In 1983 a cognitive psychologist named Lisanne Bainbridge published five pages in a control engineering journal about the person left standing in an automated plant. Her argument was that the designer automates whatever he knows how to automate and hands the operator the leftovers, which is to say the situations nobody could write a rule for. The operator's job becomes watching a process that mostly runs itself, so he stops doing the manual work that kept his judgment calibrated, and the rare emergency he is employed for finds him less capable of handling it than he was the year before the system arrived. Bainbridge's conclusion was that automation raises the training requirement instead of lowering it.2
The cheapest control on the shelf
Forty-three years later, KPMG put a version of the same question to 204 American executives at companies above a billion dollars in revenue. What is your top approach to managing the risk of AI agents over the next six to twelve months? For the second quarter running, the leading answer was a human-in-the-loop model in which a person validates outputs but does not oversee each agentic action or decision, chosen by 52 percent.1 KPMG sells advisory work on precisely this problem, which is worth knowing when you read their numbers, and the number still describes something I recognize from client after client.
Validating an output without seeing the actions that produced it is reading the last line of a proof. You can judge whether the answer looks plausible against what you already expected, which catches the errors you were primed to catch. Anything the agent got wrong in a way you would never have thought to look for goes through untouched, because the only evidence in front of you is the part that survived.
Nobody costed the second job
Underneath that survey answer sits an arithmetic problem. An organization deploys an agent because it absorbs work people currently do, and those hours go into a business case with a number attached to them. The reviewing never goes into the business case. Somebody now has to open the agent's output and form a real view about whether it is right, then carry the consequence of having waved it through, and that somebody almost always had a full week before the agent showed up.
The tell sits two pages away in the same survey. Forty-three percent of these leaders named human oversight skills, the judgment to know when to escalate, as one of the biggest obstacles to deploying agents at all.1 They have correctly identified the shortage, and they have selected the risk control that rests entirely on it.
The workforce appears to have noticed first. Resistance to AI agents among employees rose to roughly one in five in a single quarter, up from one in twenty.1
An approval step nobody has time to perform does not reduce risk. It relocates the risk onto whichever name ends up at the bottom of the record.
Where the accountability actually sits
Ask who owns the outcome of an AI-informed decision and the answers scatter across the org chart. About a third of these organizations point to a named C-suite executive, a similar share point to the CEO or the executive committee, and smaller groups name a business unit leader or a centralized governance committee.1 Not one of those people is the person clicking approve at four in the afternoon. A few weeks ago I wrote about accountability as responsibility plus the authority to act on it, and the shape here is familiar. Responsibility for the agent's behavior lands on whoever validated the output. Authority to slow the rollout, fund the review, or refuse the deployment lives several floors above them.
Then there is the question of what would trigger a refusal at all. A third of these organizations say plainly that overrides happen case by case, with no formal criteria at all.1 In the review meetings I have sat through over the years, first as a delivery manager and later as a coach watching other people's gates, that has been the common answer too: a feeling rather than a written threshold, which means the override technically exists and nobody can predict when it fires.
What a real loop costs
The most useful framing I have heard on this came out of a session I attended earlier this year. Sort the work by what a wrong answer costs you. Where a bad output is cheap and visible, start there and let the agent run, sampling the results afterward. Where errors would be catastrophic, go slower. What I would add to that, out of the delivery side of my career, is what going slower has to consist of. Put in writing what sends a decision back. Give the reviewer the agent's reasoning rather than only its conclusion, and enough room on the calendar to form an opinion worth having. The reviewer's time belongs in the budget next to the license fee.
I am not arguing against agents, and I am not going to relitigate the piece I wrote about governance moving slower than the tools people had already adopted. The sanctioned deployments simply have their own version of the problem. Adoption arrived with a policy, the policy named a reviewer, and nobody asked the reviewer what the job would actually take. Bainbridge saw the whole thing coming in a journal most executives will never open.
So here is what I would ask anyone running an agent in production this quarter. If you walked over to the person named as the human in your loop and asked how many minutes they spend on each decision, and what would make them send one back, would you get a number and a rule, or would you get a shrug? And if it is the shrug, whose name is on the outcome?
If the idea of a control that exists on paper and not in practice landed with you, that tension runs through the whole first chapter of Agile Sucks! (When You Do It Wrong). James and I open the book with organizations whose measurements looked healthy while nothing of value reached a customer, and we go into what was actually happening underneath, what should have happened instead, and why so many capable leaders missed it. If you want the longer version of the argument, the link is just below.
Read Agile Sucks! (When You Do It Wrong) →References
- KPMG LLP. (2026, June). AI quarterly pulse survey: Q2 2026. Survey of 204 U.S.-based C-suite and business leaders at organizations with annual revenue of $1 billion or more, fielded April 28 to May 25, 2026. KPMG sells AI advisory services related to the issues measured. https://kpmg.com/kpmg-us/content/dam/kpmg/corporate-communications/pdf/2026/AIPulseSurvey_Q2_FINAL.pdf ↩
- Bainbridge, L. (1983). Ironies of automation. Automatica, 19(6), 775-779. https://www.sciencedirect.com/science/article/abs/pii/0005109883900468 ↩