Who is responsible for AI agents?
10 questions every company should ask itself in the agentic era
For several years, companies focused on a relatively simple question:
How to use artificial intelligence?
This question is not disappearing. But its nature is changing.
With generative AI, organizations first deployed assistants capable of answering, drafting, searching, or summarizing. They are now entering a new phase: that of AI agents, capable of executing tasks, interacting with applications, coordinating processes, and, in some cases, collaborating with each other.
An assistant produces a response. An agent can trigger an action.
This difference is essential. It transforms AI into a subject of governance, in the same way as applications, data, or access to information systems.
The question is therefore no longer just:
How to use AI?
It becomes:
How to govern a growing population of digital agents acting within the enterprise?
Adoption is moving faster than governance
According to a global study published by Deloitte in 2026 among 3,235 business and IT leaders in 24 countries:
- 74% of organizations plan to use AI agents significantly by 2027;
- only 21% report having a mature governance model in place to manage them today.
The gap is considerable:
Nearly eight out of ten companies are moving faster on deployment than on steering.
Source: Deloitte, State of AI in the Enterprise 2026.
The situation is reminiscent of the early years of cloud and Shadow IT. Usage is developing rapidly, while rules, responsibilities, and control mechanisms remain unclear.
However, a poorly governed agent is not just an imperfect tool. It can access sensitive data, modify a process, make a decision, or trigger an action without the company clearly knowing who is accountable for it.
The 10 questions to settle
AI agent governance is not just about choosing a platform or strengthening cybersecurity. It primarily consists of making a series of organizational decisions.
1. Who is responsible for an agent?
When an agent triggers an action, makes a decision, transmits erroneous information, or acts outside its scope, who bears the responsibility?
The creator? The business team? The IT department? The process owner? The management that authorized its deployment?
The answer cannot be "the agent."
As with a critical application or an outsourced activity, every agent should have:
- a clearly identified owner;
- a documented mission;
- a scope of action;
- a defined level of autonomy;
- an escalation process;
- a team capable of taking over responsibility for it.
Without an owner, the agent quickly becomes an orphaned asset.
2. What exactly is its scope of action?
An agent should not have access to everything that is technically available.
Its scope must specify:
- the tasks it can execute;
- the decisions it can make;
- the actions that require human validation;
- the situations in which it must stop or ask for help.
This clarification helps avoid a frequent confusion: giving an agent a general mission while its access rights allow it to act far beyond that mission.
3. Who validates its production release?
Creating an agent is becoming increasingly simple. Publishing it in a live environment should not be.
Before its production release, the company should be able to verify:
- the relevance of the use case;
- the quality of the data used;
- the associated risks;
- the granted rights;
- the supervision mechanisms;
- the ability to roll back.
Governance must therefore define who can create, test, approve, and publish an agent. These roles do not necessarily have to be assigned to the same person.
4. What level of autonomy can be granted to it?
Not all agents need the same level of freedom.
An agent that reformulates a document does not present the same risk as an agent that modifies an order, responds to a customer, grants a discount, or updates a sensitive file.
The organization must be able to define several levels of autonomy, for example:
- the agent observes and recommends;
- the agent prepares an action that must be validated;
- the agent acts within a predefined scope;
- the agent acts autonomously, with post-hoc control.
As the potential impact increases, human supervision must become more explicit.
5. What data can it use?
An agent is often only as powerful as the data it accesses.
Governance must specify:
- which data is authorized;
- which data is prohibited;
- which permissions are inherited from the user;
- which data can be retained;
- how exchanges and access are audited.
An agent should never receive general rights simply because they are easy to configure. Its access must be proportionate to its mission and regularly reassessed.
Microsoft notably positions agent governance around three dimensions: security, administration, and impact measurement.
Source: Microsoft Learn, Copilot Controls Overview.
6. How to avoid overlapping agents?
In many companies, several teams are already creating similar assistants or agents:
- HR agent;
- support agent;
- training agent;
- quality agent;
- sales agent.
A few months later, three or four different versions sometimes perform the same task, using different rules, data, and quality levels.
The result can be costly:
- redundant investments;
- inconsistent responses;
- diverging data models;
- degraded user experience;
- difficulty identifying the correct version.
Governance must therefore rely on a centralized agent catalog, naming conventions, and a pooling logic.
7. What happens to an agent when its creator leaves the company?
This is one of the most underestimated questions.
What happens when:
- an agent's creator changes positions;
- a team is reorganized;
- a service provider completes their mission;
- an employee leaves the company permanently?
An agent must never depend on a single individual.
Like any critical application, it must be able to:
- change ownership;
- be documented;
- be audited;
- be taken over by another team;
- be decommissioned in a controlled manner.
Continuity of responsibility must be planned from the design stage, not at the time of the creator's departure.
8. How to administer hundreds or thousands of agents?
A few dozen agents still seem easy to manage manually. The situation changes as soon as the organization has several hundred, or even several thousand.
The question then becomes:
- Who can create an agent?
- Who can publish it?
- Who can modify it?
- Who can delete it?
- Who can connect it to sensitive data?
- How to know which agents are still in use?
Modern platforms are evolving toward inventory, lifecycle management, access control, and audit capabilities. But these features only generate value if the organization defines the rules that govern them.
9. How to measure performance and created value?
The number of deployed agents is not an indicator of success.
The company must be able to measure:
- frequency of use;
- quality of results;
- time saved;
- errors avoided;
- risks introduced;
- operating cost;
- value created for teams and customers.
An agent that is no longer used, that generates more corrections than it saves time, or whose cost exceeds the value created must be improved or retired.
10. When should an agent be stopped?
Governance should not only organize creation and deployment. It must also allow for decommissioning.
An agent should be retired when it:
- is no longer used;
- presents a level of risk that has become unacceptable;
- duplicates an existing solution;
- relies on obsolete data;
- no longer creates sufficient value;
- can no longer be properly supervised.
Knowing when to stop an agent is a sign of maturity. In the agentic age, the portfolio must constantly evolve: some agents are created, others are merged, replaced, or deleted.
Governance is not just a matter of tools
Faced with these challenges, many companies look for the right platform. This is necessary, but insufficient.
Tools allow for:
- administration;
- supervision;
- auditing;
- security;
- measurement.
They do not, on their own, determine who is responsible, which decisions must remain human, or what risks the organization is willing to accept.
Governance therefore rests on three complementary pillars.
The three pillars of AI agent governance
1. Management platforms
The company must have the capacity to:
- inventory agents;
- track their usage;
- control their access;
- assign owners;
- manage their lifecycle;
- measure their value.
Without visibility, no sustainable governance is possible.
2. Organizational rules
Every organization should define:
- creation rules;
- publication rights;
- approval criteria;
- levels of autonomy;
- human supervision mechanisms;
- conditions for retirement or replacement.
The subject becomes comparable to application governance, with one major difference: agents can act, adapt, and interact with multiple systems.
3. Company values
The governance framework must reflect the organization's principles.
For example:
- which decisions remain human;
- which risks are acceptable;
- which data is protected;
- what transparency obligations apply to agents;
- what level of explainability is expected.
This approach is consistent with the philosophy of the European AI Act, which is based notably on responsibility, transparency, and risk management.
A new function will emerge: Agent Management
Historically, companies manage employees, processes, applications, and data.
Tomorrow, they will also have to manage a growing population of agents.
Some organizations are already starting to consider roles such as:
- Agent Owner;
- Agent Operations Manager;
- AI Governance Lead;
- Agent Portfolio Manager.
These functions will not necessarily be new full-time jobs in all companies. They primarily represent responsibilities that must be clearly assigned.
The challenge is no longer to create an agent.
The challenge is to be able to manage a thousand of them.
What leaders should do right now
Most companies already have the beginnings of governance for applications, data, cybersecurity, and access.
They should now apply the same discipline to AI agents.
An initial approach may consist of:
- inventorying the agents already created within the organization;
- identifying their owners and use cases;
- mapping their access to data and applications;
- classifying their level of risk and autonomy;
- defining rules for creation, publication, and decommissioning;
- measuring the value actually produced.
This approach allows for a transition from a logic of scattered experimentation to a logic of a managed portfolio.
The Pivotal Skills AI Perspective
At Pivotal Skills AI, we observe that the success of an AI strategy rarely relies on technology alone.
The determining factors are generally:
- use cases;
- skills;
- responsibilities;
- governance;
- the measurement of created value.
The arrival of agents further reinforces this reality.
Before scaling up the number of agents, organizations would benefit from evaluating their maturity, management capabilities, and governance model in order to build sustainable and value-creating adoption.
The Digital Skills Analyzer can notably contribute to measuring usage, the AI maturity of teams, and the real impact of AI initiatives within the organization.
Conclusion
The organizations that create the most value will likely not be those that deploy the most agents.
They will be those that know how to:
- assign them an owner;
- limit their scope of action;
- control their access;
- supervise their autonomy;
- measure their value;
- decommission them when they are no longer useful or sufficiently controlled.
The question is no longer just about what AI agents can do.
It is now necessary to decide who can authorize them, supervise them, and be accountable for them.
Sources
- Deloitte, State of AI in the Enterprise 2026 and analysis "Agentic AI is scaling faster than guardrails"
- Gartner, Top Strategic Technology Trends 2025 - Agentic AI
- European Commission, governance and implementation of the AI Act
- European Commission, frequently asked questions on the AI Act
- Microsoft Learn, Copilot Controls Overview
- Microsoft Learn, Security and governance
- Microsoft Adoption, Agent Governance Whitepaper

