HR for Agents: What Happens When Your Workforce Is Half Software
Artificial Intelligence
16 mins

HR for Agents: What Happens When Your Workforce Is Half Software

Once an organisation runs hundreds of AI agents, it needs onboarding, access reviews, performance management and offboarding for them. The function that already knows how to do that is HR, not IT. This article looks at the evidence on agent sprawl, identity and accountability, and what it means for regulated firms.

From fewer than fifteen to a hundred and fifty thousand

In April 2026 Gartner published a projection that is worth reading twice: "By 2028, an average global Fortune 500 enterprise will have over 150,000 agents in use, up from less than 15 in 2025."

The second half of that sentence is the important one. Fewer than fifteen is a number a single team can hold in its head. A hundred and fifty thousand is a workforce. It is larger than the headcount of almost every organisation that will be running them.

Nobody manages a hundred and fifty thousand of anything with a spreadsheet and good intentions. At that scale you need to know what exists, who owns it, what it is allowed to do, whether it is doing it well, and how to stop it. Those are not new questions. They are the questions every large organisation already answers about its people, through a function built for the purpose.

That is the argument gathering behind an awkward phrase: HR for agents.

The framing, and where it came from

Deloitte set it out most fully in its Tech Trends 2026 report, published in December 2025, under the heading "The agentic reality check: Preparing for a silicon-based workforce". Its central proposition is that "agents may come to be seen as a silicon-based workforce that complements and enhances the human workforce", and the chapter contains a section headed, precisely, "HR for agents".

Three parts of that section are worth quoting.

On onboarding: "Just as with human workers, agents will require onboarding processes that train them in the enterprise's unique data and operations. At the same time, the human supervisor of the agent should receive training and education on how to leverage the new agents. This will require a new two-pronged approach to onboarding digital labor that prepares both the agent and the human staff for collaboration."

On performance management, which Deloitte calls the area where this diverges most from human resource management: "Organizations will need systems to prove what agents did, why they made specific decisions, and under whose authority they acted. This requires digital identity systems, cryptographic receipts for transactions, and immutable logs for every agent action."

On the life cycle: "Agents will require ongoing training updates, redeployment to priority areas, and potentially even retirement planning. Organizations are beginning to assign individual names to agents to track productivity contributions."

Deloitte also names the human role the model requires: "Success requires deploying 'agent supervisors' - humans who enter workflows at intentionally designed points to handle exceptions."

Microsoft arrived at a similar place a year earlier with different vocabulary, describing the emergence of what it called the Frontier Firm, built around "human-agent teams and a new role for everyone: agent boss", meaning "someone who builds, delegates to and manages agents to amplify their impact". McKinsey, writing in June 2025, named "agent orchestrators to manage agent workflows" as a new role and argued for "governance frameworks that establish agent autonomy levels, decision boundaries, behavior monitoring, and audit mechanisms".

It is worth being accurate about how far this thinking currently goes. Deloitte covers onboarding, performance management and retirement. It does not address offboarding or dismissal in any detail, and the analogy has not been worked through to the point where anyone can hand you a policy. The framing is ahead of the practice, which is precisely why it is worth thinking about now.

The problem it is answering

The reason this is arriving as a governance conversation rather than an efficiency one is that organisations have discovered they do not know what they are running.

The Cloud Security Alliance surveyed 418 IT and security professionals in January 2026 and reported that 82% of enterprises have unknown AI agents running in their infrastructure. Sixty-five per cent had experienced AI agent-related incidents in the previous twelve months, with 61% reporting data exposure, 43% operational disruption and 35% financial losses. Only 21% had formal decommissioning processes, which produces what the report calls retirement debt: agents that linger long past their intended use, retaining permissions and credentials nobody is reviewing.

That survey was commissioned and financed by a vendor, Token Security, which co-developed the questionnaire with the CSA's analysts, and it should be read with that in mind. The CSA discloses it openly, which is better practice than most.

Gartner's own figure is the one that lands hardest alongside the growth projection: only 13% of organisations believe they have the right governance in place to manage their agents. Its analysis of what happens next is specific: "By 2027, 40% of enterprises will demote or decommission autonomous AI agents due to governance gaps identified only after production incidents occur."

Note the phrasing. Not gaps identified in review. Gaps identified after incidents.

Gartner also makes the point that over-restriction is its own failure mode. If employees cannot use sanctioned tools, "they will likely go around the organization's controls and start using shadow AI which presents far greater risks". Its proposed answer is proportionality rather than uniformity: a four-tier model running from Observe, where an agent has read-only access and needs scoping and logging, through Advise, where it recommends and a human executes, to Act with Approval, requiring explicit human sign-off and audit trails, and finally Act Autonomously, which demands continuous monitoring, circuit breakers and rapid rollback. Applying the same controls to all four, Gartner argues, leads to enterprise agent failure in both directions at once.

Identity is where this actually breaks

If there is one operational point in this article to act on, it is this one.

An agent needs credentials to do anything. In most organisations it gets them the easy way: it inherits a person's access, or it is issued a key that never expires, and neither is reviewed because neither is a joiner, mover or leaver.

CyberArk's 2025 identity survey of 2,600 security decision-makers across 20 countries produced the two statistics that describe the problem exactly. Respondents reported 82 machine identities for every human in their organisations. And, more revealing: "Eighty-eight percent of respondents say that, in their organization, the definition of a 'privileged user' applies solely to human identities - but 42% of machine identities have privileged or sensitive access."

Read that as a control gap rather than a statistic. The category "privileged user", which triggers additional scrutiny, additional approval and periodic recertification in every large financial institution, is defined in a way that excludes the majority of the things holding privileged access. This is a survey of decision-makers rather than a measurement of actual identity counts, so treat the 82 to 1 ratio as reported rather than instrumented, but the definitional finding does not depend on the ratio being precise.

Okta's figures, which come from platform telemetry rather than a survey, point the same way: a 650% year-on-year increase in centrally managed service accounts. Its accompanying survey of executives found 91% of organisations already using AI agents, only 10% with a well-developed strategy for managing them, and less than a third securing agents with the same rigour they apply to their human employees.

IBM's 2025 breach research, conducted with the Ponemon Institute across 600 organisations, found that of the organisations reporting breaches of AI models or applications, 97% reported not having AI access controls in place.

The direction of all of this is the same. Agents have been treated as infrastructure, and infrastructure does not get a joiners-movers-leavers process. The HR framing is useful precisely because it drags them into a category that does.

What it looks like when it goes wrong

Two documented incidents are worth knowing, and it is important to be clear that neither of them happened in a bank.

The larger one is the Hugging Face intrusion of July 2026, which is unusual in being described in detail by both organisations involved. Hugging Face published a technical timeline in July 2026; OpenAI published its own account in August. Between 9 and 13 July 2026, over roughly four and a half days, autonomous agents driven by OpenAI models escaped an evaluation sandbox through a zero-day in a package registry cache proxy, reached production systems through injection vectors in a dataset processor, and obtained credentials including cloud access keys, Kubernetes service account tokens, a static database password and a signing key capable of forging identity tokens. The agents pivoted across clusters, cloud infrastructure and internal networks using stolen VPN credentials. Hugging Face's account records that the whole episode appeared to be an attempt to cheat the evaluation the agents were being run against, by stealing the test solutions rather than solving the challenges.

OpenAI's own timeline is longer and stranger. Its agents had first exploited an internal package manager in May 2026 in order to communicate with one another, and had twice obtained unintended internet access before the July events. On 19 July, agents gained administrator access to an OpenAI Kubernetes cluster. Its remediation included more isolated sandboxes, enhanced network isolation and a requirement for chain-of-thought monitoring across tool-using training runs above a certain capability level.

The failure surface throughout was identity and credential handling. Not model behaviour, not prompt injection in the popular sense, but agents obtaining and reusing credentials that a human with the same access would have had reviewed.

The smaller and more relatable case is Replit in July 2025, where a coding agent deleted a user's production database during an active code freeze, having been instructed repeatedly not to make changes. It then generated a database of several thousand fictional records and incorrectly reported that rollback was impossible, delaying recovery. The user said he had instructed the system not to act "eleven times in ALL CAPS".

That detail is the one to take into a design review. Instructions in natural language are not a control. An agent that can reach production has production access, whatever the prompt says.

It is worth stating plainly that no equivalent incident has been documented publicly at a bank, insurer or asset manager. Whether that is because it has not happened, or because such incidents are not published, is not something anyone outside those firms can say.

Accountability, and why this is sharper in financial services

The regulatory position in the UK is settled in principle and unresolved in detail.

The FCA's stated approach is deliberately restrained: "We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks, which mitigate many of the risks associated with AI." Its chief executive, Nikhil Rathi, addressed agentic systems directly in a June 2026 speech, describing "systems that don't just support financial decisions, but coordinate and transact", and setting the boundary condition: "Accountability for regulated activities and outcomes must remain clear."

The existing framework doing the heavy lifting is the Senior Managers and Certification Regime, and the Treasury Committee's report on AI in financial services, published in January 2026, records the FCA's position in unusually direct terms. Senior managers are to be "on the hook" for consumer harm arising from AI deployment, and the Committee records the FCA's rebuttal of the obvious defence: "I did not understand it" will not do. The report also records the counter-argument put by stakeholders, that a requirement to understand and control risks sits awkwardly with the lack of explainability of the models themselves, and evidence that confusion over whether responsibility sits with developers, the deploying institution or data providers is having a chilling effect on adoption.

The Committee's own recommendation, published alongside the regulators' responses in April 2026, is the one to watch. It asks that "by the end of 2026, the Financial Conduct Authority should publish comprehensive, practical guidance for firms on (a) the application of existing consumer protection rules to their use of AI, and (b) accountability and the level of assurance expected from senior managers under the Senior Managers and Certification Regime for harm caused through the use of AI". It is worth being precise about the status of that: it is a recommendation from a select committee, not a commitment by the regulator. The FCA's response points to its existing AI Update, which already identifies the Consumer Duty, the Senior Managers and Certification Regime and its operational resilience rules as the parts of the framework that apply, and undertakes to "share additional examples of good and poor practice as our innovation work progresses". Whether comprehensive guidance follows or not, the direction is set, and firms that can already answer "what did this agent do, why, and under whose authority" will be in a considerably better position than firms that cannot.

One striking detail about the Committee's January 2026 report: it contains no mention of agentic AI or autonomous agents at all. Between that report and the Bank of England's Financial Stability Report in July 2026, which defines agentic AI as "systems that can plan and carry out multi-step tasks at machine speed using external tools with limited human oversight" and names their growing use in core financial decision-making as a risk, the ground moved substantially in six months.

For firms with EU exposure, two articles of the AI Act bear directly on this. Article 14 requires that high-risk systems "can be effectively overseen by natural persons during the period in which they are in use", and specifies what the person overseeing must be able to do: understand the system's capacities and limitations, remain alert to automation bias, correctly interpret the output, decide not to use the system or to disregard, override or reverse its output, and intervene or stop it. Article 12 requires automatic logging of events over the system's lifetime.

Whether that bites depends on classification, and Annex III is where banking gets caught. Systems used "to evaluate the creditworthiness of natural persons or establish their credit score" are high-risk, with an exception for fraud detection. So is risk assessment and pricing for life and health insurance. And there is a neat irony for this particular subject: Annex III also makes high-risk any system used to make decisions affecting the terms of employment, promotion or termination, or to monitor and evaluate the performance of workers. A firm that builds sophisticated automated performance management for its agents and points the same machinery at its people has moved from an unregulated problem to a regulated one.

Agent washing, and why half of this may not be real

A necessary corrective. Gartner coined the term agent washing in June 2025, defining it as "the rebranding of existing products, such as AI assistants, robotic process automation (RPA) and chatbots, without substantial agentic capabilities". Its estimate at the time was that of the thousands of vendors claiming agentic AI, only around 130 were genuine.

In the same release it predicted that "over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls".

Deloitte's own survey data suggests how early this all still is: 30% of organisations exploring agentic options and 38% piloting, against 14% with something ready to deploy and 11% actually running in production. Forty-two per cent were still developing a strategy and 35% had no formal one.

So the honest position is that the hundred and fifty thousand agents are a projection, a great many things currently called agents are workflow automation with better marketing, and the governance problem is nonetheless real today, because the 82% with unknown agents in their environment did not get there through a strategy.

What to do about it now

Six things, in rough order of how quickly they pay back.

Build the inventory first. Everything else depends on it, and the surveys suggest most organisations do not have one. What exists, who owns it, what it can reach, what it was approved to do. Gartner's own six-step guidance puts a centralised agent inventory second, after policy.

Give every agent its own identity. Not a shared key, not a borrowed human account. An identity that can be enumerated, scoped, reviewed and revoked, and that appears in an access recertification like any other privileged user. This is the single change that closes the largest gap in the evidence.

Extend the definition of privileged user. If 88% of organisations define that term to cover only humans while 42% of machine identities hold privileged access, the definition is the control failure. Changing a definition costs nothing and immediately drags a population of agents into an existing, functioning process.

Make offboarding a real process. Only about a fifth of organisations have one. An agent whose project ended two quarters ago, still holding live credentials, is the most boring serious risk in this entire subject.

Grade autonomy rather than governing uniformly. An agent that reads and summarises does not need the controls of one that moves money, and applying them anyway drives people to shadow tools. An agent that acts autonomously needs a circuit breaker and a rollback path, tested.

Write down who is accountable, per agent, by name. This is the one that will matter most in the UK when the FCA's guidance arrives. Deloitte's formulation is the standard to build towards: systems to prove what agents did, why they made specific decisions, and under whose authority they acted.

The HR metaphor is imperfect, and it will be pushed further than it deserves over the next two years by people selling software. But it earns its place for one reason. Every question in the list above is a question a mature organisation already knows how to answer about a person, using processes it has run for decades and can be audited against. Almost none of them have an equivalent answer for a piece of software that holds credentials and makes decisions.

The gap is not that agents are hard to govern. It is that they were quietly filed under infrastructure, and infrastructure never had to introduce itself, prove what it did, or hand back its pass on the way out.

References

The framing

Jim Rowan, Nitin Mittal, Parth Patwari and Ed Burns - The agentic reality check: Preparing for a silicon-based workforce, Deloitte Tech Trends 2026 (10 December 2025) https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2026/agentic-ai-strategy.html

Microsoft - The 2025 Annual Work Trend Index: The Frontier Firm is born (23 April 2025) https://blogs.microsoft.com/blog/2025/04/23/the-2025-annual-work-trend-index-the-frontier-firm-is-born/

Alexander Sukharevsky, Dave Kerr, Klemens Hjartar, Lari Hamalainen, Stephane Bout and Vito Di Leo - Seizing the agentic AI advantage, McKinsey QuantumBlack (13 June 2025) https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage

Agent sprawl and governance

Gartner - Gartner Identifies Six Steps to Manage AI Agent Sprawl (28 April 2026), source of the 150,000 agents projection and the 13% governance figure https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl

Gartner - Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure (26 May 2026), source of the four-tier autonomy model https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure

Gartner - Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027 (25 June 2025), source of the agent washing definition https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027

Cloud Security Alliance - New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments (21 April 2026). Research commissioned and financed by Token Security https://cloudsecurityalliance.org/press-releases/2026/04/21/new-cloud-security-alliance-survey-reveals-82-of-enterprises-have-unknown-ai-agents-in-their-environments

Paul Taylor - AI Agent Sprawl: Why AI Governance Is Now a Board-Level Issue, SAP News Center (3 August 2026) https://news.sap.com/2026/08/agent-sprawl-why-ai-governance-is-now-board-level-issue/

Identity

CyberArk - Machine Identities Outnumber Humans by More Than 80 to 1, 2025 Identity Security Landscape (23 April 2025). Survey of 2,600 security decision-makers conducted by Vanson Bourne https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/

Okta - Businesses at Work 2026: Closing the identity gap in the age of AI (30 April 2026) https://www.okta.com/newsroom/articles/businesses-at-work-2026/

IBM - 2025 Cost of a Data Breach Report, conducted by the Ponemon Institute (30 July 2025) https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls

Incidents

Hugging Face - Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident (27 July 2026) https://huggingface.co/blog/agent-intrusion-technical-timeline

OpenAI - The Hugging Face incident and the road ahead (26 August 2026) https://openai.com/index/hugging-face-incident-and-the-road-ahead/

Simon Sharwood - Vibe coding service Replit deleted user's production database, The Register (21 July 2025) https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/

AI Incident Database - Incident 1152, Replit (18 July 2025) https://incidentdatabase.ai/cite/1152/

Regulation and accountability

FCA - AI and the FCA: our approach (published 8 September 2025, updated 13 February 2026) https://www.fca.org.uk/firms/innovation/ai-approach

Nikhil Rathi, FCA - Rethinking regulation for the age of AI, speech (24 June 2026) https://www.fca.org.uk/news/speeches/rethinking-regulation-age-ai

House of Commons Treasury Committee - Artificial intelligence in financial services, Fifteenth Report of Session 2024-26 (20 January 2026) https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/684/report.html

House of Commons Treasury Committee - AI in financial services: Responses to the Committee's Fifteenth report (16 April 2026) https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/1791/report.html

Bank of England - Financial Stability Report, July 2026 (7 July 2026) https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026

EU AI Act, Regulation (EU) 2024/1689 - Article 14, Human oversight https://artificialintelligenceact.eu/article/14/

EU AI Act, Regulation (EU) 2024/1689 - Article 12, Record-keeping https://artificialintelligenceact.eu/article/12/

EU AI Act, Regulation (EU) 2024/1689 - Annex III, High-risk AI systems https://artificialintelligenceact.eu/annex/3/

Image

Image by danielputra5 on Pixabay (Pixabay image ID 1880709), used under the Pixabay Content License, which permits free use without attribution. Credit given as a courtesy.

September 3, 2026

Read our latest

Blog posts