
A bank once told me a computer had declined my loan. I asked which computer I could appeal to. They had no answer, and that was twenty years ago.
The clerk wasn't being cruel. She was being honest in the only way the situation allowed. The decision had come out of a model in another building, and the model had no office hours and no opinion you could argue with. What she meant, underneath the words, was that no person in that branch would put their name next to the no. The machine had absorbed the accountability the way a sponge absorbs water, and now there was nothing left to wring out. I went home without the loan and without anyone to be angry at, which is a strange and specifically modern kind of defeat.
I think about that afternoon a lot now, because we are about to do the same thing at a scale and a speed that makes a loan officer's terminal look quaint. The software that turned me down twenty years ago could only score an application and return a number. The software we are deploying this year can read the application, email the applicant, open the case management system, file the rejection, and schedule the follow-up — all without a human touching it. We have stopped building tools that recommend and started building tools that act. And we are doing it before we have answered the question that afternoon at the bank should have taught us to ask first.
The company car
Most organizations already know how to let a fast, useful, slightly dangerous thing operate on their behalf. They've been doing it for a century. It's called a company car.
A company car is genuinely useful. It lets an employee cover ground no one could cover on foot, reach customers, get things done at a speed that would otherwise be impossible. It is also a two-ton object moving through a world full of other people, and everyone involved understands that. So we wrapped it in a small, boring, load-bearing ritual. Before the car leaves the lot, a named human is on the insurance. The keys are signed out. There is a person — not a department, not a policy, a person with a last name — who answers if the car ends up somewhere it shouldn't. The usefulness and the named driver are not in tension. The named driver is the price of being allowed to use the thing at all.
We did not require a named driver because we distrust cars. We required one because we understand that capability and accountability have to travel together, and a car is capability that can leave the building. The faster and more autonomous the machine, the more carefully we insisted on knowing whose name was on it.
An AI agent is a company car that can leave the building at the speed of an API call. It can act in a hundred places at once, at three in the morning, against systems that will obey it without asking whether anyone meant for this to happen. And we are, by and large, handing out the keys without anyone signing for them.
How the name disappears
The disappearance is rarely a decision. Nobody stands up in a meeting and proposes that no human be accountable for the agent's actions. It happens the way water finds the cracks — through the perfectly reasonable structure of how software gets built.
The model was trained by one company. It was fine-tuned by another. It was wrapped in a product by a third. It was configured by a platform team, deployed by an operations team, pointed at a workflow by a line manager, and the workflow was approved, months earlier, by someone who has since changed roles. By the time the agent does something nobody intended, the accountability has been divided into so many thin slices that no single slice is thick enough to answer for the whole. Everyone touched it. No one owns it. Each person, asked afterward, can say with total honesty that the part they touched worked exactly as designed.
This is the central, unglamorous fact about accountability, and it is worth stating plainly because the industry keeps acting as if it weren't true: accountability does not survive being distributed. It is not a fluid that you can pour into smaller and smaller containers and still have the same amount. It's more like a signature. A signature split among nine people is not nine small signatures. It is no signature. The document is unsigned, and the bank — to return to where we started — has no one to send you to.
The new tools accelerate exactly this. A protocol that lets a model reach into your files and your applications, a model that can operate a computer the way a person does — these are real and they are arriving in production now, and they are wonderful in the way the first company car was wonderful. They also mean the agent's reach now extends across systems that each had their own quiet assumption that a human was on the other end of the keyboard. The agent inherits all of that trust and none of the accountability that was supposed to come with it. It drives every car in the lot, and it is on no one's insurance.
Sign before, not after
The fix is not to slow down, and it is not to keep humans pecking at keyboards out of nostalgia. The fix is the same small ritual we already use for the car. Before an agent is allowed to act, name the human who answers for it. Not after something breaks. Before.
This sounds modest. In practice it changes everything about how you deploy, because it forces a set of questions to the front of the process where they belong. Who signs for this agent? What is it allowed to do, and — more revealingly — what is it not allowed to do without a person in the loop? At what blast radius does the named human have to be woken up? Where is the switch that stops it, and whose job is it to throw that switch? An organization that can answer those questions has a driver on the insurance. One that cannot has handed out the keys and looked away.
I run a company built on this premise, so I'll declare the bias rather than hide it. We architect agents so that ownership lands at the level of the individual employee — so the person whose work the agent does is the person whose name is on it. Not a central AI committee three floors up. The actual human whose judgment the agent is extending. That is not a compliance feature bolted on at the end. It is the load-bearing wall. An agent without a named owner is not an efficient agent. It is an unsigned decision waiting to be made, and someone, eventually, will be standing where I stood at that bank — being told a computer did it, with no computer to appeal to.
There is a tier to this, and the tier is just common sense. An agent that drafts a memo for a human to send needs a lighter touch than one that moves money or denies a claim. We don't put the intern who fetches coffee on the same policy as the regional sales fleet. But notice that even the coffee run has someone responsible for it. The graduated risk doesn't excuse the named owner; it calibrates how loudly that owner has to be paying attention. The most dangerous agents are not the ones we fear. They're the ones we've decided are too minor to bother signing for, quietly accumulating the authority to do real harm while everyone assumes someone else is watching.
What we actually owe each other
It is tempting to treat all of this as a legal problem — a matter of liability, of who gets sued. That framing is too small, and it lets the rest of us off the hook. The accountability I'm describing isn't primarily about courtrooms. It's about whether the people affected by an automated decision have anyone to talk to. It's about whether the organization itself can learn from its own mistakes, which it cannot do if no one owns them. A company that can't name who's responsible for an agent's action can't fix that action either. The unsigned decision is also the un-learnable-from one.
We are going to give these systems more authority, not less, over the coming years. The pull toward letting them run unattended will only grow, because attention is the most expensive thing any organization has and the agents are tireless and the savings are real. I am not against any of that. I'm against doing it the way the bank did it to me — building a wall of software thick enough that the human on the other side simply vanishes, and calling the vanishing progress.
So here is the whole argument in the size it actually is. The agent is the company car. It is fast and useful and worth having. Just don't let it off the lot until someone has signed for it. Decide whose name goes on the insurance before the keys change hands, not after the car is wrapped around a tree. The technology is ready to act on our behalf. The only question left is whether we are willing to be the ones it acts for — by name, in advance, in writing.
Twenty years ago I wanted a computer I could appeal to. I have since made my peace with the fact that I'll never get one. What I want now is simpler and entirely within our power to provide: not a machine that can be held accountable, but a person standing behind it who already is.