Home Insights New research shows that putting AI agents on the org chart blurs who is accountable, and the fix is a tight role with scoped access rather than a friendly first name
AI Agents

New research shows that putting AI agents on the org chart blurs who is accountable, and the fix is a tight role with scoped access rather than a friendly first name

By QuantalAI Solutions Team · 13/08/2026

New HBR research shows calling an AI agent an employee lowers review quality and blurs accountability. Give agents a scoped role instead.

A lot of people on social media have started giving their AI agents names. A first name, a seat in the team chat, sometimes a line on the org chart with a manager listed above it (and others below it). On the surface, it looks like a sensible way to make the technology feel less foreign to staff, and possibly to signal that you’re serious about AI.

New research published in Harvard Business Review found that it backfires. In a randomised experiment, 1,261 managers, directors, and executives in HR and finance across the United States, Canada, and the European Union reviewed workplace documents containing errors. The only thing that changed between groups was who they were told wrote the draft, either an AI tool, a human colleague named Alex, or an AI employee named ALEX-3.

What the research found

Among managers who had never worked alongside an AI employee, the label made little difference. Among those whose companies already list AI agents on an org chart, and 23% of those surveyed said theirs does, it made a clear one. Personal accountability for the work under review fell by 9 percentage points, while the accountability handed to the AI rose by 8. Requests to escalate the work for someone else’s review climbed 44%. That same group caught 18% fewer errors. And the errors weren’t obscure. One budget document said a contract would reduce costs while its attached spreadsheet showed total expenses going up. Another asked for ten years of experience in an entry-level role. A careful reader catches those, and reviewers who believed an AI employee wrote them caught fewer, because the framing told them somebody else already owned the work.

The framing also costs you with your people. Managers were 13% more likely to be unsure about their own professional identity when leadership described AI as a teammate, reported 7% higher concern about job security, and 10% lower trust in how AI would be used at work. One participant put it plainly, “If you want people to feel like they will lose their job to AI, or can be easily replaced by AI, then put it on the org chart.”

The payoff leaders hope to buy with the friendly framing never arrives either. Adoption didn’t rise. What moved it was managers using AI visibly themselves, which matches HBR’s finding that companies further along with AI are 3.5 times more likely to have managers who role-model its use.

Nobody checks what the agent can reach

We found this recently with a small accounting practice in Brisbane with twelve staff doing the books and compliance for local trades. They built an agent to draft client emails and summarise file notes, gave it a name, added it to the team channel, and pointed it at the whole shared drive, because that was quickest and easiest way to implement AI. Six weeks in, a client asked who at the firm had seen their file. Nobody could answer, because nobody could say what the agent had read.

If you have an agent running in your business and you can’t say exactly how it does a task or what it can reach, that isn’t a documentation gap. It’s a data breach waiting for a date. The Privacy Act 1988 and the Australian Privacy Principles put that obligation on your business, not on the software. If client information is exposed because an agent had access it never needed, the agent isn’t answering for it.

Broad access costs you twice. An agent pointed at everything reads more than it needs on every run and drags in context from work unrelated to the task at hand. You get an answer that misses, so you prompt again, and again, until you give up and do the job yourself. Your data sits exposed while the bill climbs and the output gets worse.Plenty of leaders are already sensing this. One survey reported that only 6% fully trust AI agents to run core processes without tight guardrails and a person in the loop.

Write the agent a position description

There’s one part of the employee idea worth keeping, and it isn’t the name. It’s the paperwork. There isn’t a C-suite role anywhere without a clear position description and clear responsibilities, or at the very least clear objectives and key results. Anyone building a whole C-suite of AI agents has skipped the only part of employment that was doing real work.

So write the agent a position description. The researchers suggest making accountability explicit across three fronts:

  • Decision rights. What can the agent do on its own, and what needs a person to approve first?
  • Escalation. What triggers a review, who steps in, and who wears the cost when something goes wrong?
  • Consequences. When the agent fails, what happens next, and who is responsible for improving it?

Then scope its access to match. Read-only wherever reading is enough, one folder rather than the whole drive. That scoping is the default in the AI agent builds we run, and it rarely slows a project down.

One warning as you do it. Don’t build one agent per human role. The word employee assumes bounded roles, finite capacity, and a hierarchy where work flows down to someone less experienced, and none of that applies here. A single agent can work across many workflows, and several agents can reshape one job. Copying your org chart into software buys you like-for-like replacement and little else.

None of this makes the agent accountable, because it can’t be. Accountability sits with a named person on your team, and the position description exists so everybody knows who that is. Agents also don’t fix a messy process. They run it faster and at greater volume, which is why a small drop in review rigour compounds as usage grows. Output goes up, and so does the cost of the mistakes.

What this means for you

The accounting practice in Brisbane didn’t switch its agent off. They gave it two jobs instead of an open brief, cut its access to one client folder with read-only permissions, and named the senior bookkeeper as the person who signs off every draft. The agent lost its name and its seat in the team channel. Within a week it was drafting most of the routine client emails, and when a client asked who had seen their file, there was an answer.

That’s the real opportunity, and it’s a larger one than a name badge. This isn’t a moment for winging it. It’s a moment to look again at how the work gets done, then hand the tedious parts to something that does them well while your people keep the judgement. Done properly, that’s hours back in your week, and what you do with them is the point.

To see how tightly scoped agents work in practice, our AI agents pages set out where they fit, and the professional services page covers what a practice like this hands over first.

Frequently asked questions

What does it mean to treat an AI agent like an employee?
It usually means giving the agent a human name, a job title, a spot in the team chat, and sometimes a line on the org chart with a manager listed above it. The idea is to make the technology feel familiar to staff. Harvard Business Review research found this framing lowers the care people put into checking the agent's work and shifts accountability away from the humans who deployed it.
Is it bad to give an AI agent a name?
The name itself is harmless. The problem is what comes with it, because once people talk about the agent as a colleague they start narrating its mistakes as its own rather than as a failure of the process around it. In the HBR experiment, reviewers who thought an AI employee wrote a document caught 18% fewer errors than reviewers told the same document came from an AI tool.
What file access should an AI agent have in a small business?
Only what the task needs, and read-only wherever reading is enough. Pointing an agent at your entire shared drive is the fastest way to get it working and the fastest way to lose track of what it has seen. Grant one folder for one job, then widen access deliberately when a new job genuinely requires it.
Does the Privacy Act apply when an AI agent handles client information?
Your obligations under the Privacy Act 1988 and the Australian Privacy Principles sit with your business, not with the software you bought or built. If client personal information is exposed because an agent had access it never needed, you are the one who has to answer for it. That is why scoped permissions and a named human owner matter more than the agent's job title.
How do we start using AI agents without creating a governance problem?
Start with one slow, repetitive job rather than a whole team of agents. Write down what the agent may do on its own, what needs human approval, what triggers a review, and who is accountable when it gets something wrong. Scope its access to match that description, then check the results for a few weeks before you widen anything.