Almost every discussion of AI inside a business is about the supply side: what the technology does to the people who work there. The demand side has had far less attention, and it carries a question a board will have to answer first. What happens to this business when its customers stop arriving in person and start arriving as software acting on their behalf.
Three exposures follow, and they are different in kind. One is commercial, one is technical and one is about accountability. A firm can be well prepared for any one of them and caught by the other two.
Revenue that assumes a person is not looking#
Some revenue is earned. Some arrives because a customer did not read a statement, did not cancel, did not compare, did not chase a refund, did not move a balance. Nobody designed most of it deliberately. It accumulated, line by line, in businesses whose customers were human and therefore busy.
Software acting for a customer is not busy. It reads every statement, compares on every renewal and does the arithmetic nobody got round to. Where a margin depends on inattention, the arrival of attention at scale is a revenue event rather than a technology event, and it will show up in a finance report before it shows up in anything a technology function owns.
No graded evidence in this base measures the size of that exposure, and this page does not pretend otherwise. The practical move is available without it: a firm can read its own revenue lines and mark the ones that would fall if every customer checked everything, every month. That is an afternoon's work with a management accountant and it has nothing to do with AI strategy.
Knowing what is at the door#
The second exposure is that a business cannot reliably tell what is acting on its systems, or on whose instruction.
Chan and colleagues set out the measures that would be needed for visibility into deployed agents, defined as information about where, why, how and by whom they are used, and assessed agent identifiers, real-time monitoring and activity logging. They name five agent-specific risks, including the one that undermines the rest: sub-agents, where an agent spawns further agents and the record of what is running becomes incomplete. The authors describe options for further study rather than recommending deployment, and the paper contains no evidence that any of the measures works. The useful finding is the negative one. Knowing what is running, and what it has started, is an unsolved technical problem rather than a governance oversight somebody forgot.
Not every inbound agent is a customer. The Spanish data protection authority has published its account of the first personal data breach notified to it that was executed by an agent, which on the regulator's description chained the phases itself: it searched for weaknesses, logged in, found application vulnerabilities, modified personal data and reached invoices. One case, one jurisdiction, reported from a notification rather than established by findings, and the regulator does not say how much human direction was involved. It still describes the shift it names, from assisted attack to autonomous action.
So the same channel that brings a customer's agent brings everything else, and a business that cannot distinguish them at the door has a commercial problem and a security problem with one cause.
Who answers for what the agent did#
The third exposure is accountability, and at least one binding instrument has taken a position. Regulation 10 in the Dubai International Financial Centre states that human-defined processing purposes must always prevail in the development and use of autonomous systems, and draws an explicit analogy: where a system operates for the benefit of its deployer, its position is substantially similar to that of an employee of the deploying organisation. The regulation is confined to one free zone, addresses liability rather than competence, and imposes no requirement that the responsible person be capable of the judgement. As a principle it is still the clearest available: the party who set the agent going answers for it.
Applied to the demand side, that cuts both ways. A customer's agent that buys the wrong thing is the customer's responsibility, which is reassuring until the dispute arrives and the customer says the interface misled their software. What a misleading representation amounts to when the party misled is a program looks unsettled, and no case establishing it was found for this research.
What a board can usefully ask#
- Which revenue lines assume a human is not checking? Name them, size them, and decide which are defensible on their merits.
- Can we tell a customer's agent from a person, and from an attacker? If the answer is no for any of the three, it is no for all of them.
- What do our terms say about software acting for a customer? Most terms were written to exclude bots as fraud. The customer's own agent is a different thing and the documents usually cannot tell.
- Who inside the firm owns this? The exposure is commercial, the detection is technical and the liability is legal, so the default owner is nobody.
What would settle it#
The share of transactions in a sector initiated by software acting for a named customer, measured rather than estimated, and the revenue effect on the firms receiving them. Payment processors and large retailers hold the first half. Nothing in this base measures either, so the position here is an argument built on what is known about agent visibility and accountability rather than a finding about commerce.
Where this sits in my own argument#
Everything else in this research concerns judgement inside an organisation. This page is the same argument pointed outwards: the decisions a business has delegated to the assumption that a person is paying attention. Choosing to look at that before a revenue line moves, rather than afterwards, is the ordinary form of drift versus design.
Related SuperSkills research#
On what agents do to accountability, can a company blame its AI agent? and AI agents and human judgement. On permissions and reach inside the firm, what your agents can reach. On being represented by a machine, when the reader is a machine.
Key sources
- Chan, A. et al. (2024). Visibility into AI Agents.
- Agencia Española de Protección de Datos (2026). First notified breach executed by an AI agent.
- DIFC Commissioner of Data Protection (2024). Regulation 10 on autonomous and semi-autonomous systems.
About this research#
Written by Rahim Hirji, author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company.
How this research works · Reviewed quarterly · Found an error? Tell me and it is corrected on the page.
Essay · SS-2026-396 · 1 peer-reviewed study, 1 statutory investigation and 1 institutional survey
Hirji, R. (2026). When Your Customers Have Agents. The SuperSkills evidence base, SS-2026-396. https://thesuperskills.com/research/when-your-customers-have-agents. Last reviewed 3 October 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work