The person in the audit log may not be the person in control
Agent identity, frontier-model reporting, international incident notification and AI-worker distress reveal a new organisational risk: responsibility is being compressed onto the nearest visible human.
Workforce intelligence · Issue 7
AyEye — Workforce Management
Human systems in the agentic enterprise
Tuesday, 22 September 2026
A security agent can now inherit an employee’s permissions and attach every action to that person. New York is assigning incident duties to frontier-model developers. Washington and Beijing are discussing an emergency notification channel. Meanwhile, people building advanced AI are reporting the psychological weight of risks they can see but cannot personally control. The audit log is getting better at naming a human. That does not mean it has found the person responsible.
The executive brief
- BigID has launched an agentic data-security layer that acts through a requesting user’s permissions. Every action is logged and tied to a person. That is useful for traceability, but it also exposes a design hazard: technical attribution can become managerial blame even when the person did not design the model, policy or objective.
- New York is operationalising the RAISE Act. Large frontier developers will begin registering in November and face safety-framework, quarterly assessment and 72-hour critical-incident reporting requirements from January 2027. Responsibility is being attached to the institution that creates the capability, not only to the individual who uses it.
- The United States has proposed an AI-incident notification mechanism with China. The proposal is preliminary, but its logic matters: when a system’s consequences cross boundaries, early warning can be valuable before fault is settled.
- AI safety work is producing a human burden of unresolved responsibility. The Financial Times reports stress leave, resignations and anxiety among staff at frontier laboratories and the UK AI Safety Institute. The evidence is qualitative, but it suggests that visibility without commensurate authority can become a psychosocial hazard.
- Boston Dynamics has opened a factory-based training centre for Atlas humanoids. Robots are learning parts sequencing in Hyundai’s live manufacturing environment. The people who demonstrate exceptions and validate behaviour are not merely supporting deployment; they are creating reusable machine capability.
- The UK’s statistics agency is designing a thematic account for AI. Its struggle with ownership, assets, infrastructure and downstream services mirrors a problem inside firms: AI value and AI responsibility disappear when measured only inside existing departmental categories.
ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 6–24 months
The person in the audit log may not be the person in control
Agentic systems distribute causation across models, data, policy, workflow and management, then compress the result onto one visible human identity. Organisations need to reverse that compression before accountability becomes unfair, ineffective and unsafe.
Signal one: the agent acts as you—and the record points back to you
REPORTED FACT. On 21 September, data-security company BigID launched AgentIQ, an automation layer that can investigate data exposure, rank risks, revoke access, quarantine information, apply retention rules and run remediation continuously.
BigID says agents inherit the requesting user’s permissions, with controls enforced at the API and Model Context Protocol layer rather than through a prompt. Every action is logged and attributable to a person. The product is generally available, according to the company; its claims about effectiveness have not been independently tested here. BigID announcement, 21 September
ANALYSIS. This is sensible identity engineering. An agent should not float through the enterprise without an accountable mandate. Yet the mechanism quietly fuses three different propositions:
- The action used this person’s credentials.
- The action was initiated under this person’s mandate.
- This person is responsible for the outcome.
Only the first is established by the access log. The person may have selected the objective but not the model, retrieval source, policy threshold, interface default or remediation sequence. If the organisation treats attribution as a complete explanation, the employee becomes a convenient endpoint for a system-level decision.
Signal two: law is attaching duties further upstream
REPORTED FACT. New York’s governor announced on 21 September that large frontier-model developers will begin registering with the state in November as implementation of the RAISE Act advances.
From January 2027, covered developers must publish safety and transparency frameworks, report critical safety incidents within 72 hours, file quarterly catastrophic-risk assessments and make regular disclosures to the state’s new Office of Digital Innovation, Governance, Integrity and Trust. Members of the public may also submit suspected incidents. Governor of New York, 21 September
ANALYSIS. The RAISE Act concerns frontier developers, not ordinary enterprise deployments. Its organisational lesson is broader: responsibility can sit with the institution that creates and governs a capability even when another person eventually presses the button.
That matters because agentic work tempts firms to push accountability downwards. A product team selects the model, an architect connects it to tools, a business leader sets throughput targets and an employee receives the alert. The employee is visible at the moment of action; the upstream choices are not.
Signal three: reporting can precede agreement about fault
REPORTED FACT. During US–China economic discussions over the weekend, US Treasury Secretary Scott Bessent proposed a notification mechanism for AI incidents that could pose national-security risks. Chinese state media characterised the wider dialogue as candid and constructive; no binding mechanism or operating protocol has yet been announced. Associated Press, 20 September
ANALYSIS. A hotline between states is not a template for an employee-relations process. The useful principle is narrower: notification and attribution are different stages.
When consequences can spread faster than an investigation, a party needs permission to say “this may be happening” without first accepting sole blame. Enterprise incident channels need the same separation. Otherwise, the person closest to the event may remain silent until they can defend themselves.
Signal four: responsibility without authority has a human cost
REPORTED FACT. The Financial Times reported on 21 September that staff at the UK AI Safety Institute, OpenAI, Anthropic and Google DeepMind have experienced anxiety, burnout, stress leave or resignation linked to fears about the societal consequences and pace of advanced-AI development.
The reporting is based on individual experiences and does not establish prevalence across these organisations. Employers cited wellbeing provision and safety commitments. It nevertheless surfaces a workforce risk that adoption dashboards do not show: people may feel personally implicated in outcomes whose strategic direction they cannot change. Financial Times, 21 September
ANALYSIS. Psychological safety is often discussed as confidence to speak. Agentic work adds a harder condition: confidence that speaking can alter the system.
If employees are asked to monitor risks but lack authority to slow deployment, narrow an agent’s mandate or trigger independent review, oversight can become moral load rather than meaningful control.
How responsibility gets compressed
| Distributed cause | Hidden decision | Visible endpoint | Failure mode |
|---|---|---|---|
| Executive objective | Which outcome and trade-off were prioritised? | Named user in the audit log | One person is blamed for a system they could neither fully inspect nor change |
| Workflow and policy | Which steps, thresholds and exceptions were encoded? | ||
| Model and data | Which capability, limitations and evidence shaped the act? | ||
| Permissions and interface | What could the agent do, and what appeared normal to the user? | ||
| Targets and incentives | What discouraged delay, challenge or escalation? |
ORIGINAL SYNTHESIS. These developments expose a new organisational failure mode: responsibility compression.
An agentic outcome is produced by a network of decisions, but the organisation compresses that network onto the nearest identifiable person—the requester, reviewer, frontline operator or manager whose credentials appear in the record.
This may feel reassuring. There is always a human name. It is often bad control.
Fair accountability requires matching responsibility to effective control: what a person or institution could know, decide, change and stop at the relevant moment. The employee who notices an anomalous remediation may have intervention responsibility. The executive who demanded uninterrupted automation owns the objective and incentive. The platform team owns the permissions architecture. The supplier owns disclosed model limitations and updates. The organisation owns the combined system.
The solution is not to dissolve responsibility into a committee. It is to create a responsibility topology: a record of the distinct control relationships around one objective, designed before failure rather than reconstructed by lawyers afterwards.
The responsibility topology
| Control relationship | Question | Responsibility cannot be delegated away |
|---|---|---|
| Purpose | Who chose the objective and acceptable trade-offs? | Executive or business owner |
| Capability | Who selected, tested and updated the model or machine? | Technology owner and provider |
| Mandate | Who defined data, tools, money and actions available? | Process owner, security and risk |
| Operation | Who invoked, supervised or relied on the work? | User or operating team, within actual authority |
| Challenge | Who can inspect evidence, disagree and stop? | Independent assurance and authorised frontline roles |
| Remedy | Who protects affected people and repairs the outcome? | Organisation, not the isolated user |
Unexpected connection
Agent identity + frontier-model reporting law + geopolitical incident notification + AI-worker distress
These developments sit in cybersecurity, regulation, diplomacy and occupational wellbeing. Joined together, they reveal the same design question: when capability is distributed but consequences converge, where should responsibility land?
The wrong answer is “on whoever is easiest to name”. The useful answer follows control across the system and preserves a fast route for early warning before final fault is known.
PROVOCATION
An employee must not become the legal skin around an agent
Requiring a human identity behind every agent is necessary. Treating that identity as the complete bearer of liability is not. If an employee supplies credentials while the organisation supplies the objective, model, permissions, targets and evidence environment, the organisation remains the principal actor. “Human accountable” must never become a contractual trick for transferring system risk onto the least powerful person in the chain.
What if we are right?
Opportunity. Clearer responsibility could enable more useful delegation. Employees would know which decisions genuinely belong to them, where they may challenge and which failures the organisation will remedy. Leaders could distinguish a poor judgement from a bad workflow, weak evidence or an unsafe mandate.
Organisational consequence. Agent registers and access logs would connect to objectives, decision rights, model versions, control owners and remedies. HR would help define fair accountability and psychosocial protection; technology would preserve technical evidence; risk and operations would assign intervention authority.
Likely horizon. A responsibility card for one workflow can be created now. Shared records spanning identity, HCM, workflow, model and incident systems are plausible within 12–24 months. Legal doctrine and industry standards will move more slowly.
What would prove us wrong?
The thesis weakens if enterprise agents remain simple tools whose outputs are always inspected and whose consequences are fully reversible. Existing professional accountability may be sufficient where a qualified person genuinely understands and controls the whole task.
It also fails if responsibility maps become bureaucratic artefacts that everybody signs and nobody uses, or if distributed causation is invoked to excuse obvious negligence. Some decisions do belong to individuals; deliberate misuse, reckless override and concealment still require consequences.
The practical disconfirmation is behavioural: if incident reviews based on access logs alone consistently identify the right corrective action and do not suppress reporting, responsibility compression is not a material problem there.
Optimistic possibility: accountability becomes a design resource
A responsibility topology can do more than distribute blame. It can make contribution visible.
The frontline worker who spots an unsafe pattern, the engineer who narrows a permission, the reviewer who asks for better evidence and the team that repairs an affected customer all become recognisable contributors to organisational capability.
That creates a more humane form of accountability: precise about authority, generous about learning and unwilling to leave one person carrying the moral weight of a system built by many.
PHYSICAL AI · OUTSIDE-IN ANALYSIS
A robot training centre is a new kind of factory school
REPORTED FACT. Boston Dynamics opened its Robotics Metaplant Application Center on 21 September inside Hyundai Motor Group’s Georgia vehicle plant. Atlas humanoids are being trained in real manufacturing conditions, initially to prepare and sequence parts for assembly. Component assembly is planned by 2030.
The company says operations will move to a facility roughly ten times larger in 2027, when it also expects to explore uses in aerospace, semiconductors, logistics, food and life sciences. Hyundai plans to begin deployment across its global plants with 25,000 units over the next few years and build US capacity for 30,000 robots annually. These are company plans, not deployment outcomes. Boston Dynamics, 21 September
ANALYSIS. The centre is not merely testing equipment. It converts plant knowledge into a transferable machine skill.
Operators, maintenance staff and process engineers will expose the robot to real variation: misplaced parts, awkward access, changed sequences, safety cues and workarounds. Once one machine learns, that capability can travel across a fleet. The learning contribution of local workers can therefore create value far beyond their site.
Workforce implication. Firms need an explicit method for attributing, validating and rewarding embodied teaching. Otherwise, employees may be asked to train a system that scales their knowledge globally while their contribution remains classified as routine deployment support.
MEASUREMENT · PUBLIC INFRASTRUCTURE
The national accounts can see AI only by creating a new lens
REPORTED FACT. The Office for National Statistics published its proposed approach to a UK AI thematic account on 21 September. It intends to estimate the production and use of AI, supporting infrastructure, research and development, business investment, applications and services while remaining consistent with national-accounting principles.
The ONS says existing statistics lack the granularity to isolate AI’s economic impact. It identifies unresolved questions around definitions, data, residency, economic ownership and whether value sits in an owned asset or access through a licence. The publication is a methodology roadmap, not official statistics. ONS, 21 September
ANALYSIS. Enterprises have the same visibility problem at smaller scale. AI costs sit in software, cloud, security, training and change budgets. Value appears in functions. Human review, exception handling and data stewardship disappear into existing jobs.
An enterprise “AI account” should not pretend to produce one perfect productivity number. It should reveal the full production system: machine service consumed, human complement required, capability created, risk transferred and value realised. That is also the evidence base needed for fair responsibility.
ORGANISATION DESIGN · GLOBAL CAPABILITY
AI is not ending the global capability centre; it is changing its comparative advantage
REPORTED FACT. Starbucks has agreed with the Tamil Nadu government to establish its first Indian global capability centre in Chennai and hire roughly 800 technology professionals. The investment amount was not disclosed.
Reuters reports that India now has more than 2,100 global capability centres employing about 2.36 million people, with work expanding beyond back-office processing into software, finance, product development and research. Starbucks cited skills, infrastructure and lower attrition. Reuters, 21 September
ANALYSIS. If AI simply removed routine technology work, a new 800-person centre would look anachronistic. A different interpretation is more plausible: global centres are becoming locations where enterprises assemble scarce context, engineering, control and continuity around machine-scale operations.
Cost still matters. So do talent depth, retention and round-the-clock coverage. But the durable advantage may shift from processing volume to owning operational context: understanding how global platforms behave across markets, finding exceptions and translating local evidence into reusable systems.
TENUOUS BUT PLAUSIBLE · Confidence: medium-low · Horizon: 12–36 months
The agent audit log could become a shadow performance record
BigID’s announcement concerns security and compliance, not employee performance. Yet once agent actions are tied to named people, the data will be tempting.
SPECULATION. Organisations may begin using agent telemetry to infer who delegates effectively, who triggers exceptions, who overrides recommendations and whose work produces incidents. That could surface real capability—or create a misleading, intrusive score of human performance based on systems people do not control.
The causal chain is plausible: technical attribution creates person-level activity data; leaders seek evidence of AI adoption and productivity; telemetry enters workforce analytics; behaviour shaped by interface defaults becomes interpreted as individual competence.
What to watch. Whether agent logs flow into performance systems, whether employees can contest machine-derived interpretations, whether contextual variables are retained and whether organisations separate learning telemetry from disciplinary evidence.
The constructive alternative is to use traces first for workflow improvement: identify weak permissions, poor evidence and recurring hand-offs before ranking people.
WORKFORCE WELLBEING · CONTROL
Moral load belongs in the AI risk register
The reported distress among AI researchers is an extreme case, but the mechanism can travel. A recruiter may worry that an opaque screen excludes people unfairly. A clinician may inherit recommendations they cannot fully reconstruct. A safety engineer may see a deployment risk while commercial authority sits elsewhere.
ANALYSIS. These are not simply resilience problems to solve with wellbeing benefits. They may indicate a mismatch among responsibility, information and authority.
A useful psychosocial assessment should ask: what harmful outcome can this role foresee, what is the person expected to prevent, what evidence do they receive, and can they actually change the decision? Where the final answer is no, redesigning the mandate may matter more than counselling the individual to tolerate it.
NOISE FILTER
Attribution is not accountability
A named user, immutable log and approval click can make governance look complete. None proves that the person understood the system, possessed a realistic alternative or could alter the outcome under delivery pressure.
Conversely, distributed responsibility must not become responsibility-free automation. The test is not how many names appear in a matrix. It is whether each consequential choice has an owner with the evidence and authority to make it—and whether affected people have a route to remedy.
Operating-model implication
Replace the single accountable human with an accountability surface
| Decision | Named role | Evidence retained | Right that must exist |
|---|---|---|---|
| Set the objective | Business sponsor | Purpose, trade-offs and affected groups | Revise the objective |
| Select the capability | Technology owner | Model, tests, limitations and changes | Replace or narrow the capability |
| Grant the mandate | Process and control owners | Permissions, thresholds and expiry | Suspend access |
| Operate and challenge | User or frontline team | Sources, exceptions and interventions | Reject, pause and escalate safely |
| Repair the outcome | Organisational remedy owner | Affected people, correction and learning | Compensate and change the system |
The accountability surface makes several responsibilities visible without pretending they are interchangeable. One executive should still own the objective; one authorised person should still be able to stop the work. What disappears is the fiction that the closest human caused everything around the action.
Human control watch
Assistance: a person performs the work and AI informs judgement. Accountability can remain individual where the evidence is inspectable, professional competence is adequate and rejection is genuinely possible.
Delegated execution: an agent acts through a person’s mandate. Control requires separating credential attribution from the upstream decisions that shaped capability, permissions and targets.
Autonomous control: a system acts continuously across people or systems. Accountability must attach to the organisation’s objective, architecture and remedy—not merely to the employee receiving an exception.
Today’s shift: human control is moving from naming a person after an action to designing a network of people who can shape the system before, during and after it acts.
Capability-model update
| Gaining value | Under pressure |
|---|---|
| Responsibility-topology designer | RACI ending at the nearest user |
| Agent-mandate steward | Credentials treated as complete accountability |
| Embodied-work teacher | Robot training classified as deployment support |
| AI production accountant | Software cost used as a proxy for AI value |
| Psychosocial authority assessor | Wellbeing support without mandate redesign |
| Telemetry-rights custodian | Agent logs repurposed silently for performance scoring |
ONE THING
IF I WERE TO DO ONE THING NOW
Write one responsibility card
◎ PURPOSE ─── ◇ CAPABILITY ─── □ MANDATE ─── ✋ CHALLENGE ─── ↺ REMEDY
Use the agent-assisted workflow whose consequence limit you set in the previous exercise—or choose one current workflow—and write a single-page responsibility card this week naming who owns its purpose, capability selection, mandate, frontline challenge and remedy. Beside each name, record the one decision that person can actually change; if a role carries responsibility without a real decision right, fix that mismatch or escalate it to the executive sponsor. Do not redesign the governance framework or create another committee. Test one card with the people named on it. The result will show whether your audit trail reflects effective control and will turn the earlier border, near-miss and consequence work into a fairer operating agreement.
Mental-model update
The permeable enterprise has acquired earned authority, an executable constitution, a capability border, a memory for failure and a limit on consequence.
Today it acquires an accountability surface.
Elastic autonomy cannot rest on one person standing behind every machine act. Responsibility must follow effective control across the objective, capability, mandate, operation, challenge and remedy—while authority to intervene remains unmistakably concentrated.
The emerging North Star is a permeable enterprise in which capability can move, accountability cannot evaporate and no individual is left carrying the weight of a system they were never empowered to govern.
Questions for the executive table
- Where does your audit trail name a person whose real authority is smaller than their apparent accountability?
- Which agentic objective has no clearly identified owner for remedy when an affected employee or customer is harmed?
- Are frontline people rewarded for challenging the mandate, or only for operating within it?
- When workers teach a robot or agent a reusable exception, how is that contribution recognised and protected?
- Could agent telemetry enter performance management today without the employee knowing or contesting its interpretation?
Evidence note. BigID and Boston Dynamics describe their own products and deployment plans; capability and scale claims are not independently verified outcomes. New York’s implementation timetable concerns a specific law for large frontier developers. The proposed US–China notification mechanism is preliminary. The Financial Times reports individual experiences and does not establish prevalence of distress across AI organisations. The ONS publication is a methodological roadmap, not an estimate of AI’s current economic contribution. The Starbucks figures come from the Tamil Nadu government and industry research cited by Reuters. The concepts responsibility compression, responsibility topology, accountability surface and moral load are original AyEye analysis, not claims made by the cited sources.
