From Sanskriti Khandelwal | Product & Market Analysis

Who Owns the AI Agent? Three Ownership Models, and What Each One Breaks

On this page

Only 21% of organisations report a mature governance model for agentic AI. Meanwhile 74% expect to be using agents by 2027. That gap is not a technology problem. It is an org chart problem, because AI agent ownership sits unassigned between IT, the business unit and security, and those three functions want different things.

Key takeaways

  • Ownership is four decision rights, not one job title. Who builds, who runs, who accepts the risk and who pays are separable. Most agent incidents happen at the seam where two of those rights sit in different reporting lines.
  • The title arrived before the authority did. IBM found 76% of surveyed organisations now have a chief AI officer, up from 26% a year earlier. Deloitte found only 21% with a mature agentic AI governance model.
  • Uniform control is the failure mode, not the fix. Gartner expects 40% of enterprises to have autonomous AI efforts partly derailed by 2027, through governance gaps found only after production incidents.
  • Match the model to your agent count, not your ambition. Below roughly 10 agents a central office is cheaper than a platform. Above that number, the central office becomes the queue everyone routes around.
21%Share of organisations reporting a mature governance model for agentic AI. Source: Deloitte, 2026.
76%Organisations with a chief AI officer, up from 26% a year earlier. Source: IBM Institute for Business Value, May 2026.
40%Enterprises Gartner expects to demote or decommission agents by 2027, after governance gaps surface in production. Source: Gartner, 2026.

The short answer

Who owns an AI agent? Three models work in practice: a central AI office that owns every agent, a platform team that owns the rails while business units own the agents, or ownership tiered by each agent's autonomy level. All three fail unless a named person, not a department, is accountable for each agent.

What "owning an agent" actually means

The word ownership hides four separate decision rights. Organisations argue about the word instead of the rights. Separating them is most of the work.

The first right is build. Someone specifies the agent, writes it and decides when it ships. The second is run. Someone is paged at 3am, holds the credentials and can stop it. The third is risk acceptance. Someone signs that this agent may act on customer records without a human checking each action. The fourth is budget. Some cost centre absorbs the token bill, and the incident.

Those four rights can sit in four different places without anything going wrong. The condition is that the handoffs are written down. Trouble starts when two of them are assumed by nobody. Risk acceptance is the one most often left blank. It is the only right that carries no upside for the person holding it.

The four decision rights, and where they usually sit
Decision rightWho typically holds itWhat breaks when it is unassigned
Build the agent.Business unit, or a central AI team.Duplicate agents doing the same job in three departments.
Run it in production.Platform or application engineering.No named pager, so incidents are found by customers.
Accept the residual risk.Frequently nobody at all.Agents ship with permissions nobody consciously granted.
Fund the agent.Business unit, or a central innovation budget.Cost has no owner, so nothing is ever switched off.

The middle column reflects patterns described in the surveys cited below, not a count. No public dataset breaks agent decision rights down by function.

Notice what is missing from that table. There is no row for the model provider or the orchestration framework. Those are procurement decisions. They are easier to settle than the four rows above, which is why teams spend months on them instead.

The evidence that ownership is where agents fail

Three 2026 surveys point at the same seam from different angles. None of them was designed to.

Deloitte's State of AI in the Enterprise 2026 covers 3,235 IT and business leaders across 24 countries. It found 21% with a mature governance model for agentic AI, against 74% who expect to be using agents by 2027. A separate Deloitte survey of 501 US senior leaders, fielded April to June 2026, found 39% calling themselves prepared on risk, security and governance. That was the fourth lowest readiness area measured.

Gartner reached the same place from the control side. Its analysts argue that one governance standard across every agent is itself the cause of failure. Shiva Varma, a Senior Director Analyst, put it directly. Enterprises treat agent governance as "binary, either locked down or fully trusted, and that is the root cause of failure."

Adoption is running ahead of the structure meant to hold it Share of surveyed leaders, 2026. Blue is adoption, red is readiness. Expect to use AI agents by 2027. 74% Large firms scaling agents in 2026. 40% Prepared on risk, security, governance. 39% Mature agentic AI governance model. 21% Sources: Deloitte State of AI in the Enterprise 2026, rows 1 and 4. McKinsey State of AI 2026, row 2. Deloitte US agentic survey, row 3.
These bars come from three different samples and cannot be subtracted from one another. What they agree on is direction. Intent to deploy runs at roughly double stated readiness to govern.

The IBM figure is the one worth sitting with. Chief AI officer prevalence rose from 26% to 76% in a single year. That is one of the fastest C-suite additions on record. Over the same period the readiness numbers barely moved. A title is the cheapest available response to an accountability gap, and it is the one most companies reached for first.

This is not an argument against the role. IBM also reports 5% higher return on AI investments at companies with a chief AI officer, and 79% of CEOs decentralising decision making. Those two findings sit awkwardly together. You cannot centralise accountability and decentralise decisions without saying which of the four rights moved.

Model 1: the central agent office owns everything

One team holds all four rights for every agent. It usually reports to a chief AI officer, or sits inside a centre of excellence. Business units request agents. The central office builds, runs, signs and funds them.

Where it works

This model is correct more often than its reputation suggests. It fits regulated industries and small agent estates. It fits any company where the binding constraint is consistency rather than throughput. Ten agents built by one team share an evaluation harness, a logging standard and one incident process. That is worth a great deal.

It also fits the first year honestly. With three agents in production, an operating model is overhead. I would not stand up a formal centre of excellence below that number.

Where it breaks

It breaks by becoming a queue. Every request enters one backlog, and the backlog grows faster than the team. Business units then do what people always do when a central function slows them down. They build outside it.

Gartner names both halves of this failure. Applying the same controls indiscriminately produces "over-restriction of simple agents, which slows delivery and drives shadow development, or under-restriction of more autonomous agents, which increases operational, security and compliance risk." The first half is the centre of excellence failure mode in one clause.

The second break is subtler. A central team can judge whether an agent is well engineered. It usually cannot judge whether the output is correct. Correctness lives in the domain. An agent summarising claims files is checked properly only by someone who reads claims files, and that person does not work in the central office.

Model 2: the platform owns the rails, the business unit owns the agent

The second model splits the four rights along a hard line. A platform team owns identity, credentials, logging, the evaluation harness and the ability to stop any agent. The business unit owns what the agent is for, whether it works, and the bill.

Where it works

Above roughly 10 agents across more than two domains, this is the only model I have seen scale. It removes the queue. A business unit needs no permission to build, only rails that already enforce the controls. My view is that the platform model is the only one that survives 20 agents.

It also puts the correctness judgement where the domain knowledge is. The platform team never decides whether a refund was justified. It guarantees that the refund was logged, attributable and reversible. That is the part which generalises, and the identity half of it is harder than it looks, as the piece on non human access and agent identity sets out.

Where it breaks

It breaks when the platform does not exist yet. Declaring a federated model before building the rails is the common expensive mistake here. Federated without a platform simply means nobody. Controls that were meant to be centralised are now absent everywhere, instead of present in one place.

The second failure is an incentive mismatch that tooling does not fix. The business unit captures the upside of an aggressive agent. The blast radius of a bad one is enterprise wide. Left alone, that asymmetry pushes every tenant toward more autonomy than the company would choose centrally. The counterweight is a named risk owner measured on something other than the agent's output. It also needs monitoring that survives the honeymoon period, covered in the piece on agent drift and the dashboard that stays green.

The same four rights, allocated three different ways Blue is a single clear owner. Red marks the seam where accountability is shared, and often lost. CENTRAL OFFICE. PLATFORM AND TENANTS. TIERED BY AUTONOMY. Build the agent. Central team Business unit Business unit Run in production. Central team BU on shared rails BU on rails Accept residual risk. Central team Split: name a person Rises with level Fund the agent. Central budget Business unit Business unit Read the third row across. Risk acceptance is ambiguous in two of the three models.
The third row is the one to argue about in the room. Every model allocates build and budget cleanly. Only the central office allocates risk acceptance without further work.

Model 3: ownership tiered by the agent's autonomy level

The third model stops asking who owns agents. It asks who owns this agent. Ownership escalates with what the agent can do, using a classification set at design time and re-checked at every material change.

Gartner's version separates two properties that are usually conflated. Autonomy is what an agent does without a human. Scope is the data and permissions it reaches. Its four levels run from observe, which is read only, through advise, then act with approval, then autonomous execution inside guardrails.

Ownership escalating with autonomy level
Autonomy levelWho accepts the riskWhat they are signing
Observe: read only, shows results.Team lead in the business unit.The data this agent reads is data the team may already read.
Advise: read only, recommends.The function head.Recommendations may be wrong, and a human still decides.
Act with approval.Function head plus a named approver.Approval is real, not a button clicked 400 times a day.
Autonomous inside guardrails.Executive owner plus security.The guardrails are enforced in credentials, not in a prompt.

Levels follow Gartner's published four-level model. The ownership column is our allocation, offered as a starting default rather than a standard.

Where it works

It fits mixed estates, which is nearly everyone by the second year. A read only agent that drafts a summary and an agent that issues refunds should not pass the same review. One standard for both forces you to pick which of the two you are wrong about. Tiering matches the cost of control to the size of the consequence.

It also makes the approval question concrete. Level three works only if the approver has time to approve properly, an argument set out in the piece on human in the loop architecture. An approval step nobody reads is a level four agent wearing a level three label.

Where it breaks

Agents climb the levels quietly. A level two adviser gets a write tool added in a sprint. The classification is not revisited, because nothing in the release process asks. Six weeks later the agent is level four and the org chart still names a team lead.

The fix is mechanical. Tie classification to a code change rather than to a review meeting, so a new write scoped credential triggers reclassification automatically. I think tiering is the right default. I also think most companies will implement it badly, because the trigger is the part that gets cut for time.

The rule all three models share: name a person, not a department

Whichever model you pick, one control carries most of the weight. Each agent has a single named human who accepts its residual risk. That name is written somewhere an auditor could find it.

For high risk systems in the EU this is law, not good practice. Article 26(2) of the EU AI Act says deployers "shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support." The wording is deliberate. Not a committee, not a function, and not a person without the authority to stop the thing. The wider set of duties is set out in the EU AI Act transparency checklist.

The same test works outside that scope and outside Europe. If you cannot name the person who would be paged when an agent acts wrongly tonight, the agent has no owner. The diagram does not change that. What the named person does day to day is a real job now, described in the piece on hiring an agent ops engineer.

The title spread fast. The governance did not follow. Share of surveyed organisations. Two different surveys, plotted on one scale for contrast. 100% 0% 2025 2026 26% 76% Chief AI officer. 21% Mature agent governance. Sources: IBM Institute for Business Value, May 2026. Deloitte State of AI in the Enterprise, 2026.
The red line has one measured point and is drawn flat for contrast, not because a 2025 figure exists. Treat it as a visual comparison rather than a trend.

How to choose, and what each choice costs you

The decision turns on two numbers you already know. How many agents you run, and how many distinct domains they touch. Ambition does not belong in the calculation.

Three ownership models compared
ModelBest fitMain failure modeEarly warning sign
Central agent office.Under 10 agents, regulated, consistency first.Becomes a queue, so teams build around it.Requests waiting a sprint for a first response.
Platform and tenants.Over 10 agents across several domains.Declared before the rails exist, so nobody owns anything.No shared kill switch and no shared audit log.
Tiered by autonomy.Mixed estates, as an overlay on either model.Agents climb levels without reclassification.An agent gained a write permission and nothing was re-signed.

The third row is an overlay rather than an alternative. The real choice is between the first two, with tiering applied on top of whichever you pick. Spend your attention on the last column, because each of those signs appears months before the incident.

Cost ownership should follow risk ownership. If a function head signs for an agent, the token bill should land in that function's budget. The return should be measured there too, which is the argument in agent payback by function. Split those two and you get agents nobody will defend and nobody will switch off.

Where this argument is weakest

Three problems with what you have just read, stated before someone else states them.

Three models is a simplification

Real organisations run hybrids, and the hybrids are often sensible. A company may centralise customer facing agents and federate internal ones. That is neither model one nor model two. Treat the three as reference points for a conversation, not as a taxonomy anyone should defend.

The evidence is survey evidence

Every number here comes from a self reported survey or an analyst prediction. "Mature governance model" is defined by the respondent. Technology leaders made up 55% of one Deloitte sample, which tilts what counts as maturity. The Gartner 40% is a forecast about 2027, not a measurement of anything. Nobody has published a controlled comparison of ownership models against agent outcomes.

The case for leaving ownership vague

There is a real argument on the other side. Premature structure kills experimentation. A company with two agents that convenes a governance board has bought overhead it cannot yet use. Ambiguity is cheap and reversible early. So the honest version of this post's claim is narrower than its title. Ownership stops being optional when an agent can write to a system of record, and most companies cross that line without noticing. The other ways pilots die are catalogued in the piece on agent pilot failure modes.

Frequently asked questions

Who should own AI agents in an organisation?

Ownership splits into four rights: build, run, risk acceptance and budget. The workable answer is that one named person holds risk acceptance for each agent, while build and run can sit wherever the skills are. Below roughly 10 agents, a central AI function can hold all four rights. Above that, business units should own agents and a platform team should own the shared rails.

What is an AI center of excellence and does it still work?

An AI centre of excellence is a central team that sets standards, builds shared tooling and reviews AI projects across the enterprise. It works while the agent count is low and consistency matters more than speed. It stops working when it becomes a queue. Gartner warns that over restriction of simple agents slows delivery and drives shadow development, which is the centre of excellence failure mode in one sentence.

Should IT or the business unit own an AI agent?

Both, in different senses, and the split has to be written down. IT or a platform team should own identity, credentials, logging, evaluation and the ability to stop an agent. The business unit should own what the agent is for, whether its output is correct, and the budget it consumes. The seam between those two is where accountability leaks, so name the person who accepts the residual risk.

Does a chief AI officer improve AI results?

The evidence is associative rather than causal. IBM's 2026 study of 2,000 CEOs found 76% of organisations now have a chief AI officer, up from 26% a year earlier. It also reported 5% higher return on AI investments at companies with one. That is a survey correlation. Firms appointing a chief AI officer are also firms investing more in AI, so treat the figure as directional.

How do you assign accountability for an autonomous AI agent?

Assign it to a person, not a function. The EU AI Act requires deployers of high risk systems to assign human oversight to natural persons with the necessary competence, training and authority. The same test works outside that scope. For each agent, record its name, the person paged when it acts wrongly, the actions it may take without approval, and the date the classification was last reviewed.

What is an AI governance structure for agents?

A working structure has three layers. A policy layer decides which autonomy levels are permitted and for what data. A platform layer enforces identity, logging and shutdown. An accountable owner is named for each agent. Gartner recommends classifying agents by autonomy and scope rather than applying one control set to all of them, because uniform governance produces either bottlenecks or unmonitored autonomy.

Where to start this week

Two exercises. Both take an afternoon, and neither needs budget.

First, build the four column list. One row per agent in production. One column each for who built it, who runs it, who signed for the risk and whose budget pays. Do it from memory, without asking anyone. The blank cells are the finding, and most of them will sit in the third column.

Second, run the reclassification test on one agent. Take the most autonomous agent you have. Check what it could do on the day it shipped against what it can do now. If those lists differ and nothing was re-signed in between, you know which model you are actually running.

If you take one thing

An operating model is a diagram. A named owner is a control. Companies keep buying the first and skipping the second, then find the gap during an incident.

References

  1. Gartner, Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure, 26 May 2026. Used for the 40% prediction, the Shiva Varma quotes and the four-level autonomy model. It is a prediction, not a measurement.
  2. CIO, Many autonomous agents doomed by governance failures, 2026. Used for the wording of the Gartner levels and the over restriction quote.
  3. IBM Newsroom, CEOs are Reshaping C-suite Roles for the AI Era, 4 May 2026. IBM Institute for Business Value with Oxford Economics, 2,000 CEOs, 33 countries, 21 industries, February to April 2026. Used for the 76%, 26%, 5% and 79% figures.
  4. Deloitte Insights, Agentic AI is scaling faster than guardrails, 2026. State of AI in the Enterprise 2026, 3,235 IT and business leaders across 24 countries. Used for the 21% and 74% figures.
  5. Deloitte US via PR Newswire, AI Agents are Only the Beginning, 2026. 501 US respondents, April to June 2026, 55% technology leaders and 45% line of business leaders. Used for the 39% readiness figure.
  6. EU Artificial Intelligence Act, Article 26, obligations of deployers of high risk AI systems, read 26 August 2026. Used for the paragraph 2 human oversight wording.
  7. The Register, McKinsey says enterprise AI is finally on the road to ROI, 25 August 2026. Reporting McKinsey's State of AI 2026 survey of 1,719 respondents. Used for the 40% of large organisations scaling agents, up from 27%.

The weakest thing about this source base: every figure is self reported by executives or is an analyst forecast. No dataset anywhere links a named ownership model to measured agent outcomes. The three models here are drawn from how organisations describe their structures, not from a controlled comparison of results.

SK
Sanskriti Khandelwal
Contributing Analyst, Zan Digital. Works in People and Culture at Wayground (Quizizz), and writes here on what AI actually does to how software teams work, hire and are measured.

Related reading