Handing a task to an AI agent is handing over a set of keys. Right now, most organizations are cutting keys faster than they are deciding which doors those keys should open.

The numbers say so. Deloitte surveyed 3,235 leaders and found that 74% plan to deploy AI agents, and only 21% have mature governance for them. That is not two data points. It is one gap. Deployment intent is sprinting; governance maturity is strolling. And that gap, between what organizations intend to deploy and what they are prepared to govern, is exactly where the runaway-cost incidents live. The $47,000 kind.

That’s the observation. Here is the inference I draw from it: most agent incidents are not model failures. They are delegation failures. Nobody decided, in advance and in writing, how much of the task the machine was allowed to own. The agent didn’t overstep a line. There was no line.

So draw one. Before any task goes to an agent, it gets exactly one of three answers. I call this the delegation decision.

The three answers

1. Fully delegated. The agent acts; humans audit after the fact. This is the right answer when the worst-case error is small, reversible, and bounded. where a mistake costs you an apology, not a headline.

2. Human-in-the-loop. The agent does the work; a person approves before anything executes. This is for the consequential middle: tasks worth automating, with mistakes worth catching first.

3. Never automated. Some calls stay human. Irreversible commitments, regulated judgments, anything where accountability itself is the point. Not “automate later.” Never.

Same agent. Same model. Three different leashes, sized to the task, not the technology.

Why a three-way call beats a policy document

Because it forces the decision to happen before deployment instead of after the incident. Deployment is a technology decision; delegation is a governance decision, and it has to be made one task at a time. This is the judgment layer (opens in a new tab) doing its actual job: deciding not just what the machine can do, but what it may do.

My recommendation is blunt: no task ships to an agent without one of the three labels attached.

What to take into the room: pull up your agent roadmap and force every line item through the three answers. Two warning signs. A task nobody can classify is a task that isn’t ready to deploy. And a list where everything comes back “fully delegated” means nobody actually made the decision. You just found your own version of the 74/21 gap, and it’s sitting in your roadmap waiting to become an invoice.