Jul 21, 2026 AI

The Three Questions I Ask About AI Agents (And How to Answer Them in Days)

All posts

IBM surveyed 2,000 technology executives in June 2026 and found that two thirds of CIOs and CTOs are now accountable for AI systems they don’t fully control.1 That number sounds made up; I don’t think it is. It matches what I’m seeing inside scaling companies, where teams are switching on AI agents the way they switched on SaaS ten years ago, except agents spend money and take actions on your systems.

When a leadership team asks me where to start with AI, I don’t start with strategy. I start with three questions. What agents are running in the business? Who owns each one? What do they cost? It’s really common that nobody can answer all three; I’d go as far as saying it’s the normal state. The good news is that the answers are usually quicker to find than teams expect. Days, not months. Here is how I go about it.

Question one: what agents are running?

Nobody answers this from memory, and asking around the leadership table produces a list that is maybe half the real picture. You answer it from systems of record.

The identity provider is the richest seam. The enterprise application list in Entra or Okta, and more importantly the OAuth grants and service principals, show every tool people have connected to company data; this is where agents hide. Then the automation platforms. In most mid market companies, “agents” are flows someone built in Power Automate, Zapier or Make on a Tuesday afternoon; they count, because they touch real systems. Then the embedded layer: the AI features switched on inside Salesforce, Microsoft 365, HubSpot and the rest. Nobody thinks of these as agents, but they read and act on your data all the same. Network egress logs for traffic to the main AI endpoints round out the technical picture, and a device sweep of browser extensions catches the rest.

The last source is people, and the framing matters. I run a no blame survey of team leads; amnesty, in effect. You want disclosure, not concealment, and the fastest way to get concealment is to make the first discovered agent a disciplinary conversation.

What comes out is a register with four categories: sanctioned tools, embedded features, self built automations, and personal accounts doing company work. Every business I’ve looked at has entries in all four.

Question two: who owns each one?

Ownership sounds like one question; it’s three. Who pays for it? Who maintains it? Who answers when it misbehaves? In practice these are often three different people, and quite often three different nobodies.

The test I apply to every agent on the register is simple. Who has the authority to switch it off? Who reviews what it can access? Who gets told when it fails? If those questions have no names against them, ownership has defaulted upward to the CTO or CIO; that is exactly the accountability without control gap in IBM’s numbers, and it’s how two thirds of technology leaders ended up carrying risk they never signed up for.

This is not an AI problem. It’s an ownership problem, and it existed in your business before the first agent arrived; agents just made it faster and more expensive.

Question three: what do they cost?

Four layers, found in this order. Direct subscriptions sit in the vendor ledger; easy. API and token consumption sits in provider dashboards and cloud billing; slightly less easy, but it’s there. The third layer is the one that surprises people: personal AI subscriptions buried in expenses, findable with a keyword scan of card statements. The fourth is embedded AI add ons quietly inflating SaaS renewals, findable in the contracts.

Add the four layers together and the total is usually materially more than the budget line suggests. Whether that number is fine or alarming depends entirely on question two; spend with an owner is an investment, spend without one is a leak.

What you do with the answers

The output of this exercise is one page: an agent register with a name, a purpose, an owner, a data footprint and a cost against every entry. From there the decisions get much easier. Some agents deserve investment and a proper production path. Some need controls put around them. Some should be switched off, and nobody will miss them.

IBM’s study had one finding that got less attention than it deserved: organisations with embedded controls had 25% fewer incidents and ran sixteen times more agents than those governing manually.2 The companies in control appear to be the ones going fastest. Control isn’t what slows AI down; it’s what lets you scale it without the incidents.

If you want the answers for your own business, this is what my AI Reality to Production Review does; a structured look at what’s running, what it costs, and what deserves a production path. Details at theimpactcto.com, or message me on LinkedIn.

Read next Why Shadow AI Belongs on the Board Agenda