Nobody Owns the Agent
Every risk team knows who owns a data breach. Almost none can tell you who owns a decision an AI agent just made.
Every risk team knows who owns a data breach. Almost none can tell you who owns a decision an AI agent just made.
Three independent reads point at the same hole, and two of them landed in the same July window. Smarsh and FTI Consulting found 55% of enterprises are actively deploying AI while only 26% say their governance keeps pace. DigiCert found 78% of organizations have already had an AI-related incident or vulnerability, and nearly half have no centralized visibility into the AI running inside their own walls. Gartner had already projected that 40% of enterprise applications would carry task-specific AI agents by 2026, up from under 5% a year earlier. And last week, a fourth read landed on top of the other three: Arctera’s State of AI Governance 2026, surveying 500 compliance decision-makers in finance, healthcare, and energy, found that while 55% of organizations have core AI policies, training, and review steps in place, fewer than one in five, 19%, have the logging, retention, and detection controls needed to actually prove what an AI system did, who reviewed it, and where it went.
Sit with that last number next to one more from the same report: 71% of those organizations say they are very or extremely prepared to produce a defensible audit trail. Most of the market believes it has this handled. Fewer than one in five can actually produce the record.
The agents are shipping. The proof is not. And the ownership underneath both is not being named.
The advice arriving with those numbers is nearly unanimous: name an owner. Give AI risk to the CISO. Stand up an AI committee. Harvard Business Review put it plainly this month: you outsourced the AI, but you still own the risk.
That is right about the stakes and wrong about the unit.
The wrong unit
You cannot fix a boundary-crossing problem by adding one box to the org chart. An agent that touches customer service, procurement, code, and fraud detection in a single afternoon does not belong to any one function. Assigning “AI” to a single executive just moves the same gap up one level. The CISO owns the breach. Who owns the discount the pricing agent offered, the vendor it onboarded, the candidate it screened out?
Security owns the allow-list. Compliance, per Arctera’s own data, is where 60% of organizations say AI governance primarily sits today. Legal owns the data-processing terms. Engineering owns the pipeline that ships the agent. None of them own the decision the agent makes at 2 p.m. on a Tuesday, because the decision does not respect the boundary any one of those functions was built to police.
Default custody
When no one is named at the level of the decision, the risk does not disappear. It lands, by default, on whoever is nearest when it breaks. Call it default custody: the person nearest the incident inherits a decision they never made and never authorized. The support rep who relayed the answer. The manager who trusted the output. The compliance officer who signed an attestation built on 19% of the evidence they thought they had.
The default is not neutral. It is a quiet transfer of accountability, away from whoever chose the system and toward whoever happened to be standing next to it when the record turned out not to exist.
The unit of ownership is the decision, not the technology
A governed AI system names, for every decision the agent is allowed to make on its own, who owns it, where the human sits, and what happens when it is wrong. That is a smaller and harder question than “who owns AI,” and it is the only one that actually assigns accountability, because it attaches a name to the thing that can go wrong, not to the tool that does it.
This is also where Arctera’s finding does real work. Policy without an evidence layer is a promise, not a control. An organization can have a full AI policy, a training program, and a review step, exactly the 55% that do, and still be unable to answer the only question that matters after something goes wrong: what did the system do, who reviewed it, and where did it go. Proof and ownership are the same problem wearing different clothes. You cannot name an owner for a decision you cannot reconstruct.
Three questions worth asking before the next agent ships:
Which decisions is this system allowed to make on its own, and who has signed for each one?
When it is wrong, who finds out, and how fast, and can you actually produce the record that says so?
If it made a decision you would not have approved, what in your process would have caught it before the customer did?
If you cannot answer all three, the decision is already owned by default, by whoever is nearest. That is the arrangement most AI incidents are quietly running on, and per Arctera, four out of five organizations that think they are ready would find that out the hard way.
Unowned decisions do not stay unowned. They get inherited by default.
Sources for the figures cited (Smarsh/FTI Consulting, DigiCert/Propeller Insights, Gartner, Arctera/Hanover Research) and the HBR reference are listed below, each pulled from the primary release.
Fellowship Intelligence helps organizations govern the decisions AI is already making. The Diagnostic is the place to start. Learn more at fellowshipintelligence.com.




