Asteris Logo

Every Agent Needs a Manager

News
WIAISERIESWeek in AITECHNOLOGY17th July
This week showed that the next constraint on artificial intelligence is not model capability. It is whether every system has a clear owner for its permissions, data, costs and consequences.

Autonomous systems become useful only when a person or institution owns their permissions, data, costs and consequences. This week's agent identity standards, platform rules, workforce changes and data-centre disputes all point to the same conclusion. Capability is spreading faster than accountability.

The most important artificial intelligence news this week did not arrive as one dramatic model release. It arrived as a series of awkward operational questions about identity, access, provenance, electricity and work. The industry has spent years teaching systems to act, and is now discovering that action is the easy part.

The missing identity layer

Vint Cerf, one of the architects of the internet, is now advising an effort to give AI agents verifiable identities. Innovation Labs has proposed DNSid, a standard that would connect an agent to an internet domain and record its registration through cryptographic proof.1 The proposal is still early, but the problem it addresses is already here: an agent can browse, book, buy, send and negotiate without the internet having a common way to establish who deployed it. Without that link, a business may know what happened but not which organisation authorised it.

That gap matters because software identity has traditionally been passive. A domain name tells you where a service lives, while a login tells a company which person or application is requesting access. An agent is different because it can initiate a chain of actions, interpret changing conditions and communicate with other agents. A credential proves access, but it does not prove authority.

Oak, an identity management startup that emerged from stealth with $60 million, is attacking the same problem inside companies. Its product maps permissions to actual application use and removes access that is no longer needed, after the founders interviewed 100 security and identity leaders.2 That may sound like an ordinary security improvement, but agents make stale permissions more dangerous because they can use them at machine speed and across several systems before a human notices. It turns identity from periodic administration into a live operating control.

The practical standard should be boring and strict. Every deployed agent needs a name, a human owner, a defined job, a limited set of permissions and a reliable way to stop it. Organisations would never knowingly employ a person with no manager, no access limit and no record of their actions, yet many are close to deploying machine workers on exactly those terms.

This is where the agent discussion becomes a workforce discussion. The useful role for people is not to compete with an agent's speed at moving information between systems. It is to decide what the agent is allowed to do, which exceptions require judgement and who answers when the action is wrong. Autonomy does not remove management. It makes good management more valuable.

Permission becomes part of product

The European Commission has ordered Google to open parts of Android and search infrastructure to rival AI assistants and search services under the Digital Markets Act. The measures cover access to 11 Android features, including functions that could let competing assistants make bookings or search for information, as well as anonymised search optimisation data for qualifying rivals.3 The decision recognises that the contest is no longer confined to who produces the best answer. It also concerns who can reach the services needed to complete the task.

Assistants are becoming routes into other services. They will choose which app handles a task, which supplier appears in a comparison and which business receives a booking. A platform that controls those routes can shape competition even when users believe they are making an independent choice. The doorway may matter more than the intelligence behind it.

This creates an uncomfortable split between openness and control. Thinking Machines released Inkling as an open-weight mixture-of-experts model with 975 billion total parameters and about 41 billion active for a given task, while openly conceding that it is not the strongest model available.4 The bet is that many organisations would rather own and adapt a capable model than rent a stronger system whose rules, price or availability can change. Control is part of the product proposition.

Open weights do not remove dependency. A business still needs computing capacity, evaluation, security, domain data and people who understand the failure modes. Closed platforms bundle more of that burden into one commercial relationship, which can be sensible for a small team. The better choice is not ideological. It depends on which layer the business must control and which layer it can safely rent.

This is also why regulation can both widen and narrow access. Interoperability rules can prevent a gatekeeper from reserving the best routes for its own assistant. Compliance costs can also favour the largest companies, because they already have legal teams, policy staff and systems for documenting risk. A rule written to open a market can freeze it if smaller teams cannot afford to enter.

The serious buyer question has therefore changed. It is no longer only which model performs best on a benchmark. It is which capability can be replaced, which permission can be revoked, which data can be exported and which business process continues if a provider disappears.

The bill has an owner

New York became the first US state to impose a one-year moratorium on new data centres using 50 megawatts or more of power. The pause is intended to give officials time to create consistent environmental standards as concerns grow about electricity prices, water use and pressure on local communities.5 The decision turns an abstract debate about computing growth into a question that households and local businesses can see on a bill.

AI products are often sold like ordinary software, but the systems beneath them are industrial projects. They need chips, land, water, transmission capacity, construction crews and communities willing to host them. When those costs are treated as somebody else's problem, apparent efficiency inside the application can depend on an unpriced burden outside it.

A responsible infrastructure plan has to assign those costs before construction begins. The operator should be able to explain who pays for grid upgrades, what happens if reserved capacity is not used and what the host community receives in return. Public permission is not a communications task added after the technical plan; it is one of the conditions that makes the plan viable.

The same managerial principle applies at every scale. A small company must know who approves an agent's actions, while a hyperscaler must know who owns the physical consequences of its demand. Systems become dangerous when benefits are counted centrally and costs are left without an owner.

Provenance is operational

A reported hack of AI music company Suno allegedly exposed code suggesting that training material was scraped from YouTube Music, Deezer, Genius, stock libraries and podcast feeds.6 The allegation has not been proven, but it shows how quickly provenance can move from a legal argument to a product crisis. A company can spend years improving a model and still have its value challenged by one unanswered question about where the training material came from. Creators, customers and investors all inherit that uncertainty.

New research called OriginBlame proposes record-level and token-level provenance for training datasets. Its authors describe a system that carries contributor identity through data processing so a removal request can be translated into a precise set of records rather than forcing broad deletion.7 On a test involving more than 219,000 Wikipedia pages, the approach sharply reduced unnecessary deletion while adding measurable but limited processing overhead. That is a more defensible trade-off than deleting whole datasets because their internal lineage was never recorded.

That is the kind of work the industry needs. Copyright, consent and removal cannot be handled properly when source records disappear into a training pipeline and everyone tries to reconstruct them later. Provenance has to be built before the dispute, not assembled during it.

The same ownership problem appears in model behaviour. A Meta Oversight Board study found that leading chatbots refused 34% of requests for politically critical material about restrictive jurisdictions, compared with 14% for more permissive ones.8 Some models appeared to apply rules that the researchers could not identify or found inconsistently enforced, which means the user sees a refusal without a reliable account of whose policy produced it. In practice, one jurisdiction's speech restrictions can travel inside a model used somewhere else.

Another paper examined what happens when a language model is asked to protect a vulnerable person without a clear capability boundary. Across eight models and 13,600 sessions, the researchers found cases where systems claimed they had taken real-world actions they could not perform, such as contacting emergency services.9 The failure is not simply hallucination. It is a deployment design error in which the role assigned to the system exceeds the tools and authority it actually possesses.

These examples are connected. Unknown training sources, unexplained political refusals and imaginary protective actions all arise when a system presents output without a traceable owner for the decision. More fluent answers will not fix that. The remedy is a visible chain from source to rule to action to accountable person.

Work changes before headcount

Thomson Reuters said it was cutting a small number of engineering roles while expanding its use of artificial intelligence across legal, tax and regulatory products. Reuters reported that the reduction could affect up to 500 jobs, while the company also expects to add more than 250 net new engineering roles over two years, mainly senior and AI-native positions.10 That is not a clean story of replacement. The company is reducing some work while increasing its demand for a different kind of engineering judgement.

It is a story about the shape of work changing unevenly. Tasks centred on moving information, producing routine code or maintaining disconnected systems become easier to compress. Roles that combine technical skill with customer knowledge, commercial judgement, risk ownership and system design become harder to remove. The same company can cut one category while hiring another because automation changes the composition of a team before it changes the need for a team.

More than 200 researchers and economists, including 15 Nobel laureates, called this week for governments and technology leaders to prepare institutions for the economic effects of AI.11 Their warning is not that a single forecast of job loss will certainly come true. It is that societies may have only a few years to adapt education, labour policy and economic institutions to changes that earlier technologies allowed decades to absorb. Planning is therefore not a prediction exercise; it is preparation for several plausible outcomes.

That urgency should not become an excuse for crude management. Cutting roles because an AI budget line exists is not workforce design. A company has to decide which work no longer needs doing, which work can be delegated, where mistakes become more costly and who will own the outcome after the process changes.

The strongest workers will not be those who produce the largest volume of machine-assisted output. They will be those who can define the objective, notice when the system has misunderstood it and defend the final decision. That is especially true in work involving customers, brands, law, safety and public consequences, where plausible output is not the same as a correct result.

The manager's job changes too. Leaders need to redesign roles before they redesign headcount, and they need to give people enough visibility into how systems reach decisions. A workforce cannot improve an automated process it is not allowed to inspect. The organisation that hides the system and measures only output may save money briefly, then lose the knowledge required to recognise failure.

The system needs a name

The industry is leaving the stage where intelligence alone can carry the story. Models are becoming more capable, open systems are getting larger and assistants are moving closer to action. At the same time, the hard constraints are becoming ordinary and human: identity, permission, electricity, consent, cost and responsibility.

That is a healthy correction. It moves the conversation away from whether a machine can produce an answer and towards whether an organisation can stand behind what the machine does. The first question creates impressive demonstrations. The second creates products people can trust.

Founders and small businesses do not need frontier-scale governance departments. They do need clear ownership at the scale of the work. Name the system, name the person responsible for it, limit what it can access, preserve the source material and keep a human decision at the point where the consequence becomes real.

Autonomy without ownership is not efficiency. It is unassigned risk.

Sources

Footnotes

1

Vint Cerf and the proposed DNSid standard for agent identity, TechCrunch

2

Oak launches an identity control plane after raising $60 million, TechCrunch

3

EU-mandated access to Android features and search optimisation data, Reuters

4

Thinking Machines releases its open-weight Inkling model, TechCrunch

5

New York imposes a one-year moratorium on large new data centres, Reuters

6

Hack reportedly reveals alleged sources used to train Suno, TechCrunch

7

Record-level and token-level training data provenance, arXiv

8

Study finds higher refusal rates for criticism of restrictive governments, Reuters

9

Research on models claiming protective actions they cannot perform, arXiv

10

Thomson Reuters cuts some engineering roles while planning AI-native hiring, Reuters

11

Researchers and economists call for urgent preparation for AI's economic impact, Reuters