← Research
Research

When agents become part of the workforce, who manages them?

Every management technique for controlling delegation assumes the delegate is slow enough to catch and legible enough to correct. Agents are neither, and the org chart is a record of accountability rather than of employment.

Last reviewed: 2 September 2026

Principal-agent law applied to artificial agents, the sub-agent gap nobody can currently close, the one national framework that names the capability cost, and the four duties Article 26 puts on a named human.

Questions this page answersQuestion this page partly answersAll 811 questions this research covers

A named person, with the competence to do the work the agent does, the authority to stop it, and a record of having exercised both. That is the direction every serious framework points, and almost no organisation has arranged. European law already says it in terms: a deployer of a high-risk system must assign human oversight to natural persons "who have the necessary competence, training and authority, as well as the necessary support". The unresolved problem sits underneath. Chan and colleagues, writing on visibility into AI agents, state that we lack methods for determining when an agent has created a sub-agent. Management assumes you can see what you are managing.

The answer, in one line

A named person with three things: the competence to evaluate the work the agent does, the authority to suspend it without asking anyone, and a record of having exercised both.

Share as a card

Agency law had the vocabulary before the technology arrived#

Noam Kolt, in an article forthcoming in the Notre Dame Law Review, argues that the useful frameworks for this already exist: the economic theory of principal-agent problems and the common law doctrine of agency relationships. Applied to AI agents, they name three problems precisely. Information asymmetry, where the agent knows things about its own process the principal does not. Discretionary authority, where the agent must be given latitude for the delegation to be worth anything, and that same latitude carries the risk. Loyalty, where the agent's objective and the principal's interest come apart.

The contribution that matters for a manager is the second half of Kolt's argument. The conventional solutions to principal-agent problems, incentive design, monitoring and enforcement, may not be effective for governing agents that make uninterpretable decisions and operate at unprecedented speed and scale. Every management technique a human organisation uses to control delegation assumes the delegate is slow enough to catch and legible enough to correct. Kolt's conclusion is that new technical and legal infrastructure is required, organised around inclusivity, visibility and liability.

This is a law review argument rather than an empirical finding, and it should be read as one. Its value is that it stops the conversation restarting from first principles. Organisations have several centuries of practice at the question of who is accountable when someone acts on your behalf, and the answer has never been the delegate.

You cannot manage what you cannot see#

Chan and colleagues, at the ACM Conference on Fairness, Accountability and Transparency in June 2024, set out the practical measurement problem. They define visibility as information about where, why, how and by whom AI agents are used, and assess three categories of measure: agent identifiers, real-time monitoring and activity logging. Each has implementations varying in intrusiveness and informativeness, and each applies differently across centralised and decentralised deployment.

Two of their risk arguments describe things a manager would have to handle. On delayed and diffuse impacts, they work through a hiring agent given a long-horizon goal that screens applications, interviews, decides and then analyses the performance of its own hires, and note that bias in such a loop could be hard to identify and become deeply entrenched, with the most severe consequences visible only in aggregate across companies. On sub-agents, they are blunt about the gap:

Stopping an agent from causing further harm might involve intervening not only on the agent, but also on any relevant sub-agents. Yet, this process may be difficult because we lack methods for determining when an agent has created a sub-agent.

Read that against any org chart. A manager of humans knows how many people report to them. A manager of agents may not know how many agents are running under the one they authorised. Every span-of-control assumption in management practice fails at that point, and the failure is technical rather than organisational, so no amount of governance policy fixes it.

The framework that names the capability cost#

Singapore's Infocomm Media Development Authority published its Model AI Governance Framework for Agentic AI in January 2026. Of the national frameworks this research has read, it is the only one that names the workforce consequence rather than the risk consequence alone. Section 2.4.3:

As agents take over entry level tasks, which typically serve as the training ground for new staff, this could lead to loss of basic operational knowledge for the users. Organisations should identify core capabilities of each job and provide sufficient training and work exposure so that users retain foundational skills.

Section 2.4 also warns of "the potential loss of trade craft" and requires "sufficient training... to ensure that humans retain core skills". A governance framework has arrived at the argument this estate makes about missing rungs from an entirely separate direction, which is the most useful kind of corroboration.

It is guidance rather than statute, and it should be described that way. What it settles is that the deskilling risk of agent deployment is no longer a contrarian position held by people who write about human capability. A regulator has written it down.

European law has already named the person#

Article 26 of Regulation (EU) 2024/1689 sets out what a deployer of a high-risk system must do, and three of its paragraphs read as a job description for whoever manages an agent that falls in scope.

Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

Paragraph 5 requires the deployer to monitor operation on the basis of the instructions for use, to inform the provider and the market surveillance authority without undue delay where the system presents a risk, and to suspend use of that system. Paragraph 6 requires retention of the automatically generated logs under the deployer's control for a period appropriate to the intended purpose, and at least six months. Paragraph 7 adds an obligation most organisations have not budgeted for:

Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system.

Four duties, and each one implies a person. Somebody assigns the oversight. Somebody monitors. Somebody decides to suspend, which is an authority question rather than a technical one. Somebody keeps the logs and can produce them. See who can override an AI system and how to audit an AI-assisted decision.

Should an agent appear on the organisation chart?#

The question sounds like a category error and is not. An org chart is a record of accountability, not of sentience or employment. It answers one question: if this goes wrong, whose name is on it. An agent performing work that a person is accountable for belongs on the chart for the same reason a contractor, an outsourced team or a critical system owner does, and leaving it off does not remove the accountability. It removes the record of where it sits.

Three things follow if you take that seriously. The agent needs an owner rather than a sponsor, meaning a named individual and not a steering group. It needs a scope statement that a person can read and check against behaviour, which is what NIST's playbook means when it requires assigned responsibilities to supersede, disengage or deactivate a system showing performance inconsistent with intended use. And it needs a review of its work in the same cycle as a person's, because an agent whose output has never been sampled is producing unverified work at volume.

The awkward case, which nobody has answered, is what happens when a person manages more agents than people. The estate's central concern arrives through the operating model at that point: the job becomes supervision of work the person may not be able to do. See who supervises work they cannot do.

Why the manager gets less capable while the span gets wider#

Lisanne Bainbridge described the pattern in 1983, about process control rather than language models. Automating the routine parts of a task leaves the human with the hardest residue, monitoring and exception handling, while removing the routine practice that built the competence to do it. Her conclusion is the one every agent deployment plan should carry: automation makes the remaining human role harder rather than easier.

Applied here, the manager of agents is asked to catch the exceptions in work they no longer perform, at a volume and speed that no longer permits reading it all. Shao and colleagues, interviewing 1,500 US domain workers across 104 occupations about 844 O*NET tasks, found worker preferences diverging sharply from technical capability, including an "Automation Red Light Zone" where the capability exists and workers do not want it used. Their Human Agency Scale is a useful instrument for this decision precisely because it separates what the tool can do from what the people doing the work think it should.

Acemoglu, Kong and Ozdaglar give the formal version of the long-run risk: a dynamic model in which agentic AI substitutes for the human effort that produces general knowledge, with a conditional tipping point beyond which general knowledge vanishes despite high-quality personalised advice. It is a theoretical model with no empirical estimation, and the authors say so. What makes it worth citing is that the erosion argument can be stated with its assumptions visible, which is more than most of the vocabulary in this area manages.

What to put in place before the second agent#

Rahim's earlier reading of the agent shift#

"Agentic AI" (2024) framed the category break in the terms this page uses: the difference between an intern who waits for instructions and a colleague who sees what needs doing, and the question of whether agents need training and guidance in the way new employees do. "The Agents Are Here. You're Just Not Paying Attention" (March 2026) is the developed version. The European Business Review piece of 21 August 2026, "Why the Real AI Risk is Not Automation, but Accountability Gaps in Leadership Decisions", sets out the accountability tests and the HATS and HATE framing.

Attribution note, kept strictly. HATS and HATE are Hirji's, are post-book, and are not book content. Missing rungs and synthetic seniority are his coinages with dated first publication. The principal-agent framing is Kolt's, the visibility taxonomy is Chan and colleagues', the ironies of automation are Bainbridge's, and the Human Agency Scale is Shao and colleagues'. Capability debt appears here as description and carries no claim of first use.

No field study has tested any of these recommendations#

It does not claim there is evidence that any of this works. The recommendations are derived from legal obligation, published governance frameworks and the human factors literature. No field study has tested whether a named agent owner with stop authority produces better outcomes than a steering group, because the deployments are too new and nobody has run the comparison.

It does not claim a settled definition of an agent. Chan and colleagues use the term for systems with relatively high degrees of agency, distinguishing them from systems that only aid human decision-making, and they note that current agents sometimes struggle with simple tasks. The word is used for at least three different things in commercial marketing, and a governance rule that does not define its own scope will be argued around.

It does not claim the European provisions apply to your agents. Article 26 binds deployers of high-risk systems as classified by the Regulation, and most commercial agent deployments will fall outside that. The provisions are cited as the clearest published statement of what oversight requires, which is a different claim from a compliance obligation.

It does not claim to answer whether agents can manage other agents. That question is on this research's watch list, and it stays there until there is something to cite beyond vendor description.

Key sources

On agents, AI agents and human judgement and should I let an AI agent act on my behalf. On oversight, meaningful human oversight, why human in the loop is not a safeguard and the invisible work of oversight. On the supervision problem, who supervises work they cannot do and synthetic seniority. On decision authority, allocating AI decision rights and the delegation boundary map.

About this research#

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company. The FAccT paper was read in full at the conference's own copy, the Kolt abstract at arXiv, and the text of Article 26 at source; every quotation on this page is from the document rather than from reporting of it. No implementation date is given for the European provisions, because the timetable has been amended and the published texts consulted did not agree. Vendor material describing agent management products is deliberately not used.

How this research works  ·  Reviewed quarterly  ·  Found an error? Tell me and it is corrected on the page.

Evidence review · SS-2026-163 · Graded against the published rubric

Cite this page

Hirji, R. (2026). When agents become part of the workforce, who manages them?. The SuperSkills evidence base, SS-2026-163. https://thesuperskills.com/research/who-manages-ai-agents. Last reviewed 2 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

When agents become part of the workforce, who manages them?

A named person with three things: the competence to evaluate the work the agent does, the authority to suspend it without asking anyone, and a record of having exercised both. Article 26(2) of Regulation (EU) 2024/1689 states the principle for high-risk systems, requiring deployers to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 5 requires monitoring and suspension where the system presents a risk, and paragraph 6 requires the deployer to keep the system's automatically generated logs for at least six months.

Should AI agents appear on an organisation chart?

An organisation chart records accountability rather than sentience or employment, and it answers one question: whose name is on this if it goes wrong. An agent doing work a person is accountable for belongs on it for the same reason a contractor or a critical system owner does. Leaving it off does not remove the accountability, only the record of where it sits. Three things follow: a named owner rather than a sponsoring committee, a scope statement checkable against actual behaviour, and sampling of the agent's output on the same cycle as a person's review.

What is the sub-agent problem?

An agent can instantiate further agents to accomplish parts of a task, each of which may itself malfunction or be attacked. Chan and colleagues, in Visibility into AI Agents at FAccT 2024, write that stopping an agent from causing further harm might involve intervening not only on the agent but on any relevant sub-agents, and that this may be difficult because we lack methods for determining when an agent has created a sub-agent. Every span-of-control assumption in management practice fails at that point, and the failure is technical rather than organisational.

Does any regulator mention deskilling from AI agents?

Singapore's Infocomm Media Development Authority does, in its Model AI Governance Framework for Agentic AI published in January 2026. Section 2.4.3 states that as agents take over entry level tasks, which typically serve as the training ground for new staff, this could lead to loss of basic operational knowledge for users, and that organisations should identify core capabilities of each job and provide sufficient training and work exposure so that users retain foundational skills. Section 2.4 warns of the potential loss of trade craft. It is guidance rather than statute.

In this hub

Judgement, oversight and accountability

Who decides, who checks, and who is answerable when the machine was involved.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Agents are where this stops being a thought experiment. There is the AI agents and accountability version, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.