Martin Wheatley
Founder, The AI Leader Lab Β· CIMA Qualified Β· Managing Director, Rawson Ellis
You hire a new starter who joins on Monday. But, nobody wrote down that they'd be joining. No manager's name is against them. No one's quite sure what systems they can get into, or what they're allowed to do once they're in.
You'd never let that happen with a person, it's a basic element of running a company and onboarding a new person to your business.
And yet it's roughly how a lot of businesses are bringing in AI agents right now.
Let me split the word "agent" in two, because it gets used for very different things:
- One kind is a lightweight helper. A custom version of ChatGPT, or one of Google's Gemini "Gems," that drafts something and hands it back to you to check. Useful, low risk, fine.
- The other kind takes actions on its own. It sends the email, updates the record, kicks off the process, sometimes moves money.
That second kind is the one this piece is about, and it's the one that deserves to be treated like a new-hire, not a gadget.
Your newest employee isn't a person but it's still an employee.
Here's what's happening; different people across the business quietly switch these action-taking agents on to save themselves time, help them accomplish more and take some of the load while they tackle more meaty tasks.
Someone in marketing sets one up.
Operations wires up a couple more.
Each does a sensible job on its own and are set up with the right intentions. But, almost nobody keeps is a single list of all of them.
The business-software company SAP put numbers on it at the start of August, drawing on its own survey of companies using these tools:
Ninety-eight percent of firms are either running AI agents or about to. Fewer than half can actually see a list of the ones they've got.
No company runs without a list of who it employs, for HR if nothing else. A fair few are now running a workforce of agents with no such list at all.
Why an untracked agent costs more than an untracked subscription
With the lightweight kind, a mistake is a bad draft or an "AI-slop" generic response. You spot it, you bin it, and you're done.
With an action-taking agent, the mistake is an action that's already happened.
Two ways that bites, from what I've seen.
The first is money. If an agent has been given access to payments, it can make a transaction that isn't easy to reverse. You'd want a strong two-stage approval sitting in front of anything like that. "Would want" and "does have" are not the same thing, and the gap is where the trouble lives.
The second is reputation. A customer-facing agent that answers emails can damage a relationship if no one even knows it's switched on. It's also an open door for bad actors. There's a trick called prompt injection, where someone sends the agent a cleverly worded message that fools it into handing over information it was holding, or acting outside what it was meant to do. If you can't say what your customer-facing agents are, what they can reach, and how they reply, you can't answer for any of that.
There isn't really a defence for getting this wrong.
A leader is meant to know what they're putting into the business and how it's run. That's nothing new; it's an old standard, applied to a new kind of worker.
The shift that makes this a leadership job, not an IT ticket
The reason this can't just be handed to "the computer person" is that these agents act rather than suggest. A person still has to own the outcome and it shoudl be a person that is responsible for that task or workflow being completed.
While IT should be involved with the overall infrastructure, monitoring network and assistance with agent administration; if the accountability is centralised outside of the main team operating the work it gets stranded away from the people actually answerable for the business.
For anyone in financial services or insurance, this is a strong point worth reiterating. The FCA has said it won't be writing a separate AI rulebook. It's leaning on the rules that already exist, which keep accountability with the senior managers, (under the Senior Managers and Certification Regime - SMCR), who are already accountable, and expect customers to be treated fairly whoever, or whatever, is doing the work.
Data protection sits in the same place. What an agent does with company data, personal data, and anything sensitive belongs in the thinking before it goes live, not after.
"The tool did it" will never be a strong defence.
Onboarding an agent like you'd onboard a person
Here's the version you could start on Thursday, and it borrows straight from how you already run people.
When an action-taking agent gets built, give it the things a new hire gets:
- A job description: what is it actually employed to do.
- A record that it exists, in one shared place.
- An access list: what systems and data it can touch, and what it's allowed to action.
- And a named owner, a real person answerable for it, whether that's the head of the department it runs in, the person who built it, or a blend of the two.
Then treat the rest of its working life the same way:
- Someone signs off building it.
- Someone approves it going live.
- Someone keeps half an eye on it, because agents suffer a kind of drift, getting slowly less reliable as the models move on and their information ages.
- And someone decides when it's done and switches it off.
Offboarding an agent matters as much as offboarding a person, and it's the step almost everyone forgets.
Some tools make the visibility easy. Microsoft, for instance, logs your agents in an admin area, so a leader can see what's live and what each one was built for. Where a platform doesn't give you that, a simple tracked list, checked now and then against what people are really doing, does the job. The mechanism matters more than the software.
Above all of it, once you're past a couple of pilots and agents are spreading across teams, a small oversight group that reports into the board earns its place. Not a committee for the sake of one but somewhere the questions get answered out loud: how we propose a new agent, who's responsible when one needs changing, and what running list the board actually sees. It doesn't have to be heavy but it does have to exist.
Ultimately building a culture of responsible AI usage with adequate employee training, sharing best practice and being public about what is working and what is not is fundamental to embracing agentic technology.
I'd rather a leader knew about five agents and ran them like employees than owned a clever fifty and couldn't tell you what half of them touch. It comes back to something simple:
You can't govern what you can't see.
If it would help to sit your leadership team down and work out what "onboarding an agent" looks like for a business your size, that's a short conversation I'm happy to have. You can book a slot with me here, and we'll keep it practical.
More soon, M.
β»οΈ Enjoy this? Repost to your network if you found this useful.
π Follow Martin Wheatley for more AI for leadership.
β πππ‘π₯ππ£π π‘πππππ§π¨ ππππ€π’π πΌπ-ππ€π£πππππ£π©. Putting AI to work with your people, without replacing what makes them great.
βοΈ If that's the conversation you're interested in having, leave a comment, drop a DM, book a call, or visit my website. All links in my profile.
Sources
- SAP News Center, "AI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue," 3 August 2026. https://news.sap.com/2026/08/agent-sprawl-why-ai-governance-is-now-board-level-issue/ (carries the SAP LeanIX Agentic AI Survey 2026: 98% deployed or planning, fewer than half with an agent inventory)
- Gartner, "Gartner Identifies Six Steps to Manage AI Agent Sprawl," 28 April 2026. https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl (only 13% of organisations believe they have the right governance in place)
- FCA, "AI and the FCA: our approach." https://www.fca.org.uk/firms/innovation/ai-approach (no separate AI rulebook; relies on existing senior-manager accountability under SM&CR and on Consumer Duty)
- HM Treasury, "Financial Services AI Adoption Plan," 14 July 2026. https://www.gov.uk/government/publications/ai-adoption-plan-financial-services/financial-services-ai-adoption-plan



