Writing

You Can See the Agents. Nobody Owns the Output.

The stall is often not a missing AI policy. It is a company that can see its sanctioned agents and cannot name who produced the last thing a customer read.

Executive summary

  • Okta's AI Agents at Work 2026 (Apprize360, fielded March 2026; 292 executives and 492 knowledge workers, seven countries): 90% of executives are confident they can see the AI tools in use. 52% of knowledge workers used AI tools without approval; 24% do it regularly. In the US the unsanctioned share is 67%.
  • Since 2 August 2026, EU Article 50 requires a customer-facing sentence: this is an agent, this is synthetic. The high-risk logging, oversight, and documentation duties that would let an auditor reconstruct why apply from 2 December 2027.
  • Most companies do not take ownership of AI slop, data leaks, or hallucinated content. That is the structural consequence of visibility theater plus a sentence without a trail — not a survey result.
  • The operator move: inventory the third workforce — built, bought, personal. For one consequential output last week, name who produced it, which system, what data it saw, and who will sign if it is wrong.

The dashboard is not the workforce

Ninety percent of the executives in Okta's survey are confident they have visibility into the AI tools in use. Ninety-five percent are confident employees use AI responsibly. Ninety-two percent say agents are already in widespread or moderate use — 58% widespread, 35% moderate.

That is a dashboard of sanctioned agents. It is easy to look at and call it visibility.

Half the workforce is not on it. Fifty-two percent of knowledge workers used AI tools without approval. Twenty-four percent do it regularly. In the United States the unsanctioned share is 67%.

The company can see the agents it blessed. It cannot see the system that produced the email, the deck, the customer reply, the research. That work happened on a personal account, in a tool the team already uses, on a login nobody registered.

This is not concealment of method. When AI adoption hides what your team knows, the method is often in plain sight. What is hidden is which system did the work.

The motives are ordinary. Of workers who used unapproved tools, 80% said their own account was easier; 78% said the team already uses it; 57% said approval is too slow; 49% said approved tools do not meet the need. Sixty-five percent of executives say the AI policy is very clear. Forty-three percent of knowledge workers agree.

A policy PDF will lose to the personal login. You cannot govern a workforce you have not named.

What the unapproved path actually sees

Of the workers using unapproved tools: 54% share internal mail, 45% share HR information, 39% share confidential documents. More than 20% share login credentials. Twenty-eight percent share banking or payment information.

Fifty-eight percent of executives already report an AI-related security incident or close call in the past twelve months. Only 34% always apply the same security controls to digital labor as to people.

Okta frames the governance question as three questions: Where are my agents? What can they connect to? What can they do? The gap in the survey is that "my agents" reads as three populations, not one: built in-house, bought and deployed, and deployed by employees without approval. The dashboard answers the first two. The third is the population half the workforce belongs to.

The sentence is due. The trail is not.

On 2 August 2026, Article 50 of the EU AI Act became enforceable. Chatbots, agents, and avatars that interact with people must disclose that the person is not talking to a human. Deepfakes must be labelled. Synthetic content must carry machine-readable marks. Existing generative systems have until 2 December 2026 for the marking and detection requirements only. Fines run up to €15 million or 3% of global turnover.

The obligation binds providers and deployers whose outputs reach people in the Union — not only EU-headquartered firms.

What is not yet required: the logging, oversight, and documentation duties that would let an auditor reconstruct why an agent produced what it produced. Those attach to high-risk systems listed in Annex III and apply from 2 December 2027. The disclosure sentence is live. The trail is not.

This matters for the ownership question. An agent can say I am not a human and still leave no record of which model ran, which data it saw, who reviewed it, or who the deployer was. Link those two facts to the visibility gap in the survey and you have the structural situation: the label is on the box; the owner of what is inside it is not named. Chat logs are not what we know about a system; they are what the system said. The gap between those two things is where what your organization remembers lives — and where memory as a governance problem begins.

A label on a black box

When slop ships, data leaks, or a hallucination goes to a customer, there is often no named owner of the output. That is a structural consequence — not a survey result. Visibility theater means the sanctioned dashboard looked clean. A disclosure sentence means the customer was told it was synthetic. Neither requires anyone to have named, in advance, who was responsible for what the agent produced.

The pattern is the same one in nobody told the agent what done means: the work happens; the output exists; nobody signed the passing condition before it shipped.

Name the third workforce

Inventory three populations: built in-house, bought and deployed, and deployed by employees without approval. The third is the hardest to list and the most consequential to ignore.

For one consequential output from last week — an email, a customer document, a piece of research — reconstruct: who produced it, which system, what data it saw, and who will sign if it is wrong. If you cannot do that without interviewing five people, you do not own it.

The operator move is to make the sanctioned path the fastest path. Eighty percent of workers used an unapproved tool because their own account was easier. The governance answer is not a stricter policy. It is a system where the approved tool is the path of least resistance.

Engram is a study and working prototype of what a context system that keeps provenance inside the organization can look like — not a hosted product or a SaaS offering. The argument it tests is that capture is cheap; the hard part is making what the system knows inspectable and attributable.

What this means

Visibility into sanctioned agents is not visibility into the work. A dashboard that shows your approved tools cannot show the system that produced the last customer-facing output. A disclosure sentence tells the customer they are talking to a machine. It does not tell you, or them, who is responsible for what the machine said.

A disclosure sentence is not a trail. The trail — the audit record, the named model, the data scope, the human reviewer, the signer — is what ownership actually requires. That trail is not yet legally mandated for most systems, and most companies have not built it voluntarily.

The structural consequence is that liability sits with no one in particular. When that is true of output a customer received, it is not a compliance gap. It is an ownership gap.

Take this with you

Five paste-ready prompts sit next to this essay: a third-workforce inventory, a last-output reconstruction, a live-vs-later disclosure card, an ownership diagnostic for slop and leaks, and a sanctioned-path check. Fill the brackets. Do not let the model invent the owners, the systems, or the times.

Open the prompt kit.

Sources: Okta, AI Agents at Work 2026; Okta, Agent SSO announcement; European Commission, Article 50 in force (2 August 2026); EC, AI Act enforcement timeline; Cooley, EU AI Act transparency obligations (3 August 2026).