
TOPSHOT – A robot using artificial intelligence is displayed at a stand during the International Telecommunication Union (ITU) AI for Good Global Summit in Geneva, on May 30, 2024. Humanity is in a race against time to harness the colossal emerging power of artificial intelligence for the good of all, while averting dire risks, a top UN official said. (Photo by Fabrice COFFRINI / AFP) (Photo by FABRICE COFFRINI/AFP via Getty Images)
AFP via Getty Images
Fifty-seven percent of organizations now deploy AI agents for multistage workflows, while 81% plan to use them for more complex tasks in 2026, according to an Anthropic survey. But many companies are still developing the systems required to manage them: 82% of enterprises surveyed by the Cloud Security Alliance had discovered at least one AI agent or autonomous workflow previously unknown to their security or IT teams.
The rapid adoption reflects a broader change in how companies view artificial intelligence. Agents are moving beyond drafting, research and basic chat into customer conversations, internal databases and business operations. They can schedule appointments, update records, qualify leads and complete work previously assigned to employees.
The shift is already prompting a broader discussion about how companies should manage AI agents as a new kind of digital workforce. Microsoft, Okta and other technology providers are developing systems that give agents distinct identities, named owners and limited permissions. The National Institute of Standards and Technology (NIST) is also examining how existing standards for identification, authorization and auditing should apply to agents.
Nextiva, the business-communications company, markets its XBert AI assistant as an “AI employee.” The agent can answer customer calls and messages, schedule appointments, qualify leads and route requests across connected business systems. Businesses can define what it handles, determine when it transfers a conversation to a person and review transcripts of its interactions.
Calling software an employee implies that it can represent a company, exercise limited authority and complete work on its behalf. The company deploying it remains responsible for what it says and does.
“Trust in an AI agent works the same way trust in an employee does. It has to be earned and it has to be verifiable,” Yaniv Masjedi, chief marketing officer at Nextiva, told me in an interview. An agent should identify itself as AI, explain what it can and cannot do and offer access to a human at any moment, he added.
“Behind the scenes, businesses need the same rigor they’d apply to a new hire: defined authority, logged actions, and a named human who owns the outcome. The AI never owns the outcome. The business does. If your agent makes a promise, that’s your promise.”
Managing A New Digital Workforce
The level of oversight an agent needs depends partly on what it can do. An agent answering questions from an approved knowledge base presents a relatively contained risk. One that can access customer records, send messages, issue credits or modify accounts requires more precise controls.
Companies need to manage their identities and access almost as deliberately as they manage employees. The controls surrounding an agent become part of its practical job description: which systems it may enter, which actions it may take and which decisions still require human approval.
“If an agent is going to work like an employee, give it an employment file: a manager of record, a scoped job description, a badge that expires, a written deferral threshold, and an offboarding process,” Anupam Satyasheel, CEO of Occams Advisory and co-founder of Occams AI, wrote in a response to me.
“A human employee’s badge is deactivated on their last day. Most agent credentials have no last day,” he added.
Recent research by Okta suggests that the basic management infrastructure is still being built: 47% senior executives said they could identify all agents in their environments, 46% could control what those agents accessed and 45% could authorize their individual actions.
The challenge is to impose enough structure while preserving the flexibility that makes agents valuable.
“Agents are flexible by design. Scope them too tightly and you’ve built an expensive way to run a script. Scope them too loosely and you’ve got no governance at all,” Imran Siddique, chief platform officer at Opaque Systems, told me in a written response.
Siddique argues that agents should receive distinct machine identities and explicit capabilities instead of broad job titles or permissions inherited from a human user.
“This agent can do exactly this set of actions—nothing implied, nothing inherited,” he said.
Human roles often come with informal expectations and unspoken authority. AI agents operate through system access: if a connected account allows an action, the agent may be able to take it even when the company never intended to grant that authority.
Establishing Trust
Identifying the human responsible for an agent is one part of that structure. Companies must also be able to recognize the agent itself, limit its permissions and reconstruct its actions.
Verification platform Sumsub recently introduced a Know Your Agent framework that connects agents to verified human identities. “Linking an AI agent to a verified human identity is the foundation of accountability, but it might no longer be sufficient on its own,” Ilya Brovin, chief growth officer at Sumsub, told me in a written response. Organizations must be able to determine who is responsible for an agent, what it is authorized to do and what it has actually done, he added.
That requires a persistent machine identity, scoped permissions, continuous authentication and a tamper-resistant activity record. “Trust must be continuous, not event-based,” Brovin added.
The distinction reflects how agents differ from one-time identity checks designed for human users. A person may verify their identity once before opening an account or accessing a service. An agent may operate continuously, move between systems and perform new actions hours or days after its initial authorization.
Customers should be able to tell which company an agent represents, whether they are dealing with AI, what kinds of requests it can handle and how to reach a person for a sensitive or consequential decision. Internal teams need a fuller record showing who authorized the agent, which data it accessed, what action it took and whether that action fell within its approved scope.
The rise of AI employees requires businesses to apply familiar management principles—ownership, job descriptions, limited access, supervision and offboarding—to a new category of worker. As agents join the digital workforce, the companies that benefit most will be those that pair greater autonomy with clear boundaries and accountability.