TL;DR: AI agents now open pull requests, provision accounts and change production systems, but Newcore argues that responsibility breaks when actions run under shared service accounts without a traceable owner, delegation record or approval trail. Accountable autonomy depends on distinct identity, least privilege and human oversight at the point of high-consequence action.
Editorial analysis by NHI Mgmt Group, based on content published by Newcore: “Every Agent Action Needs an Owner: Building Accountability into AI Agents”.
Questions worth separating out
Q: What breaks when AI agents rely on shared service accounts or API keys?
A: Shared credentials hide which actor actually performed the action, make revocation coarse, and blur accountability across humans and machines.
Q: When should organisations require human approval for an AI agent action?
A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse.
Q: What are the warning signs that agent accountability is failing?
A: Approval rates near 100%, unclear ownership for sub-agent actions, and audit logs that cannot identify the delegator or approver all suggest the control is ceremonial.
Practitioner guidance
- Define a distinct identity for every agent Stop using shared service accounts as the default execution layer for AI agents.
- Record delegation for every task Maintain a durable link between the agent, the human owner and the task being performed, including sub-agent chains.
- Move approval to the tool boundary Require explicit approval in the API or orchestration layer for any action that changes production systems, permissions, customer data, external communication or money movement.
AI agents and accountability: what identity teams need to prove?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Accountability is the first identity control that breaks when agents move from suggestion to execution. A human can be named, supervised and recertified. An agent acting under shared credentials can diffuse responsibility across the model, the launcher and the system owner until no one is clearly accountable. The implication is that agent governance has to start with a distinct subject of record, not with policy language.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should fraud teams balance AI automation with human oversight in decision-making?
A: Fraud teams should use AI to handle high-volume pattern detection, anomaly scoring, and rapid triage, then keep humans in the loop for edge cases, novel fraud patterns, and high-impact actions. The practical goal is not full autonomy, but a hybrid operating model where models improve speed and coverage while analysts provide judgment, context, and continuous training feedback.
👉 Read our full editorial: Accountable AI agents need identity, delegation and human oversight