For thirty years, software did what it was told. You opened it, instructed it, and it produced an output you then acted on. The human was always the last step. Agentic AI breaks that pattern: it pursues a goal you set, makes intermediate decisions on its own, calls other tools, and takes actions in the world — booking, sending, ordering, replying — without stopping at each step to ask. The output is no longer a suggestion. It is a deed done.
This is a smaller technical leap than it sounds and a far larger management one. A spreadsheet that miscalculates wastes your afternoon; an agent that miscalculates can email the client, move the money, or reorder the stock before anyone looks. The question stops being “is the tool any good?” and becomes the question you ask of any new hire: what may it decide alone, what must it bring to me, and how will I know if it goes wrong?
The organisations that win the agentic era will not be the ones with the cleverest models. They will be the ones that learned to manage them.
When software starts taking actions, procurement becomes management. You are no longer buying a tool; you are supervising a worker that never sleeps and never explains itself.
What follows: the shift from tool to colleague, the oversight spectrum (in, on and out of the loop), why most agentic projects fail, how to manage an agent like a new hire, and five moves to do it well.
The day software stopped waiting for you
The shift is easy to miss because the interface looks the same. You still type a request into a box. But where a tool returns something for you to check, an agent goes off and does it — decomposing the goal into steps, choosing which systems to touch, retrying when it fails, and reporting back only when it is finished or stuck. It holds a kind of authority no spreadsheet ever did: the authority to act before you have looked.
That authority is what makes agents valuable and what makes them a governance problem. The same property that lets one absorb a week of drudgery in an afternoon lets it make a week of mistakes just as fast. And because it acts in the gaps between your glances, the failure mode is not a wrong answer on a screen you can ignore — it is an action already taken in the world, sometimes irreversibly. The agent does not wait for you. That is the point, and the peril.

The agent does not wait for you. That is the point, and the peril.
In the loop, on the loop, out of the loop
The central decision in managing an agent is not whether to trust it but how much rope to give it — and that is not one setting but a spectrum. In the loop: the agent proposes, a human approves each consequential action before it happens. On the loop: the agent acts, a human monitors a stream of its actions and can intervene or halt. Out of the loop: the agent runs autonomously, reviewed only after the fact, if at all.
None of these is right in general; each is right for a particular task. The discipline is to match autonomy to stakes — to put high-consequence, hard-to-reverse actions firmly in the loop, and reserve out-of-the-loop running for the cheap and the reversible. The failure that should worry a leader is not choosing the wrong posture deliberately. It is drifting into out-of-the-loop autonomy by neglect — granting an agent room to act simply because no one decided to take it away.
The model works; the management doesn’t
Gartner expects more than 40% of agentic AI projects to be scrapped by the end of 2027 — and the stated reasons are not that the models were too weak. They are escalating costs, unclear business value, and inadequate risk controls. In other words, the failures are managerial, not technical. Organisations are deploying autonomous workers with no job description, no probation, no performance review and no one clearly answerable for the result — and then are surprised when it goes wrong.
This should be oddly reassuring, because management is a thing we know how to do. We have centuries of practice at the questions agents now pose: how to delegate without abdicating, how to set boundaries, how to supervise at a distance, how to hold someone to account for an outcome. The mistake is to treat an agent as an IT deployment rather than as the hire it functionally is. The technology is new; the discipline it demands is not.

Onboard it like a new colleague
So treat the agent as you would a capable, fast, literal-minded new recruit who has read everything and understood nothing of your context. Give it a job description: the goals it owns, the actions it may take, the ones it must escalate. Put it on probation: run it in the loop, watching every action, until it has earned a longer leash. Review its performance: sample its decisions, not just its uptime. And name an accountable owner — a person, not a committee — who answers for what it does.
Above all, keep the one control that everything else depends on: the right to halt. A human must always be able to stop the agent, reverse what can be reversed, and fall back to a manual process — instantly, without a vendor ticket. An autonomy you cannot interrupt is not delegation; it is abdication. Build the off-switch before you build the workflow, and test that it works before you ever need it.
An autonomy you cannot interrupt is not delegation. It is abdication.
Five moves before you deploy an agent
Before an agent takes a single autonomous action in your name, these five should already be in place.
Write the job description
State the goals the agent owns, the actions it may take unaided, and the ones it must escalate. If you cannot write this down, the agent is not ready to start.
Set the autonomy by stakes
Place each action on the spectrum — in, on, or out of the loop — by how costly and how reversible it is. High-stakes and irreversible stays in the loop, full stop.
Build the off-switch first
Guarantee a human can halt the agent, reverse the reversible, and fall back to manual — instantly, without a vendor in the way. Test the kill-switch before you trust the workflow.
Name an accountable owner
One person, not a committee, answers for what the agent does. Accountability does not transfer to software, and “the system did it” has never been a defence.
Review the decisions, not the uptime
Sample what the agent actually decided and ask whether you’d stand behind it. Dashboards show that it ran; only inspection shows whether it ran well.
Do this and the agent becomes what it should be: a tireless colleague that absorbs the drudgery while a human keeps the judgement, the accountability, and the hand on the switch.
The technology is new. The discipline it demands — delegate, supervise, hold to account — is as old as management itself.
- Gartner (2025) — “Predicts”/press releases: 33% of enterprise software applications will include agentic AI by 2028 (up from <1% in 2024); at least 15% of day-to-day work decisions made autonomously by 2028 (up from 0%).
- Gartner (25 June 2025) — “Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,” citing escalating costs, unclear business value and inadequate risk controls.
- NIST — AI Risk Management Framework (AI RMF 1.0, 2023): govern, map, measure, manage; human oversight and the ability to intervene as core controls.
- Human-automation oversight literature — the “human-in-the-loop / on-the-loop / out-of-the-loop” framing of supervisory control over autonomous systems.
