According to the State of AI in the Enterprise: The Untapped Edge (Deloitte AI Institute, January 2026), 74% of global companies surveyed plan to use AI agents at least moderately within two years. Most have yet to designate anyone accountable when these agents make mistakes.

Technological maturity is only one dimension of the problem. This report, which surveyed 3,235 executives across 24 countries, indicates that only 21% of companies have a mature governance model for their AI agents, and 84% have not redesigned their positions around these tools. The gap between the speed of deployment and the speed of institutional adaptation creates a responsibility architecture full of holes, in which consequential decisions will be made without anyone truly knowing who made them.

The Essentials

74% of companies surveyed by Deloitte plan to use AI agents at least moderately within two years, but 84% have not redesigned their positions accordingly, and only 21% have mature AI agent governance, according to the State of AI in the Enterprise: The Untapped Edge (Deloitte AI Institute, January 2026). The central risk is not job elimination but the absence of a chain of responsibility when an autonomous agent makes an erroneous decision. Companies that have begun redefining positions and establishing human oversight protocols achieve measurably superior results compared to those that merely deploy.

75% Plan, 21% Govern: The Arithmetic of the Void

When a human trader makes a bad decision, you know who to call. When an AI agent approves a loan, triggers an order, or rejects a candidate, the causal chain becomes diluted. Who configured the agent? Who validated its decision thresholds? Who was supervising at the moment of error?

These questions are not hypothetical. They already arise in companies that have begun deploying, and the answer is often embarrassed. The KPMG Q4 AI Pulse Survey confirms the trend: adoption accelerates, governance follows slowly. The gap between the two is not a statistical curiosity; it is the description of an institutional void.

This void has a logic. AI agents promise immediate and measurable productivity gains. Governance, meanwhile, is costly, slow, and does not produce flattering metrics for a board of directors. Deployment thus advances as a scout, and organizational structure follows at a distance.

Researcher Milo Rignell, who works on technology policy and AI regulation, emphasizes this point: deployment decisions are made by actors whose incentives are oriented toward short-term performance, while governance requires investments whose benefits are diffuse and deferred. Without external correction, whether from regulation or market constraints, this gap tends to widen.

The mechanics are similar to what has been observed in other technological transitions: the tool arrives, uses improvise, rules come after the incident. The difference with AI agents is that the decisions they make can commit third parties, budgets, and professional lives, under conditions where traceability remains largely optional.

Why Job Elimination Is the Wrong Subject

The public debate about AI and work is saturated by the question of job elimination. This is understandable, but it diverts attention from the more immediate problem that the data reveals.

The fact that 84% of companies have not redesigned their positions around AI agents says something specific: human workers who coexist with these agents have not had their role redefined. They continue to operate under previous job descriptions, without formalizing what falls under their judgment and what falls under the agent’s. This ambiguity is not comfortable to manage daily, but it is also legally fragile: in case of error, it makes responsibility attribution nearly impossible.

Economists studying technological transitions, including Daron Acemoglu and Simon Johnson in their analysis of the conditions under which technology benefits the majority, emphasize that technology above all reconfigures power relationships and decision chains, beyond simply replacing workers. Who controls the agent? Who can stop it? Who is informed of its decisions? These governance questions determine the impact on human work far more than the mere volume of jobs eliminated or created.

There is an instructive precedent. When automation transformed production lines in the 1990s, companies that had invested in redefining operator positions, transforming them into process supervisors rather than executors, achieved better results over time than those that simply substituted machines for human hands. The lesson still holds: the tool alone is not enough; it is its integration into a redesigned organization that determines the outcome. A similar dynamic had already been observed in agricultural automation, where productivity gains were accompanied by a profound recomposition of roles without local institutions anticipating it.

Companies That Have Begun Redefining Positions Achieve More

Deloitte data allows a direct comparison between companies that have invested in position redefinition and human oversight and those that merely deployed. The former achieve measurably superior results, whether in terms of productivity, team satisfaction, or quality of decisions made by agents.

This result is not counterintuitive if one understands how current AI agents work. These systems operate within objectives defined by their parameters. When these parameters are poorly calibrated, the agent efficiently optimizes for the wrong objective. Human oversight does not consist of checking each decision, which would cancel out productivity gains, but of maintaining the capacity to intervene in edge cases, to detect systematic drift, and to adjust parameters accordingly.

Companies that have formalized this oversight role, by designating explicit supervisors, by defining decision thresholds beyond which the agent must request human validation, and by documenting the agent’s decisions to enable auditing, construct an architecture of responsibility. Those that do not construct an architecture of opacity.

Managerial caution is a first requirement, to which is added a legal dimension. In sectors where decisions have direct consequences for third parties—credit, insurance, health, recruitment—the absence of a clear chain of responsibility is beginning to attract the attention of lawyers and regulators. The question of whether an AI agent can be a “decision-maker” in the legal sense remains open in most jurisdictions. Until this is settled, companies that have not equipped themselves with human oversight protocols operate in a regulatory blind spot.

Two Scenarios for Closing the Gap Before It Becomes a Social Problem

The gap between adoption and governance is not fixed. Two trajectories are plausible by 2030, according to signals emerging today.

The first scenario is convergence through incident. An autonomous agent makes an erroneous decision in a high-stakes context: a credit denial based on an undetected bias, a medical error in an AI-assisted protocol, a contested automated layoff in court. The publicized incident forces regulators to act. Companies, under constraint, rapidly institute responsibility frameworks they could have built progressively. Governance catches up with deployment, but through constraint and in urgency, with the costs that implies. The European Union, with its AI Act that entered into force in 2024, has partially anticipated this scenario for high-risk systems. In the United States, the framework remains largely sectoral and fragmented.

The second scenario is preventive governance. Companies that invested early in position redefinition and human oversight gain a visible competitive advantage in decision quality, resilience against errors, and capacity to justify their practices to customers and regulators. This advantage creates an imitation effect. Governance standards rise without waiting for regulatory constraint, driven by competitive logic. The 21% of companies with mature governance become a market reference rather than a virtuous minority.

These two trajectories are not mutually exclusive. The regulatory scenario can accelerate the competitive dynamic, and vice versa. But they imply different collective needs. In the first case, the urgent need is a legal framework for responsibility in algorithmic decisions, which allows a court to determine who is accountable for an agent error and under what standard. In the second, the need is more methodological: standards for auditability of automated decisions, frameworks for human oversight adapted by sector, and certification mechanisms that make governance comparable and verifiable.

Two signals will allow us to distinguish which trajectory gains traction over the next two or three years. First, the evolution of the percentage of companies with mature governance: if this figure rises above 30% without a major triggering incident, the preventive scenario is taking hold. Second, the first lawsuits over AI agent decisions: their nature, outcome, and publicity will condition the speed and form of institutional response. The European AI Office, created to oversee implementation of the AI Act, will also provide data on how companies operating in Europe adapt to regulatory constraint, which will indirectly illuminate the American situation by contrast.

Concrete Practices of Leading Companies

Companies that have begun closing the gap do not follow a single model, but their practices converge on a few axes.

Position redefinition begins first with decision mapping. These companies have identified which decisions would be made by agents, which decisions would remain human, and which decisions would require human validation upstream or downstream. This mapping is not an internal policy document; it is the basis for a reorganization of responsibilities. For employees whose work is affected, this translates into an explicit role redefinition: process supervisor rather than executor, responsible for detecting anomalies and intervening on edge cases.

Human oversight, in these organizations, is formalized rather than implicit. Decision thresholds are defined beyond which the agent must flag and await validation. Decision logs are maintained, enabling later audit. Periodic reviews examine decisions made by agents to detect systematic drift before it becomes an incident.

On the governance front, these companies have designated explicit supervisors for agent performance and errors. In some cases, this responsibility is carried by cross-functional committees associating technical, legal, and operational teams. The objective is not to slow deployment but to ensure that the chain of responsibility exists before the agent makes its first consequential decision.

This approach does not eliminate the risk of error. AI agents make errors. The question posed by Deloitte and KPMG data is not whether errors will occur, but whether the organizations in which they occur will be capable of responding to them: detecting them quickly, understanding the cause, correcting the parameterization, and reporting on them. It is this capacity for response, more than the absence of incident, that distinguishes organizations with mature governance from others.

Regulation as Signal, Not Solution

The temptation, facing this gap, is to wait for regulation to impose a standard. This wait is rational in the short term and risky in the medium term.

Milo Rignell and other researchers working on technology policy emphasize that regulation is effective when it codifies practices that have already proven themselves, not when it invents solutions that actors have not yet tested. The European AI Act was built on emerging practices in industry and research. In the United States, where the regulatory framework is more fragmented, de facto standards often emerge from actors themselves before being formalized by sector regulators.

For American companies, the regulatory horizon remains uncertain. Large technology platforms, which have the most influence on agent deployment standards, have an interest in clear rules rather than state fragmentation, but their position on the form of these rules varies considerably. User companies, those deploying agents in operational processes, meanwhile have an interest in sectoral benchmarks that allow them to demonstrate compliance to customers and regulators.

In this context, companies investing now in governance are not merely managing a risk. They are acquiring an organizational capacity that will become a prerequisite, whether that prerequisite is imposed by regulation or by market expectations. The open question, which the next two to three years will begin to answer, is whether this investment will be made early enough for governance to precede incidents rather than follow them.


Sources

  1. KPMG Q4 AI Pulse Survey
  2. Deloitte State of AI in the Enterprise 2026 – official press release, State of AI in the Enterprise: The Untapped Edge (Deloitte AI Institute, January 2026) (survey of 3,235 executives across 24 countries)
  3. Daron Acemoglu and Simon Johnson, Power and Progress, PublicAffairs, 2023, MIT Shaping Work
  4. European AI Act – Regulation EU 2024/1689 – EUR-Lex
  5. European AI Office – Official Page European Commission
  6. Deloitte – AI agents scaling faster than their guardrails
  7. National Law Review – Legal considerations for Agentic AI