AI agents need a management layer before they need more autonomy. Fortune reported on September 16 that Cisco, Intuit, Workday, and ServiceNow are all building ways to monitor, govern, and contain agents as they take on more work inside companies. That is the practical signal. The next phase of AI adoption is not just buying agents. It is deciding who manages them, what they are allowed to do, and how the business proves what happened after they act.
That sounds less exciting than autonomous work. It is also where adoption happens.
The companies moving fastest are not treating agents as magic employees. They are treating them as a new operating layer that needs visibility, permissions, records, and review. If your company skips that layer, you get agent sprawl.
The new problem is not whether agents can do work
The last year of agent coverage has been obsessed with capability. Can the agent write code? Can it search? Can it book meetings? Can it handle a customer issue? Can it use tools without a person clicking every button?
Those questions mattered when agents were demos. They are not enough when agents enter the business.
Fortune’s reporting is useful because it shows what serious companies are actually building around agents. Cisco launched an internal platform called MyAgent in August and gave roughly 90,000 employees access. The company says it reached 50% daily adoption within two weeks. Employees can create their own agents, but Cisco requires approval from a centralized team before those agents become authorized. Around 700 have been approved.
That is not a story about model capability. It is a story about operating control.
Cisco’s executive vice president of operations, Thimaya Subaiya, told Fortune the company wants to avoid “agent sprawl” and will not authorize third-party agents across random pockets of the organization. Whether you agree with that level of centralization or not, the management principle is right. Someone has to know which agents exist, what they touch, and whether they are still doing the job they were created to do.
Agents turn governance into daily operations
Most companies hear “AI governance” and picture a policy deck. Acceptable use. Legal review. Security language. Maybe a committee.
That will not survive contact with agents.
Agents act. They request information, call tools, draft messages, update records, hand work to people, and sometimes hand work to other systems. A policy can describe what should happen. It cannot show you what actually happened at 2:14 p.m. when an agent pulled customer data, summarized it, and sent a recommendation to a sales manager.
Intuit seems to understand this. Fortune reported that when Intuit designed its generative AI operating system, GenOS, the company also drew a security, risk, and fraud layer into the architecture from the beginning. Every AI request is tracked and every response is recorded. Intuit CTO Alex Balazs put it plainly: “You don’t want to try to retrofit the ability to enforce security and responsible AI foundations after the fact.”
That sentence should sit on every AI rollout plan.
Retrofitting oversight is how companies end up with tools people use but nobody owns. By the time leadership asks what the agents are doing, the workflows are already distributed across departments, vendors, accounts, and shadow experiments. Cleaning that up is harder than building the record layer first.
The agent system of record is coming
Workday’s phrase is the one business leaders should pay attention to: an “agent system of record.”
That is the shift. Agents are becoming a class of worker the business has to account for. Not human workers, but non-human identities performing work inside the organization. If they have access, tasks, permissions, outputs, and consequences, they need records.
A useful agent system of record should answer basic questions. Which agents exist? Who owns each one? What systems can they access? What work are they allowed to perform? What did they do today? What requires human approval? What happens when they fail silently?
If your organization cannot answer those questions, it is not ready to scale agents. Scaling agent work without a record layer is just adding invisible labor to the business.
That invisible labor becomes a liability. PwC’s Joe Atkinson told Fortune that “the agent made me do it” will not be a moral or legal defense. He is right. Responsibility does not disappear because the action came through software. The business still owns the outcome.
The first step is boring, which is why it works
This is where leaders tend to overcomplicate the problem. They hear agent governance and assume they need a new platform, a task force, and a six-month architecture program.
Maybe eventually. Not first.
The first step is an inventory.
List every AI agent, assistant, automation, and workflow currently touching business work. Include the unofficial ones. Especially include the unofficial ones. For each one, capture the owner, use case, systems touched, data touched, approval requirements, failure mode, and whether the output is reviewed before it affects a customer, employee, vendor, or financial record.
That inventory will be uncomfortable. Good. The discomfort is the signal.
Fortune also cited new Collibra research showing that seven in ten data management, privacy, and AI decision-makers say poor or unaligned data foundations are the root cause when AI pilots hit roadblocks. In large organizations with $100 million or more in revenue, Fortune reported that 96% tie AI project failure to poor data foundations, and 64% say they need manual review before autonomous agent outputs go live.
That is the real work. Not more autonomy. Better foundations. Clearer ownership. Review paths. Records. Permissions. A way to see the work.
Agents are not a shortcut around management. They are a reason to get more precise about it.
The companies that win with agents will not be the ones that let software roam freely through the business. They will be the ones that make agent work visible enough to trust, boring enough to repeat, and accountable enough to scale.