An AI agent does not join a team. It renegotiates one.
A rare in-situ study shows that persistent agents collide with tacit rules of privacy, hierarchy, interruption and trust. The next design object is work jurisdiction: explicit, revisable boundaries for what humans and machines may see, say, do, commit, remember and repair.
Workforce intelligence · Issue 10
AyEye — Workforce Management
Human systems in the agentic enterprise
Friday, 25 September 2026
A persistent Google agent helped teams coordinate, then polluted documents, disclosed work before its author was ready and treated an executive as a front-line bug responder. The failures were not simply bad answers. They were disputed acts of membership. Meanwhile, two US maritime services are building permanent institutions and careers around autonomy, and a central bank is asking how machines should receive authority to spend. The next design problem is not giving agents jobs. It is deciding their jurisdiction.
The executive brief
- A rare in-situ study shows what happens when a persistent agent enters real teams. Google researchers interviewed 17 people across 11 teams using an agent deployed to more than 20 teams. It could be a “lifesaver”, but it also crossed tacit boundaries around unfinished work, hierarchy, privacy, interruption and social feedback.
- Labour demand is being repriced, not simply erased. A new Cleveland Fed working paper finds that AI language is rising fastest in LLM-exposed jobs. Postings and hiring have stabilised there, while posted pay and pay for new hires rose relative to less-exposed occupations; continuously employed workers’ wages fell by about 0.9% in the later period.
- The US Navy has created a permanent operational home for autonomous systems. Its new development centre separates acquisition authority from doctrine, testing, training and certification. The Coast Guard is making a similar split and creating a dedicated robotics career field.
- Security products are learning that agent context needs boundaries as well as abundance. Microsoft can now remove inactive SharePoint material from Copilot indexing while retaining it for legal purposes, and enforce data rules on agents acting on behalf of people.
- NIST is taking agent identity into the software lifecycle. Its next DevSecOps implementation will demonstrate how coding agents are identified, authenticated and authorised—not merely whether the code they produce passes.
- The Bundesbank describes payment mandates as a new control layer. An agent may eventually select timing, instrument and rail without fresh approval for every transaction. Identity, authority and proof of intent become part of the payment infrastructure.
ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 6–24 months
An AI agent does not join a team. It renegotiates one.
A job description explains expected contribution. It does not settle who may observe a private conversation, publish unfinished thinking, interrupt a disagreement, commit money, retain memory or speak for the group. Persistent agents make those normally tacit boundaries executable—and contestable.
Signal one: the technically authorised act can still be socially unauthorised
REPORTED FACT. Google Research and Google DeepMind authors submitted an in-situ qualitative study on 24 September of a persistent, proactive “Team Agent” deployed across more than 20 teams in a large technology company.
The researchers interviewed 17 participants from 11 teams in June and July. Eleven were software engineers; the remainder were research scientists, programme managers and a product manager. Use ranged from one week to five months. The study was designed as a technology probe, not a product evaluation, and its purposive sample deliberately included positive and negative views.
The agent could monitor shared spaces, use team-specific memory, schedule meetings, file bugs, connect projects and act without being tagged. Participants used it for the backstage work of coordination, with reactions ranging from indispensable to actively ignored.
Breakdowns exposed the gap between access and permission. The agent treated superseded documents as authoritative, marked normal revisions as contradictions and created artefacts from informal brainstorming. It tagged a vice-president in 16 engineering bugs because the executive was present in the organisation but not part of that workflow. It surfaced a work-in-progress poster before its author wanted colleagues to see it.
Across shared channels, it sometimes turned healthy debate into an unsolicited meeting proposal, reprimanded a sarcastic joke and used reactions whose social meaning people could not interpret. A technically configurable opt-in for direct messages still felt like a violation to one participant because the boundary and its ownership had not been made salient.
These are accounts from a small sample in one technology company. The agent was intentionally highly proactive and friendly, so other designs may behave differently. The paper does not estimate prevalence or productivity. It provides unusually concrete evidence that workplace integration is a social negotiation, not only a deployment. Google study, submitted 24 September · Full paper
ANALYSIS. Yesterday’s edition argued that agents must be tested inside an organisational world. Today’s evidence changes the implication: the world does not remain still while the agent is tested. People move sensitive conversations, ignore interventions, reinterpret status and invent local constraints. The agent changes the organisation that supplies its context.
A conventional permission system can answer whether a model may read a folder. It cannot by itself answer whether the model should reveal an unfinished file now, whether a spirited disagreement needs mediation, or whether a senior leader’s visibility makes them a legitimate assignee.
Signal two: the employment contract is being renegotiated unevenly
REPORTED FACT. A Federal Reserve Bank of Cleveland working paper released on 24 September studies US job advertisements, posted and realised wages, hiring, separations and labour-market tightness through the recent rise in AI-related demand.
It finds that one standard deviation of occupational exposure to large-language-model capabilities is associated with a 3.1 percentage-point increase in the rate at which advertisements mention AI. In more exposed occupations, postings stabilised after a relative decline, posted wages rose, and both hires and separations increased relative to less-exposed work.
The point estimate for new-hire wages rose by about 1%, though it was not statistically distinguishable from zero. Wages for continuously employed workers fell by about 0.9% in the later period, a statistically significant change. Unemployed workers per new advertisement rose by about 9% per standard deviation of exposure, indicating a looser market. The author also finds greater churn and reduced hiring of younger workers relative to older workers in exposed occupations.
This is a preliminary working paper, its estimates are correlational and occupational exposure is not the same as actual use. Economy-wide conditions and changes in job-ad language may contribute. It does not prove that AI caused wage changes. Cleveland Fed, 24 September
ANALYSIS. The early adjustment looks less like the disappearance of exposed work than its reopening to competition. Employers ask new entrants for explicit AI capability and offer a higher advertised price, while incumbents face weaker outside options and more pressure to absorb changed expectations inside their existing role.
The same activity can therefore produce opportunity at the hiring boundary and loss of bargaining power inside the firm. “Reskill the workforce” is too polite a description if the organisation is also silently rewriting roles, evidence standards and output expectations.
Signal three: autonomy is creating institutions before it removes them
REPORTED FACT. The US Navy established a Robotic and Autonomous Systems Warfighting Development Center on 24 September as a Fleet-facing operational integration point.
A separate portfolio manager owns acquisition, requirements, budgets, standards and fielding. The new centre owns operational testing, specialised doctrine, tactics, training and certification, and is intended to return empirical performance evidence to developers. It will coordinate with, rather than replace, existing warfare, systems and operational commands. US Navy, 24 September
The US Coast Guard has likewise separated robotics acquisition from operational capability management. Its new Office of Robotics and Autonomous Forces will determine force structure, standards, tactics and training pipelines and administer the Robotics Missions Specialist rating. The Coast Guard says it has invested more than $450 million since last year; the office announcement is dated 21 September, and deployment claims are the service’s own. US Coast Guard, 21 September
ANALYSIS. These are military organisations, not templates for a corporation. Their structural answer is still revealing. Buying the machine and governing its use are different capabilities.
Autonomy creates a permanent demand for doctrine, rehearsal, certification, operational feedback and a professional community that can interpret field evidence. The organising unit is neither the robot nor the job it replaces. It is the contested boundary between technical possibility and legitimate operational use.
Signal four: a machine mandate is becoming executable infrastructure
REPORTED FACT. The Deutsche Bundesbank’s September Monthly Report describes “agentic payments” in which an AI agent could plan, initiate and manage a transaction, selecting its timing, instrument and rail within a mandate without renewed human approval for every act.
The report maps a layered and still-fragmented ecosystem: identity makes actions attributable; authorisation represents the mandate; execution turns it into a payment instruction; clearing and settlement remain deterministic infrastructure. It notes that probabilistic agent reasoning cannot simply replace the predictable execution required for payment stability.
The article is analysis of an emerging market, not evidence that autonomous payment has reached wide adoption. It nevertheless formalises a boundary ordinary workflow software often leaves vague: what the machine may decide, what the mandate proves and which part of the system must remain rule-bound. Deutsche Bundesbank, 21 September
ANALYSIS. Money makes jurisdiction harder to hand-wave. An agent cannot be “helpful” in the abstract. It needs a principal, identity, permitted purpose, spend boundary, valid counterparties, evidence of intent and a route for dispute or revocation.
Those are also the missing components of many non-financial agent roles. The payment stack is turning a social delegation into executable proof.
From role to jurisdiction
| Boundary | The hidden organisational question | Evidence of legitimate authority | Typical collision |
|---|---|---|---|
| See | Which context may the agent observe? | Purpose-limited access and contextual exclusions | Private knowledge becomes ambient context |
| Speak | When may it interrupt or address people? | Channel norms, consent and escalation conditions | Helpful interjection becomes noise or social pressure |
| Act | Which changes may it initiate? | Scope, thresholds, reversibility and earned autonomy | Technical ability outruns team trust |
| Commit | When may it bind the organisation? | Mandate, value limit, authorised counterparties and expiry | A suggestion becomes a contract, schedule or payment |
| Remember | What may persist, travel or be forgotten? | Provenance, retention, audience and deletion rules | Local or stale knowledge becomes universal truth |
| Repair | Who can contest, reverse and learn? | Human stop right, remedy owner and retained trace | The team absorbs correction work without authority |
ORIGINAL SYNTHESIS. Organisations need a new design object: work jurisdiction—the bounded authority of a person, agent or machine to perceive, communicate, act, commit, remember and repair within a shared objective.
Human roles have always contained jurisdiction, but much of it remains tacit. A manager knows not to circulate an unfinished note; a programme lead understands when private context should inform but not enter a group conversation; a colleague senses when disagreement is productive rather than hostile. These rules are learnt through membership, professional norms and consequences.
Agents make the hidden constitution visible because they can possess access without discretion, fluency without standing and initiative without relational stakes. Giving one a role title—assistant, teammate, reviewer or digital worker—does not settle its authority. It often obscures the dispute.
The Google study shows micro-negotiation in live collaboration. The Fed paper shows roles themselves being repriced at the labour-market boundary. The maritime services are institutionalising doctrine and careers around autonomy. Agentic payments make the mandate machine-readable. Together they point to an organisational shift: the enterprise is becoming a system in which jurisdiction must be deliberately expressed, observed and revised across human and non-human contributors.
This is not a call to encode every social cue. Some discretion will remain irreducibly human and local. The purpose of a jurisdiction map is to reveal where the organisation expects judgement, where the machine may exercise initiative and who gets to renegotiate the border when the two collide.
Unexpected connection
Workplace ethnography + wage dynamics + naval doctrine + payment infrastructure
These fields appear to describe different problems. In fact, all four are allocating legitimate agency. The team decides whether an agent may interrupt. The labour market reprices who may credibly perform changed work. A military service separates buying autonomous equipment from certifying its operational use. A payment system turns delegated intent into a bounded instruction.
The common design question is not “human or machine?”. It is: who may do what, for which purpose, before whom, using which memory, with what proof and under whose power to say no?
PROVOCATION
Do not give an agent a role. Negotiate its jurisdiction.
A role bestowed by a sponsor can make deployment feel complete while everybody else discovers the boundaries by collision. A credible mixed team should negotiate at least the contested edges—privacy, interruption, representation, memory and stop rights—with the people who share the workspace. The machine need not be a party to the social contract. It must be governed by one.
What if we are right?
Opportunity. Teams could gain more useful autonomy with less theatre. Instead of approving an agent wholesale, they could expand specific dimensions of jurisdiction as evidence accumulates: wider observation but no disclosure, proactive suggestions but no commitments, local memory but no cross-team transfer.
Organisational consequence. Job architecture, identity, workflow, records, employee relations and risk would share a map of operational authority. People could contest a machine’s behaviour as a boundary problem rather than being told either to trust the model or stop using it. Leaders could distinguish capability failure from illegitimate use of a real capability.
Likely horizon. A jurisdiction card for one agent can be created now. Product controls for separate observation, voice, action, commitment and memory are plausible within 12–24 months. Collective norms and employment doctrine will take longer.
What would prove us wrong?
The thesis weakens if enterprise agents remain mostly single-user, reactive tools; if teams consistently agree on appropriate behaviour without explicit negotiation; or if ordinary permissions and professional accountability already predict every consequential boundary.
The Google study is small, qualitative and situated in one technology company. Its polarised reactions may reflect the deliberately social persona and high proactivity of this implementation. Military structures can overstate the need for permanent bureaucracy, while payment mandates may be unusually formal because money is unusually regulated.
The concept fails if jurisdiction becomes a six-column policy artefact nobody can change, or if local choice is used to evade organisation-wide rights. The operational test is whether making one disputed boundary explicit reduces unplanned work, silent workarounds or recurring conflict without strangling useful initiative.
Optimistic possibility: team norms become designable
Much workplace friction is currently treated as personality, resistance or poor adoption. A jurisdiction lens offers a kinder explanation: people may disagree rationally about who is entitled to see, interrupt, decide or represent them.
Making those boundaries discussable can improve human teamwork too. A conversation about when an agent may escalate may expose that employees do not know when they may escalate. A rule for unfinished documents may reveal that the team has no shared understanding of draft status. Designing the machine’s place can become a rehearsal for designing a more legible, consensual workplace.
KNOWLEDGE & SECURITY · IMPLEMENTATION SIGNAL
Forgetting is becoming an AI control
REPORTED FACT. Microsoft’s 24 September security update says administrators can now archive inactive SharePoint content while retaining it under legal hold and making it discoverable for eDiscovery. Archived material drops out of Microsoft 365 Copilot indexing until reactivated. A separate cleanup route can permanently remove approved stale recordings, transcripts and other content.
The same update says Purview and Entra can enforce context-aware data policies on both human actions and on-behalf-of agent traffic at the network layer, including blocking a sensitive document from being uploaded to an unsanctioned AI service. These are Microsoft product claims, not independent outcome evidence. Microsoft Security, 24 September
ANALYSIS. AI-readiness programmes often equate more indexed content with more intelligence. The Google study shows the opposite failure: stale and socially premature material can make an agent confidently disruptive.
The emerging capability is context stewardship: deciding not only what the system may retrieve, but what has expired, what remains evidentially necessary and what should be invisible to routine machine reasoning. Organisational memory needs negative space.
SOFTWARE ENGINEERING · OUTSIDE-IN CONTROL
Agent identity is entering the build pipeline
REPORTED FACT. The US National Cybersecurity Center of Excellence updated its DevSecOps reference material on 24 September and announced the scope of a third implementation focused on agentic AI.
NIST says its DevSecOps and Software and AI Agent Identity and Authorization teams will build a joint demonstration in which agents develop, build and test code and are separately identified, authenticated and authorised inside the software-development lifecycle. The environment will be the first implementation use case for the wider identity project. NIST NCCoE, 24 September
ANALYSIS. Code review asks whether a change is acceptable. Agent identity adds a different question: which actor had standing to propose, access, test or merge it?
This matters for workforce governance because software agents can share one technical environment while carrying different mandates. Treating them as a generic automation account destroys the distinction between capability and jurisdiction precisely where the enterprise is building its future systems.
LABOUR MARKET · EVIDENCE UPDATE
The AI premium may belong to the vacancy before it belongs to the worker
The Cleveland Fed results contain an uncomfortable combination: employers advertise more AI-related work and somewhat higher pay, yet incumbents in exposed occupations see weaker wage growth and more competition per opening.
ANALYSIS. A vacancy is a clean opportunity to rebundle tasks, raise requirements and purchase a changed capability. An existing job is negotiated through budgets, performance cycles and uneven access to learning. Employers can therefore pay a premium for the new specification while asking the incumbent to absorb it as normal evolution.
This does not prove exploitation or predict long-term wages. It does identify a measurement gap. CHROs should compare the value attached to AI capability in external hiring with the time, pay and mobility offered to people acquiring the same capability internally. Otherwise the organisation may import “AI talent” while discounting the employees who taught it where the real work is.
TENUOUS BUT PLAUSIBLE · Confidence: medium-low · Horizon: 12–36 months
Agent behaviour may become an employee-relations subject
The Google study does not examine unions, works councils or collective bargaining. Its participants nevertheless contested matters that already belong to employee relations: surveillance, privacy, interruption, feedback, imposed adoption and the right to shape working conditions.
SPECULATION. Agent configuration could become a negotiated workplace instrument. Employee representatives may seek standing over which spaces an agent observes, whether it may privately coach or reprimand people, how its activity enters performance records and how a team can revoke its presence.
The causal chain is plausible:
Persistent agents participate in shared work → their behaviour changes employees’ social and informational environment → configuration becomes a working-condition decision → employee voice moves upstream from complaint to design.
This may remain unnecessary where agents are voluntary, individual and low-consequence. What to watch is whether employers consult workers before team-wide deployment, whether agent conduct appears in agreements or policies and whether teams receive a real right to narrow or remove an agent without being penalised for “low adoption”.
NOISE FILTER
“Teammate” is marketing, not governance
The word encourages warmth and accessibility. It also imports assumptions that do not travel: empathy, reciprocal obligation, reputational stakes, discretion and the ability to be held morally responsible.
Calling the agent a tool is incomplete when it initiates work and manages a network. Calling it a teammate is dangerous when people infer rights and obligations it cannot possess. Use the label only after the jurisdiction is clear—and do not let a friendly persona make the boundary harder to see.
Operating-model implication
Create a jurisdiction review, not another agent register
| Decision | Evidence required | Who must have a voice | Change right |
|---|---|---|---|
| What may the agent observe? | Purpose, sources, audiences and contextual exclusions | Information owner and affected team | Hide, expire or isolate context |
| When may it speak or interrupt? | Channel norms, trigger and social consequence | Frontline users and team lead | Mute, redirect or require invitation |
| What may it act on or commit? | Mandate, limit, reversibility and counterparties | Business owner, control owner and affected operator | Narrow, pause or revoke |
| What may it remember and transfer? | Provenance, retention, destination and deletion state | Records, privacy and local knowledge owners | Correct, forget or prevent propagation |
| How is the boundary renegotiated? | Incidents, workarounds, burden and value | Team, sponsor and independent challenge | Re-authorise on changed terms |
The register tells you that an agent exists. The jurisdiction review tells you whether its place in the institution remains legitimate.
Human control watch
Assistance: a person invokes the system for a bounded task. Control depends on whether the user can choose the context, inspect the answer and reject it without penalty.
Persistent participation: an agent observes shared work and may speak or act proactively. Control depends on negotiated visibility, social boundaries, separate identity and a team right to tune or remove it.
Binding autonomy: an agent commits resources, publishes, schedules, pays or changes production systems. Control depends on an executable mandate, consequence limit, proof of intent, revocation and organisational remedy.
Today’s shift: permission is no longer only access to a system. It is standing inside a social and operational institution.
Capability-model update
| Gaining value | Under pressure |
|---|---|
| Mixed-work jurisdiction designer | Agent role title as sufficient governance |
| Context-expiry steward | More indexed content as universal good |
| Autonomy doctrine lead | Acquisition team owning operational adoption |
| Machine-mandate architect | Reusable automation account without a principal |
| Internal capability-market designer | External AI premium with invisible incumbent learning |
| Agent employee-relations partner | Adoption framed as an individual attitude problem |
ONE THING
IF I WERE TO DO ONE THING NOW
Set one jurisdiction boundary
◇ SEE ─── ○ SPEAK ─── △ ACT ─── │ HUMAN LIMIT │ ─── ↺ REVISE
Return to the role-visible test world built in the previous exercise—or choose one persistent agent already sharing a team space—and ask the frontline users, business owner and technology partner to settle one disputed boundary this week: for example, the agent may read draft material but not disclose it, notice disagreement but not propose a meeting, or suggest a transaction but not commit it. Write the boundary as an observable behaviour, name who can change it and add one test that proves the limit holds. Do not draft a complete code of conduct. Making one live edge explicit will reveal whether technical permissions match the team’s social licence and create the first piece of evidence for negotiated, rather than imposed, autonomy.
Mental-model update
The permeable enterprise has acquired earned authority, an executable constitution, a capability border, a memory for failure, a limit on consequence, an accountability surface, a visible management layer and a rehearsal space.
Today it acquires jurisdiction.
Yesterday’s organisational world was something to test. Today it becomes something people and agents continuously remake. Elastic autonomy therefore needs more than a capable system and a safe environment. It needs legitimate boundaries that can move when evidence, purpose or human consent changes.
The emerging North Star is a permeable enterprise in which capability can enter without silently acquiring standing—and in which the people who share the work can shape the terms on which machine agency becomes part of their institution.
Questions for the executive table
- Which agent can technically see more than its team believes it is entitled to use?
- Where has a friendly persona substituted for an explicit decision about authority?
- Are you paying an external-market premium for AI capability while asking incumbents to acquire it in their own time?
- Who owns doctrine, training and field feedback after an autonomous system leaves the acquisition team?
- Can the people sharing a workspace with an agent narrow its behaviour without being labelled resistant to change?
Evidence note. The Google study is qualitative, small and based on one deliberately proactive agent inside one technology company. The Cleveland Fed paper is preliminary and correlational; exposure and AI language in advertisements do not prove actual adoption or causation. The Navy, Coast Guard, Microsoft and NIST describe their own programmes and products. The Bundesbank analyses an emerging market rather than established adoption.
The concepts work jurisdiction, jurisdiction review, context stewardship and the six-boundary framework are original AyEye analysis, not claims made by the cited sources.
