Your AI agents now have an owner. The documents they cite still don't
Glean enforces a single owner per agent, Gartner makes ownership a requirement. The documents those agents cite still have no named accountable owner.
If your group is building an agent registry right now, every agent in it is getting a named owner, a record of who created it and, more and more often, a review of changes before they go live. This is the only moment when adding a column costs one line. Once the registry has been declared complete and presented to a steering committee, going back to ask a new question takes a campaign. The missing question is simple: for the documents each agent cites when it answers, who would sign off the correction? An agent built in a few weeks is being granted what the procedure that commits the group has never been granted in years.
This piece is for the CDO, CTO or head of knowledge management at a large enterprise whose agents already read internal documentation: procedures, technical notes, terms and conditions, quality standards. If your agents still read only a handful of hand-picked, recent sources in a closed pilot, the argument will bite at the first scope extension.
The person this text makes uncomfortable sits somewhere other than the reader’s chair. It is the business process owner whose procedure an agent in production cites most, say the head of indirect procurement. The scene happens at a registry review. The owner of the “Procurement assistant” agent is named in two seconds: it is the person who built it, and the tool displays the name. Then someone asks who is accountable for the off-catalogue purchase approval procedure, the one the agent cites whenever it is asked about an urgent purchase. Three names go round the table: the author, who has since left, the department that approved it, the intranet team that published it. The head of indirect procurement says nothing. They know everyone is about to turn to them, and they have never reread the version that is online.
The move this article proposes lives in that registry: one more column, which we call the accountable-owner column, in which every document an agent cites is given the role that would sign off its correction. It is described below, with its reading rule.
Two answers come up before the end of the page. The first: “our AI governance platform covers this.” It holds the registry, the non-human identities, the access rights, and it is precisely what gave each agent an owner. The second: “our documents already have an owner, there is a field for it in our document management system, and the quality process approves every procedure.” Both are accurate within their scope. The registry governs the object that acts, the document management system records the object that is stored, and the question asked at the review falls between the two. The agent’s owner has neither the mandate nor the expertise to decide between two versions of an internal standard. As for the “owner” field in your document management system, check what it actually holds: depending on configuration, it may name the person who uploaded the file rather than the person accountable for it.
We have covered the auditability of an agent’s decisions — what the log records and what it leaves out — and then which document prevails when two of them disagree. This piece has a narrower, more practical focus: the tooling gap between two objects the enterprise now governs side by side, the agent and the document, and the registry where that gap can be closed.
What agent governance actually delivered in 2026
This governance deserves to be described at its best, because it is real and moving fast. On 8 September 2026, Glean, a vendor of enterprise search and agents, made a single owner per agent mandatory. Multiple owners can no longer be added, agents that had several were migrated automatically after a two-week grace period, and the original creator is kept as audit metadata in every case. The same release shows, before an agent is published, the exact list of changes about to go live. On 26 May 2026, Gartner placed clear ownership of an agent’s behaviour among the governance requirements for the most autonomous agents, and predicted that by 2027, 40% of enterprises would demote or decommission autonomous AI agents because of governance gaps identified only after production incidents.
Three primitives, then: a single owner, a record of the author, a check before publication. They apply to the agent, and to the agent only. The single owner covers the agent, not the sources it reads. The same release notes give an unintended illustration: for files stored on Azure Files, when identity metadata is available, the search “author” and “owner” facets are derived from the file’s ownership in the storage system. The tool then knows who saved the document. It holds no information on who is accountable for it.
What transfers to a large non-tech enterprise is the phenomenon; the product stays with its vendor. Whatever platform your IT department chooses, governance arrives with the agent, because the agent is a new object, deployed by an identified team, in a tool that can enforce rules from the moment it is created. The document is an old object, produced by dozens of departments in tools that never had to answer for what an AI would do with it. The same asymmetry is very likely to show up in your organisation, whatever the vehicle: the assistant in your office suite, an agent platform, or an in-house build.
Gartner had already sketched the pattern in a public press release on 28 April 2026, setting out six steps to manage agent sprawl. Identity, permissions and life cycle appear for the agent. For information, the dedicated step asks organisations to keep it current, manage its permissions and archive it when obsolete. The press release names no one accountable for it; we have not read the full client-only research note.
An agent is only as reliable as the sentence it cites
In front of an internal auditor, a regulator’s inspector or an unhappy customer, the audit trail stops at the agent’s boundary. We know who built it, who changed it, when the latest version went live. We do not know who is accountable for the sentence the agent cited, or whether that sentence was still correct on the day it was served.
A perfectly governed agent that cites a procedure with no accountable owner produces an answer no one is accountable for. Its owner can withdraw the answer, rephrase it, narrow the agent’s scope. They cannot correct the procedure. And the person who can, the process owner, has no reason to know that their document feeds three agents, because they are recorded nowhere as the person accountable for it.
The alternative most often heard is that governing the agents is enough: a complete registry, non-human identities, least-privilege access, and the risk would be under control. This is exactly the boundary where the head of indirect procurement reappears. The registry can say that the Procurement assistant cited the off-catalogue approval procedure, and even when. It cannot ask them anything, because it does not know they exist.
The answer requires no new job. A document’s accountable owner is a written assignment added to a role that already exists: process owner, domain lead, quality manager. What is missing is a place to write it down and a moment when the question gets asked.
What real field work showed, and what it does not establish
The CDO of a CAC 40 industrial group summed up the first diagnostic K-AI ran on one of its bases as follows: “We discovered 32% of our base was divergent duplicates. K-AI surfaced them in two weeks, we resolved in six.” The quote is published on K-AI’s customers page, with its author’s initials only.
Two clocks appear in that sentence. Detection takes two weeks and belongs to the tool. Resolution takes six weeks and belongs to the enterprise: “we resolved”. The quote does not say what filled those weeks, how the people asked to decide were designated, or whether an agent was reading that base. It therefore establishes nothing about document ownership itself. It establishes that detection and resolution run on two separate clocks, and that the second one is kept by the customer’s teams. Our reading, argued and not demonstrated by this case, is that a divergent duplicate is the document object with the most implicit owners, and that the question “who do we send this to?” is part of what those weeks absorb.
The accountable-owner column
The move fits into a single column added to a document that already exists in your organisation, or is being created: the agent registry.
What it produces. For each agent in production, three lines: the three documents it cites most, and for each, the role that would sign off its correction. This is the only coined term in this article.
Its home. The agent registry itself, held by the team that runs AI governance. No side file, no spreadsheet attachment: the column lives where the agent already has its owner, and follows the same review cycle.
When its first lines get written. When an agent is entered in the registry or its ownership is transferred, in calm conditions. Never the day after a disputed answer, which is precisely when nobody wants to sign anything.
A filled-in line. Agent: Procurement assistant. Agent owner: procurement tools lead. Cited document: off-catalogue purchase approval procedure. Accountable owner: indirect procurement process owner. Last correction signed by that owner: no record.
To find the most-cited documents, two sources depending on your tooling: the citations kept by the assistant, if your configuration keeps them, or three regular users of the agent, asked which documents come back most often in its answers. The exercise assumes neither in particular.
Its reading rule. If the accountable-owner cell holds a named role that would agree to sign, the agent is governed down to its sources on those three documents. If it holds a team name, the agent owner’s name, or stays empty, the agent is governed on a source no one is accountable for. Two outcomes. When most of an agent’s lines are named, it stays in production and the column follows its ordinary review. When most are empty or point back to the agent itself, any extension of its scope waits until a written assignment has been made.
Its failure mode. If every line fills in easily, you will have spent one review meeting confirming that your governance holds, which is useful evidence. If the lines fill up with team names, the column will simply have moved the silence of the review into a table. That is why the reading rule rejects teams: an accountable owner is a role that signs.
The record it creates. Writing a name in this column creates a document stating, on a given date, who was meant to be accountable for a procedure cited by the AI. If the decision turns out to be wrong, the record at least shows that the question had been asked, and of whom. That is better than a registry proving only that no one had asked it. The legal weight of such a record depends on your context and deserves your legal department’s view before it becomes a group rule.
What the DKP category adds, and where it stops
A Document Knowledge Platform (DKP) is the document quality and governance layer that runs upstream of AI systems: it governs the document estate (Govern), detects and handles anomalies, duplicates, obsolescence and contradictions (Clean), and only activates the corpus for agents once those two steps hold (Activate). Against the three primitives delivered for the agent, it gives the document their operational counterparts: every detected case routed to the accountable owner who must decide, the author of every version kept, contradictions checked before a version feeds the AI. It does not appoint the accountable owner; it makes the gap visible and routes the work to whoever fills it.
It replaces neither the agent registry, nor the AI governance platform, nor the document management system, nor enterprise search. It runs before them, on the estate they consume, and its governance is continuous: a corpus that is clean on activation day starts degrading with the first note published without review. This position does not depend on a vendor’s latest release notes or on the next analyst report. The document layer comes before the engine, whatever tool governs the agent this quarter.
The split of responsibilities is worth writing down. K-AI is accountable for counting anomalies, for making the count reproducible and for routing each case to the relevant expert with a prepared diagnosis. The decision on which document prevails stays with the business: the accountable owner decides. Technically, the analysis plugs into existing sources with no migration, covers only the designated document content, excluding transcripts, usage logs and telemetry, within a contractual ingestion scope, and no data is reused to train models.
And if you do nothing
The status quo has a predictable outcome. The agent registry will be complete, and will stay that way, with an owner column filled in at one hundred percent. The first disputed answer will go up to the agent’s owner, who will withdraw it or restrict the agent, unable to correct the source. The procedure will stay online, cited by the other agents that read it. The accountable-owner question will be asked at that point, under pressure, by someone looking first for whoever is to blame for the incident.
The work proposed here rests on a budget line that already exists if you deploy agents: the agent governance programme and its registry review. The trade-off is a scheduling dependency: if that programme slips, the column slips with it. Hence the value of starting with the three most-used agents, without waiting for the registry to be complete.
Conclusion: audit, clean, monitor
The sequence stays the same. Audit: add the accountable-owner column to the registry and read what it reveals, agent by agent. Clean: for documents with no accountable owner, or in contradiction with another source, obtain the written assignment, then the signed correction. Monitor: keep the column alive at the registry’s pace, so that every new agent arrives with its sources and their accountable owners.
At the next registry review, the head of indirect procurement will be no more comfortable than they are today. They will at least know why people turn to them, and what they are being asked to sign.
Frequently Asked Questions
Our AI governance platform already gives every agent an owner. What is missing?
The agent’s owner is accountable for the agent: its configuration, rights and scope. That owner is not accountable for the documents the agent cites, and usually has neither the mandate nor the expertise to decide between two versions of a procedure. What is missing is an accountable owner per cited document, recorded in the same place as the agent’s owner.
Isn’t the “owner” field in our document management system enough?
Depending on configuration, that field may name the person who uploaded or created the file, sometimes derived automatically from the storage system. It then says who saved the document, not who would sign off its correction. The two may coincide, and the accountable-owner column is precisely how you check.
Do we need to create a new “AI document owner” role?
No. A document’s accountable owner is a written assignment added to an existing role: process owner, domain lead, quality manager. What is usually missing is a place to write it down, and the agent registry offers one that is already reviewed.
How do we find out which documents our agents cite most?
If your assistant keeps the citations behind its answers, they give a direct answer. Otherwise, three regular users of an agent usually know which documents keep coming back. The exercise starts with the three most-used agents and the three most-cited documents for each.
What confidentiality framework applies to a review of our document estate?
The ingestion scope is contractual and limited to the designated document content, excluding transcripts, usage logs and telemetry. No data is reused to train models. The scope is approved jointly by the business Document Owner and the CISO or DPO, never by IT alone.
Sources
- Glean — Release notes, September 08, 2026 — single owner per agent, migration after a two-week grace period, creator kept as audit metadata, change view before publishing; author and owner facets derived from resolved NTFS file ownership for the Azure Files connector, when user identity metadata is available.
- Gartner — Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure, 26 May 2026 — public press release: governance proportional to autonomy level; clear ownership of agent behaviour sits among the requirements for the most autonomous levels, alongside the prediction that 40% of enterprises will demote or decommission autonomous agents by 2027.
- Gartner — Gartner Identifies Six Steps to Manage AI Agent Sprawl, 28 April 2026 — public press release: six steps, including agent identity and life cycle and AI information governance.
- K-AI — customers page — quote from the CDO of a CAC 40 industrial group and the method of routing each case to the right expert.
Where to Go From Here
K-AI Corpus Diagnostic — 10 business days on your document estate, full report of the 20 most critical anomalies, money-back guarantee if no meaningful anomaly is found. A one-hour conversation is enough to fill in the first lines of the accountable-owner column for your most-used agents: which documents they actually cite, which of them contradict each other, and which role each case should go to. Reach the K-AI team: contact@k-ai.ai. The scope of every diagnostic is validated jointly by the business Document Owner and the CISO/DPO, never by IT alone.
K-AI already works with CMA CGM, Veolia, PwC, BNP Paribas, TotalEnergies and CEVA Logistics. Partners: AWS, Snowflake, Microsoft, Wavestone, Devoteam.
