsibility, transparency, and risk management.

A new function will emerge: Agent Management

Historically, companies manage employees, processes, applications, and data.

Tomorrow, they will also have to manage a growing population of agents.

Some organizations are already starting to consider roles such as:

  • Agent Owner;
  • Agent Operations Manager;
  • AI Governance Lead;
  • Agent Portfolio Manager.

These functions will not necessarily be new full-time jobs in all companies. They primarily represent responsibilities that must be clearly assigned.

The challenge is no longer to create an agent.

The challenge is to be able to manage a thousand of them.

What leaders should do right now

Most companies already have the beginnings of governance for applications, data, cybersecurity, and access.

They should now apply the same discipline to AI agents.

An initial approach may consist of:

  1. inventorying the agents already created within the organization;
  2. identifying their owners and use cases;
  3. mapping their access to data and applications;
  4. classifying their level of risk and autonomy;
  5. defining rules for creation, publication, and decommissioning;
  6. measuring the value actually produced.

This approach allows for a transition from a logic of scattered experimentation to a logic of a managed portfolio.

The Pivotal Skills AI Perspective

At Pivotal Skills AI, we observe that the success of an AI strategy rarely relies on technology alone.

The determining factors are generally:

  • use cases;
  • skills;
  • responsibilities;
  • governance;
  • the measurement of created value.

The arrival of agents further reinforces this reality.

Before scaling up the number of agents, organizations would benefit from evaluating their maturity, management capabilities, and governance model in order to build sustainable and value-creating adoption.

The Digital Skills Analyzer can notably contribute to measuring usage, the AI maturity of teams, and the real impact of AI initiatives within the organization.

Conclusion

The organizations that create the most value will likely not be those that deploy the most agents.

They will be those that know how to:

  • assign them an owner;
  • limit their scope of action;
  • control their access;
  • supervise their autonomy;
  • measure their value;
  • decommission them when they are no longer useful or sufficiently controlled.

The question is no longer just about what AI agents can do.

It is now necessary to decide who can authorize them, supervise them, and be accountable for them.

Sources

Frequently asked questions

Pourquoi la gouvernance des agents IA est-elle cruciale pour les entreprises ?

La gouvernance des agents IA est cruciale car ces agents peuvent déclencher des actions, prendre des décisions et accéder à des données sensibles. Sans un cadre de gouvernance clair, les entreprises s'exposent à des risques accrus d'erreurs, de non-conformité et de difficultés à identifier les responsabilités, comme le souligne le fait que seulement 21% des organisations ont un modèle de gouvernance mature selon Deloitte.

Qui est responsable lorsqu'un agent IA commet une erreur ou agit en dehors de son périmètre ?

La responsabilité d'un agent IA ne peut pas incomber à l'agent lui-même. Chaque agent doit avoir un propriétaire clairement identifié, une mission documentée et un périmètre d'action défini. Cela assure qu'une équipe ou une personne puisse en reprendre la responsabilité en cas de problème, évitant ainsi un actif orphelin.

Comment une entreprise peut-elle éviter la prolifération d'agents IA redondants ?

Pour éviter la redondance, une entreprise doit mettre en place un catalogue centralisé des agents, des règles de nommage strictes et une logique de mutualisation. Cela permet de s'assurer que plusieurs équipes ne développent pas la même tâche, évitant les investissements superflus et les incohérences de réponses.

Comment gérer la propriété et le cycle de vie d'un agent IA si son créateur quitte l'entreprise ?

Un agent IA ne doit jamais dépendre d'un individu. Comme toute application critique, il doit pouvoir changer de propriétaire, être documenté, audité et repris par une autre équipe. La continuité de responsabilité doit être planifiée dès la conception de l'agent pour éviter toute interruption ou perte de contrôle.

Comment les entreprises peuvent-elles mesurer la valeur et la performance réelles des agents IA ?

La mesure de la valeur et de la performance des agents IA ne se limite pas au nombre d'agents déployés. Elle doit inclure la fréquence d'utilisation, la qualité des résultats, le temps économisé, les erreurs évitées, le coût de fonctionnement et la valeur créée pour les équipes et les clients. Un agent qui ne crée plus de valeur doit être amélioré ou retiré.