- What is an AI agent?
- When agents become part of the workforce, who manages them?
- Should AI agents appear on an organisation chart?
A named person, with the competence to do the work the agent does, the authority to stop it, and a record of having exercised both. That is the direction every serious framework points, and almost no organisation has arranged. European law already says it in terms: a deployer of a high-risk system must assign human oversight to natural persons "who have the necessary competence, training and authority, as well as the necessary support". The unresolved problem sits underneath. Chan and colleagues, writing on visibility into AI agents, state that we lack methods for determining when an agent has created a sub-agent. Management assumes you can see what you are managing.
The answer, in one line
A named person with three things: the competence to evaluate the work the agent does, the authority to suspend it without asking anyone, and a record of having exercised both.
Agency law had the vocabulary before the technology arrived#
Noam Kolt, in an article forthcoming in the Notre Dame Law Review, argues that the useful frameworks for this already exist: the economic theory of principal-agent problems and the common law doctrine of agency relationships. Applied to AI agents, they name three problems precisely. Information asymmetry, where the agent knows things about its own process the principal does not. Discretionary authority, where the agent must be given latitude for the delegation to be worth anything, and that same latitude carries the risk. Loyalty, where the agent's objective and the principal's interest come apart.
The contribution that matters for a manager is the second half of Kolt's argument. The conventional solutions to principal-agent problems, incentive design, monitoring and enforcement, may not be effective for governing agents that make uninterpretable decisions and operate at unprecedented speed and scale. Every management technique a human organisation uses to control delegation assumes the delegate is slow enough to catch and legible enough to correct. Kolt's conclusion is that new technical and legal infrastructure is required, organised around inclusivity, visibility and liability.
This is a law review argument rather than an empirical finding, and it should be read as one. Its value is that it stops the conversation restarting from first principles. Organisations have several centuries of practice at the question of who is accountable when someone acts on your behalf, and the answer has never been the delegate.
You cannot manage what you cannot see#
Chan and colleagues, at the ACM Conference on Fairness, Accountability and Transparency in June 2024, set out the practical measurement problem. They define visibility as information about where, why, how and by whom AI agents are used, and assess three categories of measure: agent identifiers, real-time monitoring and activity logging. Each has implementations varying in intrusiveness and informativeness, and each applies differently across centralised and decentralised deployment.
Two of their risk arguments describe things a manager would have to handle. On delayed and diffuse impacts, they work through a hiring agent given a long-horizon goal that screens applications, interviews, decides and then analyses the performance of its own hires, and note that bias in such a loop could be hard to identify and become deeply entrenched, with the most severe consequences visible only in aggregate across companies. On sub-agents, they are blunt about the gap:
Stopping an agent from causing further harm might involve intervening not only on the agent, but also on any relevant sub-agents. Yet, this process may be difficult because we lack methods for determining when an agent has created a sub-agent.
Read that against any org chart. A manager of humans knows how many people report to them. A manager of agents may not know how many agents are running under the one they authorised. Every span-of-control assumption in management practice fails at that point, and the failure is technical rather than organisational, so no amount of governance policy fixes it.
The framework that names the capability cost#
Singapore's Infocomm Media Development Authority published its Model AI Governance Framework for Agentic AI in January 2026. Of the national frameworks this research has read, it is the only one that names the workforce consequence rather than the risk consequence alone. Section 2.4.3:
As agents take over entry level tasks, which typically serve as the training ground for new staff, this could lead to loss of basic operational knowledge for the users. Organisations should identify core capabilities of each job and provide sufficient training and work exposure so that users retain foundational skills.
Section 2.4 also warns of "the potential loss of trade craft" and requires "sufficient training... to ensure that humans retain core skills". A governance framework has arrived at the argument this estate makes about missing rungs from an entirely separate direction, which is the most useful kind of corroboration.
It is guidance rather than statute, and it should be described that way. What it settles is that the deskilling risk of agent deployment is no longer a contrarian position held by people who write about human capability. A regulator has written it down.
European law has already named the person#
Article 26 of Regulation (EU) 2024/1689 sets out what a deployer of a high-risk system must do, and three of its paragraphs read as a job description for whoever manages an agent that falls in scope.
Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.
Paragraph 5 requires the deployer to monitor operation on the basis of the instructions for use, to inform the provider and the market surveillance authority without undue delay where the system presents a risk, and to suspend use of that system. Paragraph 6 requires retention of the automatically generated logs under the deployer's control for a period appropriate to the intended purpose, and at least six months. Paragraph 7 adds an obligation most organisations have not budgeted for:
Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system.
Four duties, and each one implies a person. Somebody assigns the oversight. Somebody monitors. Somebody decides to suspend, which is an authority question rather than a technical one. Somebody keeps the logs and can produce them. See who can override an AI system and how to audit an AI-assisted decision.
Should an agent appear on the organisation chart?#
The question sounds like a category error and is not. An org chart is a record of accountability, not of sentience or employment. It answers one question: if this goes wrong, whose name is on it. An agent performing work that a person is accountable for belongs on the chart for the same reason a contractor, an outsourced team or a critical system owner does, and leaving it off does not remove the accountability. It removes the record of where it sits.
Three things follow if you take that seriously. The agent needs an owner rather than a sponsor, meaning a named individual and not a steering group. It needs a scope statement that a person can read and check against behaviour, which is what NIST's playbook means when it requires assigned responsibilities to supersede, disengage or deactivate a system showing performance inconsistent with intended use. And it needs a review of its work in the same cycle as a person's, because an agent whose output has never been sampled is producing unverified work at volume.
The awkward case, which nobody has answered, is what happens when a person manages more agents than people. The estate's central concern arrives through the operating model at that point: the job becomes supervision of work the person may not be able to do. See who supervises work they cannot do.
Why the manager gets less capable while the span gets wider#
Lisanne Bainbridge described the pattern in 1983, about process control rather than language models. Automating the routine parts of a task leaves the human with the hardest residue, monitoring and exception handling, while removing the routine practice that built the competence to do it. Her conclusion is the one every agent deployment plan should carry: automation makes the remaining human role harder rather than easier.
Applied here, the manager of agents is asked to catch the exceptions in work they no longer perform, at a volume and speed that no longer permits reading it all. Shao and colleagues, interviewing 1,500 US domain workers across 104 occupations about 844 O*NET tasks, found worker preferences diverging sharply from technical capability, including an "Automation Red Light Zone" where the capability exists and workers do not want it used. Their Human Agency Scale is a useful instrument for this decision precisely because it separates what the tool can do from what the people doing the work think it should.
Acemoglu, Kong and Ozdaglar give the formal version of the long-run risk: a dynamic model in which agentic AI substitutes for the human effort that produces general knowledge, with a conditional tipping point beyond which general knowledge vanishes despite high-quality personalised advice. It is a theoretical model with no empirical estimation, and the authors say so. What makes it worth citing is that the erosion argument can be stated with its assumptions visible, which is more than most of the vocabulary in this area manages.
What to put in place before the second agent#
- One named owner per agent, at a grade with authority to stop it. Not a committee. The test is whether that person could suspend the agent this afternoon without asking anyone.
- A competence rule for the owner. They should be able to produce or evaluate a sample of the agent's work unaided. Where nobody in the organisation can, that is the finding, and the deployment decision changes.
- An inventory that includes agents you did not commission. Chan and colleagues' identifier argument exists because the population is not self-evident. Start from what is calling your systems, not from what you approved.
- Logs kept for a stated period, and someone whose job is to read a sample. Six months is the European floor for high-risk systems. Retention without sampling produces evidence for an investigation and no early warning.
- A written stop condition and a tested stop. NIST's playbook names five triggering conditions for deactivation, including risks exceeding tolerance thresholds and mitigation beyond the organisation's capacity. A stop that has never been exercised is a plan rather than a control. Deployment is not a ratchet.
- A sub-agent question in every review. Ask what this agent can instantiate, what permissions those inherit, and how you would know. If the answer is unclear, the scope is wider than the approval.
- An answer to Article 26(7) if you have European staff. Informing workers' representatives before a high-risk system goes into service at the workplace is a consultation timeline, not a notice, and it has to start before deployment.
- A capability line in the business case. The IMDA framework asks for identified core capabilities per job and sufficient work exposure to retain them. That is a staffing and rota decision, made at the point of deployment or not at all. See the capability audit.
Rahim's earlier reading of the agent shift#
"Agentic AI" (2024) framed the category break in the terms this page uses: the difference between an intern who waits for instructions and a colleague who sees what needs doing, and the question of whether agents need training and guidance in the way new employees do. "The Agents Are Here. You're Just Not Paying Attention" (March 2026) is the developed version. The European Business Review piece of 21 August 2026, "Why the Real AI Risk is Not Automation, but Accountability Gaps in Leadership Decisions", sets out the accountability tests and the HATS and HATE framing.
Attribution note, kept strictly. HATS and HATE are Hirji's, are post-book, and are not book content. Missing rungs and synthetic seniority are his coinages with dated first publication. The principal-agent framing is Kolt's, the visibility taxonomy is Chan and colleagues', the ironies of automation are Bainbridge's, and the Human Agency Scale is Shao and colleagues'. Capability debt appears here as description and carries no claim of first use.
No field study has tested any of these recommendations#
It does not claim there is evidence that any of this works. The recommendations are derived from legal obligation, published governance frameworks and the human factors literature. No field study has tested whether a named agent owner with stop authority produces better outcomes than a steering group, because the deployments are too new and nobody has run the comparison.
It does not claim a settled definition of an agent. Chan and colleagues use the term for systems with relatively high degrees of agency, distinguishing them from systems that only aid human decision-making, and they note that current agents sometimes struggle with simple tasks. The word is used for at least three different things in commercial marketing, and a governance rule that does not define its own scope will be argued around.
It does not claim the European provisions apply to your agents. Article 26 binds deployers of high-risk systems as classified by the Regulation, and most commercial agent deployments will fall outside that. The provisions are cited as the clearest published statement of what oversight requires, which is a different claim from a compliance obligation.
It does not claim to answer whether agents can manage other agents. That question is on this research's watch list, and it stays there until there is something to cite beyond vendor description.
Key sources
- Kolt, N. (2025). Governing AI Agents. Notre Dame Law Review, Vol. 101, forthcoming.
- Chan, A., Ezell, C., Kaufmann, M., Wei, K., Hammond, L., Bradley, H., Bluemke, E., Rajkumar, N., Krueger, D., Kolt, N., Heim, L. and Anderljung, M. (2024). Visibility into AI Agents. FAccT '24.
- European Union (2024). Regulation (EU) 2024/1689, Article 26: Obligations of deployers of high-risk AI systems.
- Infocomm Media Development Authority, Singapore (2026). Model AI Governance Framework for Agentic AI, Version 1.0.
- National Institute of Standards and Technology. AI Risk Management Framework Playbook, MANAGE 2.4.
- Bainbridge, L. (1983). Ironies of Automation. Automatica, 19(6).
- Shao, Y. et al. (2026). Future of Work with AI Agents.
- Acemoglu, D., Kong, D. and Ozdaglar, A. (2026). AI, Human Cognition and Knowledge Collapse.
Related SuperSkills research#
On agents, AI agents and human judgement and should I let an AI agent act on my behalf. On oversight, meaningful human oversight, why human in the loop is not a safeguard and the invisible work of oversight. On the supervision problem, who supervises work they cannot do and synthetic seniority. On decision authority, allocating AI decision rights and the delegation boundary map.
About this research#
Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. The FAccT paper was read in full at the conference's own copy, the Kolt abstract at arXiv, and the text of Article 26 at source; every quotation on this page is from the document rather than from reporting of it. No implementation date is given for the European provisions, because the timetable has been amended and the published texts consulted did not agree. Vendor material describing agent management products is deliberately not used.
Evidence review · SS-2026-163 · Graded against the published rubric
Hirji, R. (2026). When agents become part of the workforce, who manages them?. The SuperSkills evidence base, SS-2026-163. https://thesuperskills.com/research/who-manages-ai-agents. Last reviewed 2 September 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work