Your newest colleague has no manager.

Nobody owns the agent

An agent is AI that does not only answer, it acts. It sends, books, updates, approves. Nobody owns the agent means there is no named person who is responsible for what it does.

Something in your company is already sending things out with your name on them. Ask a leadership team who is responsible when one of those goes wrong and you get a pause, then four people looking at each other. This page is about closing that pause. Ten minutes per agent, no software.

8 min read 3 September 2026 Updated 7 September 2026
A team at work, each person with their own AI agent beside them
How it usually surfaces It sent four hundred emails over the weekend. On Monday three people each thought somebody else had set it up. A COO, 140 people, this summer

How it turns up

You have had at least one of these.

All three started as something small and useful, and none of them looked like a governance question at the time. I would not have flagged them either.

An empty desk with an agent still working beside it
The agent that came with the pilot A vendor set it up during a trial in January. The trial quietly became production. The person who configured it left in March and took the login with him. It is still running, and nobody switches it off because nobody can say which process stops if they do.
Someone at work with their agent alongside them
Four hundred emails over the weekend The follow-up agent kept mailing, including two accounts that were already in a dispute your sales lead was carefully managing. He heard about it from the client on Monday morning. Not from you, and not from a log.
A meeting room where the question is being asked
Who approved that discount The client asks. Three people look at each other and the fourth points at a tool. There is no record per decision, so the honest answer is that you cannot reconstruct it. That answer is fine internally and expensive in front of a customer.
Nobody owns the agent means an agent is doing the work of a person without anyone being responsible for what it does. More than half of organisations have had an agent step outside its permissions, and almost half had an incident involving one in the past year.1 Only 15% can say ownership is written down for most of their agents.1

In short

  1. An agent does the work of a person, and your company has nowhere to put it. No line on the chart, no owner, no review.
  2. Two thirds of companies have tried agents. Fewer than one in ten have got them to the point where they deliver real value.2
  3. More than half have had an agent do something outside what it was allowed to do.1 Only 8% say that never happens.
  4. The courts are not waiting for you to sort this out. Air Canada argued its chatbot was a separate entity responsible for its own words, and lost.4
  5. Ask a leadership team to name the owner of one specific agent and the room takes a second too long. That second is the whole problem, and it costs ten minutes to fix.

This page probably found you because

  • Something went out under your company's name that no person actually sent, and you had to explain it
  • You are about to sign off a second wave of agents and you would like the first wave to have owners before you do
  • A client or an auditor asked who is responsible for an automated decision and you needed a day to answer
  • Someone made a list of what is running and the list was longer than you thought

What you take away

  • Five lines that give one agent an owner, in about ten minutes
  • The numbers worth quoting in your own leadership team, with where each one comes from
  • What a court already decided about who answers for a bot
  • Where ownership sits in the five AI Culture Levels, and what moves you there

What we mean by it

Most leaders meet this as a tooling question. It behaves like an org chart question.

The conversation starts with which platform and which model, and those are answerable questions with vendors and pricing behind them. The one that gets skipped is much simpler than that. This thing does the work of a person, so where does it sit and who is its manager.

A new hire gets an onboarding, a manager and a review date in six weeks. An agent gets a login and a channel in Slack. Then it starts writing to your customers.

Most organizations can't say what those agents have accessed, what decisions they've made, or who is accountable when something goes wrong. Ben Kliger, co-founder and CEO of Zenity1

Read that back slowly. What it touched, what it decided, who answers for it. The first two usually take a week of digging to reconstruct, if you can reconstruct them at all. The last one you could settle on a Thursday afternoon, for nothing, and almost nobody has.

What the studies found

Two thirds tried. Fewer than one in ten got it working.

Nearly two thirds of organisations have piloted agents. Under 10% have scaled them to the point where they deliver real value.2 That gap is made of boring things. A scope, a name on it, a way to stop it. All the stuff that has to exist around an agent before anyone dares let it run on its own, and the name is the first of them.

Piloted agents ~66% Scaled to real value <10%
Enterprises that have experimented with agents, against those that have scaled them to deliver real value.2
53%
have had an agent exceed the permissions it was given. Only 8% say that never happens
47%
had a security incident involving an agent in the past year
15%
can say ownership is defined for most of their agents. A third can say it for a quarter to a half of them

That last number is the one I would put on the wall. Ownership is the cheapest part of the fix, and almost nobody has done it.

Ownership defined for 76 to 100% of agents 15% Ownership defined for 26 to 50% of agents 34% Organisations running 1 to 100 unsanctioned agents 54%
How much of the agent estate has a name under it, and how much of it nobody approved in the first place.1

Where it comes from

Nobody skipped a step. There was no step.

It arrived as a tool, so it got treated like one

Nobody assigns an owner to a spreadsheet formula. An agent comes in through the same door as a Slack plugin, so it inherits the same amount of attention, which is none. Then it starts doing things you would want a junior to check with someone about first. The behaviour moves. The paperwork does not.

AI agents are already operating at scale as part of the enterprise digital workforce, but security and governance haven't kept pace with their autonomous actions. Hillary Baron, AVP of Research at the Cloud Security Alliance1

Owning it costs something, so nobody volunteers

Being the owner means your name is on it at three in the afternoon when it does something strange. Nobody gets promoted for that. Until somebody in charge says out loud that owning an agent is part of a job rather than a punishment for having been curious, staying quiet is the sensible move. In most companies it has never been said.

An agent without an owner is a colleague nobody is managing. It still shows up every day. Paul Musters

Your org chart has no box for it

This is the honest one. A chart shows people and who reports to whom. An agent works, has access, produces output and costs money every month, and it is not employed by anyone. Most companies solve that by leaving it off the chart, which quietly means it belongs to everybody. Anything that belongs to everybody gets reviewed by nobody.

That is also why this comes back after every clean-up. You can list the agents you can see and still have no answer for the one that shows up next month, because the thing you fixed was the list and not the gap in the chart.

Which level is your company on?

Six questions, three minutes, and no name attached. You get your level, what it is costing you there, and what one step up would change.

Do the Culture Level scan
Three colleagues going through their agents at a table

A check that works

Five lines. Ten minutes per agent.

Pick one agent that is running in your business today. Take the first one you can think of. Fill in these five lines on one page.

Agent record Name of the agent
  1. What it may do, and what it may not.One sentence each. “May send follow-up mail to leads that have not replied in five days. May not mail an account with an open complaint.”
  2. Who owns the output.One name, of one person. A department does not answer at three in the afternoon, and the person who happened to set it up may have left in March.
  3. Who may change how it behaves.And who approves that change. If the answer is anyone with the login, write that down, because that is the finding.
  4. How you would know it went wrong.And within how long. If the honest answer is “when a client tells us”, you have your first fix.
  5. Who switches it off.By name, and how. Somebody should be able to do it from their phone on a Saturday.

If you cannot fill in all five within ten minutes, you have found the gap. Now do the second agent.

There is a harder version I use with clients. Ask three people, separately, to list every agent and automation running in their part of the business. Then compare the lists. In most companies the union is a good deal longer than any single list, and the ones that only appear once are the ones to look at first.

Where it sits

Agents arrive at Level 2. Owners show up at Level 4.

In the five AI Culture Levels we use with clients, agents usually arrive at Level 2 or Level 3. Ownership appears at Level 4. That distance is where this problem lives.

01Campfire60%
02Wild West25%
03Blueprint10%
04Engine4%Agents get an owner here
05Ecosystem1%
Share of organisations per level. Agents tend to arrive at Level 2 and 3. A named owner, a scope and a review are Level 4 behaviour, where about 4% of organisations sit.6

Level 2, Wild West, is daily individual use with no shared standard. Agents show up here as somebody's clever experiment. Level 3, Blueprint, is where the workflows get written down, and it is usually where the first agent quietly becomes load-bearing. Neither level has a place to put an owner, because neither level has decided that AI is part of how the company runs.

Level 4, Engine, is where that changes. AI is in the operating model, so an agent is treated the way you treat a function: it has a scope, a name above it, a review, and a way to stop it. About 4% of organisations are there. That is a small number and it is honest.

One thing worth knowing before you place yourself. Most companies are not on one level. Engineering is often two levels ahead of finance, and the agents with the least oversight are rarely in the team you are watching. We read the company at its lowest function, because that is where the next incident comes from.

What a measurement shows that an inventory does not

An Operating Profile in use. Personality type and AI level in one profile, with the agents that fit it.

A list of agents tells you what exists. It does not tell you whether the person whose name is on one can actually judge its output. That is the part that decides whether ownership is real or on paper. Somebody at Level 4 can look at what their agent produced and say this is wrong, do it again. Somebody at Level 1 will forward it, because it looks finished.

That is why the measuring happens per person: how somebody thinks and works, and how far along they are with AI. Then an agent gets an owner who can actually hold it. In practice that means the owner is often not the person who built it, and that is usually the right outcome.

About emaho

emaho measures one Operating Profile per person: personality type and AI level in a single profile. On that we build a personal set of AI agents that fit how that person works, inside the tools they already use. Fifteen minutes to complete, first profile free, built for companies between 20 and 500 people.

Fifteen minutes per person. No credit card, no strings.

A review session where the agents are on the screen

What to do

Five steps. The first one takes an afternoon.

Start with the list. Ask every team lead to write down what is running in their part of the business, including the things that came in with a tool and the ones somebody built on a Friday. Expect the total to surprise you, because more than half of companies are running unapproved agents they never counted.1 The list is only the thing that makes the next step possible.

Then put a name under each one. One person, written down, said out loud in the room. This is where it stalls, every time. People hear the word volunteer and their hands stay down. So do not ask for volunteers. Assign it the way you would assign any other part of a job. And if nobody is willing to own a particular agent even then, you have your answer about whether it should be running at all.

Write the boundaries on one page per agent, using the five lines from the test above. No framework, no policy document that needs a lawyer. Five lines that a new colleague can read in two minutes and act on.

Put a review in the calendar. Twenty minutes a quarter with the owner: what it did, what it got wrong, whether the scope still fits. Skip that and within six months it has quietly gone back to being nobody's, whatever the document says.

Last one, and in my experience it is the one that gets skipped. Check whether the owner can actually judge what comes out. Somebody who cannot tell good work from work that merely looks finished is a signature on a form, and the agent runs unwatched underneath it.

Made your list? Send me the number

Tell me how many agents you found and how many had a name under them. I will tell you what that ratio usually means and what I would do first. No pitch. You get an answer, usually the same day.

Message me on WhatsApp

What waiting costs

The bill arrives with nobody's name on it.

The one people say out loud is liability, and it stopped being theoretical in February 2024. A tribunal in British Columbia held Air Canada responsible for what its chatbot told a passenger about bereavement fares. The airline argued the chatbot was a separate entity, responsible for its own words. The tribunal did not accept that, and awarded damages.4 The amount was small, about 650 Canadian dollars. The principle is not: what your automation says, your company said. I am not a lawyer and one Canadian tribunal is not a rule for the Netherlands, so treat it as a direction rather than a verdict about your situation.

Then there is money that has already gone. Gartner expects more than 40% of agentic AI projects to be cancelled before the end of 2027, and puts inadequate risk controls in the same sentence as cost and unclear value.3 Projects rarely die because the technology failed. They die because nobody could answer what happens when it is wrong, so it never got out of the pilot.

And then there is the one that never makes it into a business case, which is the one I would actually worry about. Once a team has watched an unowned agent make a mess, the appetite for the next one drops to nothing. You end up with the worst combination available: the agents that are already running keep running unsupervised, and the ones that would have helped never get started. People will call that caution in the meeting. What it actually is, is a company that has learned to be scared of its own tools.

Asked and answered

Questions that come up about unowned agents

Who is responsible when an AI agent makes a mistake?
The company that put the agent in front of the customer. In February 2024 the British Columbia Civil Resolution Tribunal held Air Canada liable for what its website chatbot told a passenger about bereavement fares, rejecting the argument that the chatbot was a separate entity responsible for its own statements. Internally the question is narrower: which named person answers for that agent's output. In most companies today, nobody does.
What does it mean to own an AI agent?
It means one named person is responsible for what the agent produces, can change how it behaves or approve a change, would know if it went wrong, and can switch it off. A team name is not ownership, and neither is the person who happened to configure it. If you cannot write those four things down for a specific agent, it does not have an owner yet.
How many companies have named owners for their AI agents?
Few. In the Cloud Security Alliance's 2026 study of 445 IT and security professionals, only 15% said ownership was defined for 76 to 100% of their agents, while 34% said it was defined for just a quarter to a half of them. More than half also reported running between 1 and 100 agents that nobody had approved.
How do you know whether the person who owns an agent can actually judge its output?
You measure the person, not the agent. emaho builds one Operating Profile per person: personality type and AI level in a single profile. That tells you who can look at what an agent produced and say this is wrong, do it again, and who will forward it because it looks finished. In practice the right owner is often not the person who built the agent.
What is an AI agent register?
A single list of every agent and automation running in the business, with five lines per agent: what it may and may not do, who owns the output, who may change it and who approves that, how you would know it went wrong and within how long, and who switches it off. One page per agent. It takes about ten minutes to fill in and it is the cheapest control you can put in place.
Can we hold the vendor responsible if their agent gets it wrong?
Your contract with the vendor and your obligation to your customer are two different things. A customer who was given the wrong price by something on your website is dealing with you, as Air Canada found. Vendor terms may give you recourse afterwards, but they do not move the question of who answers first. This is not legal advice, and the answer depends on your contracts and jurisdiction.
What is an AI agent scope violation?
It is an agent doing something outside the permissions it was given: reading data it should not reach, changing a setting, or acting on an account it was told to leave alone. The Cloud Security Alliance found in 2026 that 53% of organisations had experienced one, and only 8% said it never happens. Most were not caught in minutes; detection ran into hours or days.
What does emaho do about AI agent accountability?
emaho works on the people side of it. Every person gets an Operating Profile, personality type and AI level in one profile, and on that we build a personal set of AI agents that fit how that person works, inside the tools they already use. Each agent has a name under it from the first day. The first profile is free, it takes fifteen minutes, and it is built for companies between 20 and 500 people.
Should an agent be owned by a person or by a team?
A person. Team ownership reads well on a slide and fails on a Saturday afternoon, because everybody assumes somebody else is looking. The team can do the work. One name carries it, the way a manager carries a function while the whole team does the job.
Why do so many AI agent projects get cancelled?
Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, naming escalating costs, unclear business value and inadequate risk controls. In practice the third one often triggers the first two: nobody can answer what happens when the agent is wrong, so it never leaves the pilot and the spend has nothing to show for it.
How does AI agent ownership relate to AI maturity?
Agents usually arrive at Level 2 or Level 3 of the five emaho AI Culture Levels, as somebody's experiment or as part of a documented workflow. A named owner, a written scope and a review are Level 4 behaviour, where AI is part of how the company runs. About 4% of organisations are at that level, which is why unowned agents are the normal case rather than the exception.

Getting going

Give one agent a name this week. Then the rest.

The five lines cost you ten minutes per agent. What they cannot tell you is whether the person whose name goes on it can judge what it produces. That is what we measure, starting with yourself.

  1. One evening, one list of namesEvery agent gets a person. You will find two you cannot fill in, and those two are the finding.
  2. Then check what the name can carryA profile per person tells you who can hold an agent to account and who would forward whatever it produced.
  3. Agents shaped around the ownerIf the person whose name is on it works differently from the person who built it, the pairing was wrong from day one.

First profile free · no credit card · built for companies of 20 to 500 · you decide what your team gets to see

Not ready to put your team in anything yet? Start with the level of the company instead. The Culture Level scan is six questions, three minutes, and asks nothing of you.

Paul Musters

Paul Musters

Fifteen years of leadership and team development in Dutch scale-ups. That practice now sits in software: one Operating Profile per person, with agents that actually fit. He writes these pages from what he runs into with clients, not from a research summary.

LinkedIn · paul@emaho.world · WhatsApp

Sources and numbers used on this page
  1. Cloud Security Alliance, Enterprise AI Security Starts with AI Agents, April 2026. Commissioned by Zenity, 445 responses from IT and security professionals, collected September and November 2025. Source of: 53% have had an agent exceed its permissions, 8% say it never happens, 47% had an incident involving an agent in the past year, 54% run between 1 and 100 unsanctioned agents, 15% have ownership defined for 76 to 100% of agents and 34% for 26 to 50%, 31% have formally adopted an agent policy, 13% feel well prepared for coming AI regulation. Quotes from Ben Kliger (Zenity) and Hillary Baron (CSA) come from the same release.
  2. McKinsey, 2025. Nearly two thirds of enterprises have piloted AI agents, fewer than 10% have scaled them to deliver real value.
  3. Gartner, press release, 25 June 2025. Over 40% of agentic AI projects expected to be cancelled by the end of 2027, because of escalating costs, unclear business value or inadequate risk controls.
  4. Moffatt v. Air Canada, British Columbia Civil Resolution Tribunal, decision of 14 February 2024. Air Canada held liable for negligent misrepresentation over information its website chatbot gave a customer about bereavement fares. Damages of CA$650.88, around CA$812 including interest and fees. Air Canada's argument that the chatbot was a separate entity responsible for its own statements was rejected.
  5. Gartner poll of 3,412 webinar attendees, January 2025. 19% had made significant investments in agentic AI, 42% conservative, 8% none, 31% waiting or unsure.
  6. emaho AI Culture Levels. Share of organisations per level, calibrated against BCG 2025 and McKinsey 2025.

Numbers are quoted as published. Where a figure is described as around or roughly, that is how the source states it. Nothing on this page is legal advice.