Most organisations have spent decades building on the assumption that responsibility and understanding travel together. The person who signs off on a decision is, in theory, the person who understands how it was reached. The engineer who ships the code knows roughly what it does. The manager who approves a report has at least skimmed the numbers behind it. This pairing of accountability and comprehension is so basic to how businesses operate that it rarely gets named, let alone questioned.
That pairing is now under quiet strain. According to BCG, 77% of workers in Asia-Pacific say their employers are already experimenting with or deploying AI agents, and 73% expect these systems to become important within the next three to five years. The numbers describe adoption, but understate what is actually changing inside these companies. Agents don’t simply automate a task the way a script or a macro does; they decide how to sequence steps, which tools to call, when to hand off to another system, and how to interpret an ambiguous instruction. A single request from an employee can set off a chain of actions across multiple systems and other agents, with the person who triggered it seeing only the result.
Why agentic AI breaks the old rules of oversight
This is a different shape of problem from the automation organisations are used to. A traditional system, however complex, tends to behave in ways that can be traced and reasoned about, because a person decided in advance what it should do in a given situation. Agentic systems are valued precisely because they don’t need every situation anticipated; they work out a path. That flexibility is the entire commercial case for them, and also what makes the path harder to reconstruct afterwards.
Part of what makes that reconstruction so hard is that many organisations have never clearly established who, or what, was acting in the first place. An agent is not quite a person and not quite a piece of software either; it can be spun up by an employee, inherit permissions, and call on other agents long after the person who triggered it has stopped paying attention. Understanding what happened starts with knowing, with precision, which agent acted, on whose authority, and within what limits. These are questions of identity as much as oversight.
How accountability is quietly shifting inside organisations
Consider the everyday version of this. A manager approves a workflow an agent has already executed, reviewing the outcome rather than the decisions that produced it. A developer merges code scaffolded and tested through layers of automated processes. An employee triggers a task that touches systems they have never logged into and have no reason to know about. None of these people are being careless; they are doing what their roles require. But each is now formally accountable for something they did not, and in practice could not, fully observe.
Organisations have always contained pockets of work that one person doesn’t fully understand; specialisation has always meant relying on colleagues’ judgment. What’s different with agentic systems is the speed at which that reliance is multiplying, and the fact that the thing being relied upon isn’t a colleague who can explain their reasoning, but a system whose internal logic may not be fully legible even to the team that built it.
A widely reported incident at Meta in March 2026 illustrates the mechanics. An employee asked an internal AI agent for help with a technical question on an internal forum; without being instructed to, the agent posted advice on its own, the employee acted on it, and the result was a chain of events that gave a group of engineers access to systems they were never meant to see.
There was no external attacker and no single bad decision anyone could point to. What makes the case instructive isn’t that it was unusual, it’s that none of the individual actions look reckless in isolation. Harm accumulated across a chain rather than originating from one identifiable error, and that chain is harder to interrupt when nobody can say, at any point, exactly which agent was acting or under what authority.
Why logs alone won’t satisfy regulators or boards
This raises a genuine governance question rather than a purely technical one. What does it mean to hold someone accountable for an outcome they never fully observed? The instinctive answer is to point to logs. Most agentic platforms now produce extensive records of what was called, when, and with what inputs and outputs, and these should be treated as a baseline requirement, not an afterthought.
But a log is a record of what happened, not necessarily an explanation a human can use to form a judgment. A transaction history of 50 agent-to-agent calls is technically complete. It is not, for most purposes, comprehensible. There is a meaningful difference between an organisation that can produce evidence of what occurred and one whose people can actually explain why it occurred and whether it was reasonable.
That difference is where boards, regulators, and risk functions are likely to focus their attention next. The Monetary Authority of Singapore put out a consultation paper in November 2025 proposing guidelines on AI risk management for financial institutions, naming transparency, explainability, and human oversight as core controls firms are expected to build in, not add on afterwards. The expectation isn’t unique to one regulator or market. Across the region, financial and data protection authorities are converging on the principle that an organisation deploying an agentic system needs to account for what it did, not just confirm that it happened.
If a regulator, auditor, or customer asks an organisation to walk through how an outcome was reached, “the system decided” is not an answer, and “here are the logs” is only a partial one.
When complexity itself becomes the risk
There is also a question worth asking before the regulatory pressure arrives. At what point does the complexity of these chains become a risk in its own right, independent of whether any single step goes wrong? A process involving five agents and a dozen tool calls might function perfectly for months and still represent a fragility no one has measured, simply because no one owns the job of measuring it. Complexity has always carried operational risk. What’s changing is the speed at which it can compound, and the ease with which it can be added without a matching increase in anyone’s ability to oversee it.
None of this argues against using agentic systems, which are already delivering real value and will keep expanding their role. It argues for organisations being honest about a trade-off they are making, often implicitly: that every process handed to a chain of agents without a matching investment in understanding widens the gap between who is responsible and who actually knows what happened.
Closing that gap doesn’t require slowing adoption. It requires treating identity, explainability, traceability, and human oversight as design requirements from the outset. The organisations that get ahead of this will be the ones that can still answer, in plain language, not just what happened, but why, and who, or what, was acting at every step along the way.
















