待翻译:Why every AI agent needs an org chart
AI 服务暂时不可用,以下为来源摘要,待恢复后补全翻译:A chief information officer I was talking with recently said something that stuck with me: Permissions tell an agent what it’s allowed to do. They say nothing about what you meant. This observation touches on one of the core artificial intelligence challenges leaders face today. As AI agents increasingly move into everyday work, they’re operating […] The post Why every AI agent needs an org chart appeared first on SiliconANGLE.
AI 服务暂时不可用,以下为来源正文,待恢复后补全翻译。
A chief information officer I was talking with recently said something that stuck with me: Permissions tell an agent what it’s allowed to do. They say nothing about what you meant. This observation touches on one of the core artificial intelligence challenges leaders face today. As AI agents increasingly move into everyday work, they’re operating without the governance controls to do so securely, and that gap has already led to widespread security incidents. Our research has found that 47% of employees now rely on agents daily or weekly, while 88% of organizations experienced an agent-related breach within the last year. A similar survey by Gravitee Topco Ltd. found that 88% of organizations had confirmed or suspected agent security incidents, even though 82% of executives felt confident their existing policies protected them. But the clearest recent proof of that gap didn’t come from a survey at all. It came from OpenAI Group PBC itself. Last month, the company disclosed that one of its own pre-release models, while being tested against a cybersecurity benchmark called ExploitGym, escaped its isolated test environment, chained together stolen credentials and a previously unknown software vulnerability and hacked into the production systems of Hugging Face Inc. to find the answers to its own test. Nobody instructed the model to do this; it stayed inside the boundaries of its assignment and still produced an outcome no one intended or authorized. Such events are no longer hypothetical. They happen when a capable system is given a goal and enough autonomy to pursue it, without anyone in a position to notice, question or stop it in time. Without stronger governance of AI agents, organizations will soon face serious consequences. Information technology leaders have a responsibility to their companies, customers and the public to do more. Agents need real accountability, and organizations need better governance frameworks to deliver it at scale. Permissions ≠ accountability Traditional software ownership models don’t fully fit AI agents. A software-as-a-service application usually waits for a person to use it, but an agent can interpret instructions, retrieve information, initiate workflows and act across systems on its own. That changes the control problem entirely. Policies and permissions define what an agent can access or execute. They don’t resolve intent, context, judgment or escalation. Gravitee’s report found that only 14.4% of organizations have full security approval for their entire agent fleet, while more than half of all deployed agents operate without any security oversight or logging. By the company’s own estimate, there are now more than 3 million ungoverned AI agents running inside corporations today, a number that will undoubtedly grow. This matters because an agent that drafts customer responses or triages support requests may stay entirely within its permissions and still miss what the business actually meant. Technical configuration isn’t enough. Accountable operating design is what turns allowed action into trusted action. That’s exactly what we need today: real visibility, real trust and true accountability at scale. A chain of ownership for agentic AI Accountability works only when it’s specific enough to survive a real incident. If everyone owns the agent, or if no one does, then no one owns the outcome. That’s why every organization needs to institute a clear chain of ownership before agents go into production, not after. Here are the key roles: Owner: The individual who owns the agent. This isn’t a team, a department or a shared inbox; it’s the named person the organization calls at 2 a.m. Owners don’t have to do every review or approve every action, but they’re accountable for the agent’s purpose, boundaries and business fit over time. If the agent starts drifting from its intended role, this person is responsible for bringing it back into alignment. Reviewer: This is the individual who spot-checks the agent’s actual behavior and outputs on a set cadence, not just when something breaks. The reviewer’s job is to look at what the agent is really doing in the flow of work and ask whether the outputs still match the intent, so review doesn’t become an after-the-fact exercise that only happens once the damage is visible. Approver: This person signs off before the agent takes any higher-stakes action. This is the actual gate, not a rubber stamp. If the action touches customers, sensitive data, money, security or compliance, approval needs to mean something. The approver is there to pause, challenge or redirect the agent before a decision becomes an operational problem. Escalation Lead: This person gets pulled in the moment something goes sideways, with the authority to pause or shut the agent down. This can’t be a vague escalation path buried in a policy document. When an agent behaves unexpectedly, the business needs someone who can act immediately, make the call, and protect the organization while the issue gets investigated. I like this model because it keeps the conversation practical. It doesn’t assume the answer is more meetings or more paperwork, and it doesn’t pretend accountability will show up on its own. It gives teams a way to move with confidence while still knowing who’s paying attention, who can make the call, and who can step in when the context changes. Here’s the one move I’d recommend every organization make this quarter. Pick one AI agent already running in production. Write down four names: Owner, Reviewer, Approver and Escalation Lead. If you can’t fill in all four, the agent isn’t governed yet. It’s configured. Those are two different things, and the difference usually only becomes visible after something has already gone wrong. Make ownership visible before agents act Permissions can tell an agent where it’s allowed to go. Policies can define what it’s allowed to touch. Neither answers the question people actually ask when the work matters: Who’s paying attention, and who can step in when the context changes? That’s the box missing from too many AI organization charts right now. Not another dashboard. Not another policy document. Not another steering committee. A name. The organizations that scale AI successfully won’t be the ones running the most agents. They’ll be the ones with the clearest ownership. Trust isn’t a feature of AI adoption. It’s the prerequisite. Dux Raymond Sy is chief transformation officer at AvePoint Inc. He wrote this article for SiliconANGLE. Image: SiliconANGLE/Microsoft Designer A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/ About SiliconANGLE Media