I've spent the last few months on discovery calls with enterprise AI program leads, and the same scene plays out almost every time. A CTO walks me through their deployment plan, lists the agents they have in production, talks about model selection, talks about cost. Then I ask: "Who manages agent number 23?" And the room gets quiet.
That pause is the most expensive silence in enterprise AI today. Companies have spent the last 18 months deploying agents the way they deploy SaaS — pick a vendor, get a budget, ship it to production. What they have forgotten is that agents do not behave like SaaS. They behave like employees. And no serious enterprise on earth would hire 40 employees and forget to assign them managers.
The numbers back this up. A 2026 Accenture and Wharton report put it bluntly: "Intelligence may be scalable, but accountability is not." Only 1 in 5 organizations has a mature governance model for autonomous agents. 63% of companies that suffered an AI-related breach had either no governance policy at all, or one still being drafted. The HFS Horizons Agentic Technology 2026 report goes further — it argues that the real bottleneck is no longer the model layer, the data layer, or the orchestration framework. It is the operating model.
You do not fix an operating-model problem with an observability dashboard. You fix it with an org chart.
Why "Platform Owner" Isn't Enough
The default answer most enterprises give today is some version of "the AI platform team owns the agents." That is a comforting answer that quietly fails three tests.
It fails the outcome test: when an agent's recommendation costs the company a quarter of expected pipeline, the platform team did not make the call — they ran the runtime. The business leader who signed off on the use case is on the hook, but they never see the dashboards.
It fails the drift test: agents are not deterministic. They drift. Models get updated. Tools get added through MCP. Permissions widen quietly. Nobody on the platform team is paid to watch for that drift on agent #23 specifically.
It fails the escalation test: when a customer sues over a chatbot's promise — as happened to Air Canada in 2024, when a tribunal forced the airline to honor a bereavement fare its bot invented — the question that lands on the General Counsel's desk is "who approved this agent to make commitments to customers?" The answer should not be "Slack."
Each of these failures shares the same root cause: a single owner cannot carry three different kinds of accountability. You need a structure.
The Three Lines Every Agent Needs
Here is the framework I have been using in discovery for ARMS, refined across roughly 30 conversations with enterprise AI program leads. Every production agent should have three named humans in its reporting chain. Not three roles. Three people, by name, in the same document the CIO can pull up in a board meeting.
Line 1 — The Operator. The Operator is the day-to-day manager. They have the kill switch. They review the agent's outputs the way a team lead reviews a junior employee's work — sampled, periodic, but real. They are the one who gets paged when the agent does something unexpected at 2am. In most companies this should be an embedded technical lead inside the business function, not a centralized platform engineer sitting three orgs away. The Operator's metric: incident frequency and time-to-detect.
Line 2 — The Function Owner. This is the business leader who owns the outcome the agent is supposed to produce. If the agent is running sales outreach, the VP of Sales is the Function Owner. If it triages support tickets, the VP of CX. Their job is not to read every log. It is to sign off on the agent's mandate, its target metrics, and any expansion of scope. They own the ROI conversation with the CFO. The Function Owner's metric: business outcomes the agent is responsible for.
Line 3 — The Risk Steward. This is a cross-functional role, usually reporting into the CRO, CISO, or Chief AI Officer if one exists. The Risk Steward does not manage any single agent — they manage the portfolio risk across all agents. They are the person who notices that you now have eight agents with write access to the customer database, and asks whether that should be true. They own the audit trail. They sign off on agents that handle regulated data, customer money, or external commitments. The Risk Steward's metric: governance maturity and audit readiness.
If any of these three lines is empty for a given agent, that agent is an organizational vulnerability waiting to be priced.
The Diagnostic
Here is a fast diagnostic you can run this week. Pull up your list of production AI agents. For each one, fill in three cells:
| Agent | Operator | Function Owner | Risk Steward |
|---|---|---|---|
If you cannot put a person's name in every cell — not "the platform team," not "TBD," not "we are working on it" — that agent does not belong in production. Pause it, assign owners, restart.
This sounds harsh. It is the same standard you would apply to a new hire. You would not let a contractor onboard without a manager, a department, and an HR record. Agents deserve at least the rigor we give to interns.
What This Changes
The most common pushback I hear is that this slows down deployment. It does — by exactly the amount it should. The point of an org chart is to make accountability legible before the work begins, not after the lawsuit lands.
The companies that figure this out first will not have fewer agents. They will have more, deployed faster, because every new agent slots into a structure that already exists. The companies still arguing about whether agents need governance at all will spend 2027 reconstructing decision trails in deposition prep.
You can build the dashboards later. Build the org chart first.
If you are running an enterprise AI program and you can name the Operator, Function Owner, and Risk Steward for every agent in production, I would genuinely like to hear how you got there. If you cannot, that is the conversation worth having.