29.05.2026

6 min read

Nearly three-quarters of organizations are integrating autonomous AI agents into their data and processes. Yet only one in five has a tested contingency plan for when an agent goes off the rails. This gap isn’t a tech issue-it’s a leadership issue. Scaling without defining who owns the outcome isn’t a KI problem; it’s a governance vacuum.

Key takeaways

  • 74 percent scale agents, 20 percent are prepared. Most grant autonomous AI access without a tested contingency plan.
  • No one is accountable. CIOs, CFOs and COOs spot governance gaps because responsibility for AI outcomes was never assigned.
  • The board is asking. Directors demand clear visibility into AI risk and liability, tied to regulatory requirements.

Related:How capital markets rate AI governance  /  Who decides what AI considers true

What sets Agentic AI apart from earlier AI

What is Agentic AI? Agentic AI refers to systems that don’t just respond-they act. They make decisions, invoke tools, and trigger actions in other systems. An agent books, orders, or alters data without requiring human sign-off at every step. That autonomy is precisely what makes liability so urgent.

A conventional language model suggests text; a human reviews it. An agent acts. The difference sounds small but reshapes the chain of accountability. When an agent places the wrong order, misinforms a customer, or writes data it shouldn’t touch, there’s no intervening checkpoint where someone could have intervened. The error occurs before anyone notices.

Current figures show how far practice has outpaced control. Nearly three-quarters of organizations already grant agents access to data and core processes-whether in pilot, scaling, or production. Only about 20 percent have a tested plan for the incident. That gap is the real risk, not the technology itself.

20 %
of organizations have a tested contingency plan for when an AI agent malfunctions. 74 percent already grant agents access to data and processes.
Source: Industry surveys on Agentic AI, 2026

Why Responsibility Vanishes

The pattern is familiar from every failed transformation. A technology is introduced because it’s available and competitive pressure demands it. Responsibility is tacked on later-whenever there’s time. With a tool that acts on its own, that delay is dangerous. The agent doesn’t wait for governance to catch up.

In large corporations, this shows up as a gap in coordination between functions. The CIO sees the technical integration. The CFO sees the costs. The COO sees the process. None of them automatically owns the question of who is liable when the agent makes a mistake at the intersection of all three domains. Without deliberate assignment, that question falls through the cracks-literally-until an incident forces it into the spotlight.

Governance Vacuum

  • Agent scales, responsibility follows later
  • No tested emergency plan
  • Liability falls between CIO, CFO and COO

Robust Setup

  • A named owner for every agent deployment
  • Tested incident plan before go-live
  • Clear boundaries on what an agent may access

What the Board Demands Now

The good news is that pressure is coming from the top, giving leadership a lever to act. Boards increasingly ask for a clear view of AI risk and liability, tied to regulatory requirements under NIS2, DORA and the EU AI Act. That question can’t be answered with a slide touting innovation appetite. It demands a commitment: who owns which agent, which data it may touch, and what happens when things go wrong.

Implementation is beginning to follow a pattern. Instead of distributing governance across individual projects, a central layer is emerging that consolidates control, steering and orchestration of agents. Whether you call it a command center or simply a clear point of accountability is secondary. What matters is that there is at least one place with oversight-and the authority to pull the plug in an emergency.

An agent that may act but has no owner is not progress. It is a risk that simply hasn’t materialised yet.

The order of steps is the real leadership decision. Whoever scales first and clarifies responsibility later has inverted the sequence and is banking on luck. Whoever defines ownership and incident response before go-live may lose two weeks. They gain control over a technology that would otherwise outpace their own oversight. Those two weeks are the cheapest insurance a CIO can buy right now.

Frequently Asked Questions

How does Agentic AI differ from previous AI tools?

Traditional AI makes suggestions, but humans decide. An agent acts autonomously, calls tools, and executes actions in other systems. This removes the intermediate step where a human could catch an error.

How wide is the gap between deployment and safeguarding?

Significant. About 74 percent of organizations grant agents access to data and processes, yet only roughly 20 percent have a tested contingency plan for failure scenarios.

Who should be responsible for an agent?

Every agent deployment requires a designated owner who defines access, boundaries, and failure behavior. Without this assignment, liability remains unclear and falls between the CIO, CFO, and COO.

What role does regulation play?

NIS2, DORA, and the EU AI Act demand verifiable control and documentation. Executives must demonstrate how an AI system makes decisions and who is liable. This can only be met with clear governance-not scattered deployment.

Does governance slow down adoption?

Hardly. Defining ownership, boundaries, and contingency plans takes little time before going live. It prevents the costly incident that can derail an entire initiative. Control and speed are not mutually exclusive here.

Image source: AI-generated (May 2026), C2PA certificate embedded in image

Share this article:

Also available in

More Articles

29.05.2026

Cloud sovereignty becomes a boardroom issue: What the EU tech sovereignty package means for DACH

Tobias Massow

6 min read The EU unveiled its Tech Sovereignty Package on 27 May. It proposes restricting the use of ...

Read Article
29.05.2026

Sight is no longer enough: Why boards demand defensibility from the CIO

Benedikt Langer

6 min read For years, CIOs sold IT budgets with a vision of transformation. That no longer works. After ...

Read Article
29.05.2026

Agentic AI without an owner: Who is liable when the AI agent makes a mistake

Eva Mickler

6 min read Nearly three-quarters of organizations are integrating autonomous AI agents into their data ...

Read Article
29.05.2026

725 billion US-Dollar CapEx: What the hyperscaler bet means for DACH-CIOs

Bernhard Liebl

5 min read The hyperscalers have released their quarterly figures. The message is clear: Google, Amazon, ...

Read Article
27.05.2026

What 2.6 to 3.4 trillion euros in AI CapEx means for DACH CIOs

Bernhard Liebl

7 min read On 20 May 2026, Nvidia CEO Jensen Huang dropped a number during the Q1-FY2027 earnings call ...

Read Article
26.05.2026

BlackRock and Morgan Stanley Evaluate AI Governance

Eva Mickler

8 min read Morgan Stanley and BlackRock have baked AI governance openly into their valuation logic as ...

Read Article
A magazine by Evernine Media GmbH