PROTOCOL VISION

Research findings · October 2026 · public sources

Who owns the rules when agents join the business?

AI agents now spend, answer and approve under rules someone has to change. We read 118,526 job postings, 1,167 company filings, 771 statements from 30 practitioners we recorded, 19 laws and policies, and the documentation of 31 agent products and protocols. They show where agent rules are edited. They are still thin on who owns those rules.

771 practitioner statements, one dot each other workrunning agentssetting limitsfinding an unwritten rule (1)
20of the 30 practitioners we recorded describe running agents themselves
15of 26 agent products document an admin role that edits an agent’s rules
1of 771 practitioner statements describes finding an unwritten rule. None describes deciding a change across functions.

The short version

So far the evidence shows where agent rules are edited, points to who runs agents, and gives an early sign of who owns their rules

Public sources show that products put agent rule edits in admin settings. They point to existing staff, mostly technical, running agents. On who owns an agent’s rules the evidence is still thin: an early sign is that firms own them as standards set up front, not as approvals of each change.

By an agent’s rules we mean its instructions, tools and limits: what it may do, spend or say, and when it must hand over to a person. One vocabulary marks how sure we are: High, the evidence shows; Medium, it points to; Low, an early sign.

RUNNINGThe range around 86 (63–115) includes parity, and practitioner speech is a small, self-selected sample coded by one model per speaker.

The evidence points to existing staff, not new hires, running most agents

In job ads that means technical staff more than business teams: 86 ordinary ads list agent work for every 100 AI-titled ones (range 63–115), and about half of those are technical jobs. In speech, 20 of 30 practitioners describe running agents, and 6 of 10 who discuss staffing gave the work to existing staff.

CHANGINGHigh on what the documentation says. 15 of 26 products name the role that edits limits, short of the two-thirds we set in advance, and none contradicts the pattern.

Products show agent rule edits happen in admin settings

In Claude, ChatGPT, Codex, Copilot, Agentforce and most others, an admin edits an agent’s limits in the product, under central policy. This is what products allow, not what firms do.

STANDARDSExploratory re-code of 35 decision duties. The split is fragile: it rests mostly on IT change, and agent duties come mostly from AI-titled senior roles.

An early sign: agent controls are being owned as standards, not as change approvals

About a quarter of agent rule duties in job ads carry decision rights, more than credit, pricing or IT change. All nine set standards and frameworks up front; none approves individual changes, which is common in IT change and pricing (11 of 26 decision duties elsewhere). This may partly reflect that agent work sits with architects.

Sources118,526 job postings from 218 employers1,167 company filings771 statements from 30 practitioners111 provisions in 19 laws and policies31 agent products and protocolsHow we know

Chapter 1 · The work

High that finding unwritten rules and deciding changes are nearly absent from public sources: when we planted examples, the coders found nearly all of them. How much people talk about running agents is less certain: speech extraction catches about half of what is said.

Public sources show finding unwritten rules and deciding rule changes barely appear; running agents is what people talk about

771 statements · 30 practitioners

771 things people said about working with agents

We transcribed recorded talks and podcasts by 30 practitioners who run functions with AI agentsWe collected 38 recordings. 30 have timestamps, so every statement can be checked against the audio. All counts here use those 30 practitioners. and split them into single statements about their work.

Most of it is about something else

Two AI models from different vendors sorted each statement independentlyEach model coded every statement on its own. A third pass settled disagreements. Before coding, both had to find planted test examples. Prompts and codes are on GitHub.. 600 describe other work: strategy, adoption, results.

149 describe running agents

Supervising, tuning and training agents is the work people talk about. Counted by speaker, 20 of the 30 practitioners describe itA few speakers talk at length: three sales managers account for 89 of these statements. So we compare speakers, not statement counts..

she spends 20% of her time managing the agents, orchestrating the agents.Sales leader, podcast, 2026

21 describe setting what agents may do

Limits, guardrails and hand-off rules. In job postings, setting limits is about a quarter of agent-related duties.

One describes finding an unwritten rule. None describes deciding a change across functions

It is not a blind spot in our method: when we planted examples, the coders found nearly all of themThe coders caught 94–100% of hidden test examples of this work.. The work is simply absent from the public record. The clearest paid example is one engineering duty at Amgen.

Map rules, exceptions, data dependencies and human decision points before selecting deterministic automation, classical ML, deep learning, GenAI, RAG, agents or a manual approach.Amgen · Sr Machine Learning Engineer posting · 2026

Chapter 2 · The tools

High on what the documentation says. It shows what products allow, not what firms do. Four products’ documentation could not be retrieved.

Product documentation shows agent rules are edited in admin settings; it shows what products allow, not how firms approve a change

    We read 31 products’ documentation to see where rule changes happen

    We read the public documentation of 31 agent products, governance platforms and protocols, as published on 10 October 2026, and coded where an agent’s limits live and who may change them.

    Coding assistants put it plainly: an admin edits what the agent may do

    Seven of eight assistants and coding agents document an owner or admin role that sets agent limits. Organisation settings override the user, and most keep an audit log.

    Business agent platforms mostly do the same

    Seven of twelve document a named permission. Some vendors pair the editor with a decider.

    These guardrails are controlled by your admin and typically signed off by your internal leadership or key decision-makers.Salesforce Agentforce documentation

    Governance platforms record approvals but rarely say who edits

    Inventories, approval workflows and audit trails, but only one of six names the role that changes a limit.

    Protocols leave it to the implementer or the user

    MCP and A2AMCP (Model Context Protocol) connects an agent to tools and data. A2A (Agent2Agent) lets agents call each other. AP2 (Agent Payments Protocol) and ACP (Agentic Commerce Protocol) let agents pay on a user’s behalf. leave authorisation to whoever builds on them. Payment protocols put the limit in a mandate the user signs.

    15 of 26 products name an editor: a majority, short of the two-thirds we set in advanceBefore reading any documentation we set a test: at least two-thirds of products would have to name an editor. 15 of 26 do, so the evidence is mixed rather than conclusive..

    Every platform shows an agent is a lasting design plus short-lived runs

    A design (instructions, tools and limits) persists; runs created from it last minutes or hours, often many at once. So the design can be owned, and each run can only be traced back to it. No law registers agents.

    Explore · Who holds what

    Five roles are taking shape around agents. Who sets their standard is an early sign; who approves each change is still open

    Select a role to see the evidence behind it and how sure we are.

    OUTSIDE THE FIRM

    INSIDE THE FIRM

    Explore · Law

    High on what the texts say: every quote was checked by script. The AI-law count rests on 4 provisions on changes, coded by one coder.

    The law shows overseers for high-risk uses, not owners of rules, and no law registers agents

    Of 111 provisions in 19 laws and policies, only trading rules and AI labs’ own voluntary policies name who decides a rule change. Binding AI law names no one. Filter by family.

    For high-risk uses (hiring, lending, insurance, health and similar decisions), the EU AI Act and Colorado will require deployers to name trained overseers: Colorado from January 2027, the EU from December 2027. Most agents in support, sales or internal work fall outside that. In the EU a deployer is any organisation using an AI system professionally, so this applies to ordinary companies, not just AI labs.

    Context · Where it sits

    High: the gap between technology and business functions is wide and holds across all three measures, with intervals that do not overlap for the largest functions.

    Job postings show AI and agent hiring sits in technology functions; business functions barely hire for it yet

    Each row is a business function; each column is a different measure on its own scale. Technology functions are shaded. All three columns come from 118,526 job postings. Dots show estimates, lines their 95% intervalsFunctions were assigned from job titles and occupation codes: about 82% right on a blind check, 95% counting defensible alternatives. Agent-duty shares for data and AI and for security are conservative. Governance duties are counted from a keyword family checked at 85% precision. Only 7.8% of AI-titled postings state who the role reports to, so reporting lines cannot be mapped yet..

    Scroll sideways for all three measures.

    Explore · Decision rights

    Medium that agent rule duties carry decision rights as often as other rule systems, or more. Low on the split between standards and change approvals: it is an exploratory re-code.

    Mature rule systems pair a standards owner with change approvals; agent rule work so far has only the first

    We coded rule duties in job ads as editing, applying or deciding a rule, for agents and eight other rule systems. About a quarter of agent rule duties carry decision rights (9 of 40), above the 9.1% median elsewhere. So our pre-registered test that agents are an exception, with too few deciders, failed.

    Every agent decision duty sets standards up frontAn exploratory re-code of all 35 decision duties, coded without seeing the domain. The split is significant (p ≈ 0.03) but fragile: it rests on IT change, and without it p ≈ 0.14. Role type may explain part of it: agent items come mostly from AI-titled senior architect postings, and identity-and-access duties, done by similar architects, also all set standards. “Change management” also catches change that is not IT change.. In other systems many approve individual changes or exceptions.

    set the engineering standards that define how agentic AI gets deployed at scaleSalesforce job posting, 2026
    CAB approvalsNorthern Trust job posting, 2026 (CAB: change advisory board)
    Review and approve complex chargeback claims … pricing exceptionsAmgen job posting, 2026

    Written documents tell the same story. In all eight comparison domains, a public document names who approves rule changes. For agents, documents name deciders for AI use in general; only Microsoft Entra’s vendor documentation names approvers for changes to an agent’s access.

    Context · Compared with other control paradigms

    Agent operations differs from data and financial controls in what is controlled, who edits it, and where it runs

    Data teams and financial controllers have run rules for decades. Set side by side, agent operations stands out in five ways. Each row carries its own confidence.

    What differsData operationsFinancial controlsAgent operations
    The unit you control Documented on every agent platform we examined: a design lasts, runs created from it last minutes or hours. Bank model-risk guidance gives each model an owner.Lasting pipelines, datasets and models; a bank model has a named ownerLasting algorithms, credit policies and price lists, each with an ownerA lasting design plus many short-lived runs: designs can be owned, runs only traced
    How rules are written and changed 15 of 26 products document an admin role that edits agent limits; practitioners describe changing guardrails themselves.In code and schemas, by data engineersIn risk systems and policy documents, by specialist teamsIn plain language, in each vendor’s admin settings, by whoever holds the admin role, often the staff running the agent
    Who decides changes Exploratory re-code: all 9 agent decision duties set standards; elsewhere 11 of 26 approve specific changes. Fragile, and partly explained by architect roles.Data owners approve access to their dataCommittees and named approvers sign off individual changes and exceptionsA standards owner is emerging; approval of individual changes is not yet assigned
    What the law asks for From the legal texts read in full: trading rules, GDPR, the EU AI Act and Colorado SB26-189.A named data protection officer (GDPR)Named owners of algorithm changes, licensed algorithm designers, a CEO who certifies controlsA trained overseer for high-risk uses only (hiring, lending, insurance, health); no law names agents
    Where the work runs Company controls reach only what the company owns; personal subscriptions on personal devices sit outside them. The personal-device cells are reasoned from how controls work.On company platformsOn company and exchange systems onlyAlso on staff members’ own AI subscriptions, beyond the reach of company controls
    How fast it formalised Dated milestones from our role profiles and Internet Archive captures; start dates are a judgement.Data science: about 5 years to a certification, 9 to an occupation codeDecades to binding lawAbout 2.4 years to an agent-named credential; deployer duties scheduled within 4 to 5

    Data operations is covered here through data-science milestones and bank model-risk guidance, not a separate study.

    Context · Is it DevOps again?

    Inside teams, agent work is spreading the way DevOps did. In hiring, it looks like a race for scarce AI skills

    DevOps formed when existing developers and operators took on each other’s work to coordinate, without a new profession or a law. Switch lenses to compare the evidence.

    The dates are graded against primary sources, but the start dates differ in kind, and the order of milestones is common to enterprise software in general.

    Roles that ended up with a law took fifteen years or more to get one; the dates point to agent work moving faster, with a first credential in about two and a half years and deployer duties for high-risk uses within five

    Agent work reached its first agent-named vendor credential (Salesforce’s Agentforce Specialist, March 2025) about 2.4 years after the practice went public in October 2022, roughly twice as fast as DevOps (5.4 years) or data science (5.0 years). It already sits under a general EU duty on deployers, the firms that use AI (AI literacy, from February 2025). Substantive deployer duties for high-risk uses are scheduled within four to five years: Colorado from January 2027 and the EU’s high-risk rules from December 2027. Most agents in support, sales or internal work fall outside them. We found no binding text aimed at DevOps or data-science work over a comparable span. None of these laws names agents.

      Years from when each practice went publicStart dates differ in kind. DevOps and data science start when firms showed their practice; agents start with a research paper and an open library (ReAct and LangChain, October 2022). Counted from a firm milestone, agents reached the credential 2.5 years after Adept’s ACT-1 (September 2022) or 1.0 year after Klarna’s assistant (February 2024). “About twice as fast” holds either way. Trading control’s start ranges from 1976 to 2009 depending on the definition; we draw it from 1987.. DevOps was absorbed into an existing job, data science became a new occupation, the security officer was mandated by law, and trading control became a licensed duty. Dates come from our role profiles, the legal texts read in full, and Internet Archive captures for the agent timeline.
      See the dates
      MilestoneDevOpsData scienceSecurity officerAlgorithmic trading controlAI agents
      Practice goes publicJun 2009Flickr’s talk on daily deploysApr 2009Facebook’s data team described in public1985a head of information security at JP Morgan1976 to 2009contested; drawn from 1987Oct 2022ReAct paper (6 Oct); LangChain repository (17 Oct), its first commit named agents on 22 Nov
      Job titles appearMar 2011+1.7 years, 134 “devops engineer” ads2008title coined before the practice went public; 806 ads by Jan 20121995+10 years, Citibank names a Chief Information Security OfficerNot datedJun 2023+0.7 years, “AI engineer”; no archived count of “agent engineer” titles before late 2025
      First credentialNov 2014+5.4 years, AWS DevOps EngineerMar 2014+5.0 years, Cloudera data science certificationBy 1998+13 years, CISSPJan 2017+30 years, Series 57 exam, required by regulators for those who design or change algorithmsMar 2025+2.4 years, Salesforce Agentforce Specialist, a rename of its AI Specialist credential (exams from Sep 2024); general AI credentials from Sep 2023
      Shared metricsMar 2013+4 years, State of DevOps surveyNone foundNone foundNone foundResearch benchmarks onlyno shared operating measure
      Official occupationNone of its owna job title under Software Developers (15-1252)Nov 2017+8.6 years, its own code: Data Scientists (15-2051)By 2010within 25 years, Information Security Analysts (15-1122, now 15-1212)None of its ownfalls under securities tradersNot expectedour forecast: none in the 2028 US classification (70%)
      Binding lawNone foundNone foundDec 2002+17 years, FISMA and the FTC Safeguards Rule require a designated security officerNov 2010+23 years, SEC Rule 15c3-5: the CEO certifies trading controls. Later: FINRA registration of algorithm designers (Jan 2017); EU RTS 6, a designated approver of changes (Jan 2018)Feb 2025+2.3 years, general EU duty: deployers take measures to support AI literacy (Art. 4, wording since weakened). Scheduled, for high-risk uses only: Colorado deployer obligations for consequential decisions apply from 1 Jan 2027 (+4.2); EU Art. 26 duties for Annex III high-risk systems from 2 Dec 2027 (+5.2), already postponed once from Aug 2026
      Split or successorApr 2023+13.8 years, platform engineering2017 to 2019+8 to 10 years, ML and analytics engineers2000chief privacy officers split offNone foundFrom Sep 2024vendors rename agent products within about three years

      Context · Annual reports

      High for the counts, which are phrase hits on the full text of the filings. Medium for what the passages say. 2026 is a partial year, though most annual reports are filed by March.

      Annual reports show agent language surging, mostly written by vendors describing their products

      Share of companies filing a 10-K, the annual report US-listed companies file, that use an agent phrase. Vendors write about 60% of these passages. “Employers studied” are the employers in our job-posting sample that file 10-Ks. Select a year.

      Personal AI at work

      High on what the controls do: each is stated in vendor documentation or follows directly from how it works. How common unmanaged personal use is cannot be measured from public sources.

      Vendor documentation shows company controls reach only what the company owns: the device, the browser, the network path or the account

      Staff increasingly use their own AI subscriptions and agents for work. Every control we found works only where the company owns something: the device, the managed browser, the network path, the sign-in on the company’s email domain, or the company’s own apps. A personal account on a personal device sits outside all of them, and no source can measure how common that is. A dashed edge marks an inferred cellA dashed edge means the cell follows from how the control works, but no document we collected says it outright. The other cells are stated in vendor documentation or guidance, fetched 11 October 2026. Sources and quotes are in the repository..

      Control layerCompany devicework accountPersonal devicework sign-inPersonal devicepersonal AI account
      Devicedevice management, managed AI settings, endpoint data-loss rules Reachede.g. Claude Code managed settings pin logins to the company organisation, with documented exceptions; Microsoft Purview endpoint DLP covers devices once they are “onboarded” Not reached (inferred)the company doesn’t manage the device Not reached (inferred)
      Browserenterprise browser or extension with data rules Reachedin the managed browser profile: Chrome Enterprise “restricts access to unapproved external generative AI tools” Not reached (inferred)unless work sign-in requires the managed browser Not reached (inferred)
      Networkproxy, secure web gateway, tenant restrictions (blocking other organisations’ sign-ins on the company network) Reachedonly traffic the company routes: Microsoft Entra tenant restrictions apply to “users on their network” and can block personal Microsoft accounts Not reached (inferred)traffic doesn’t pass through the company network Not reached (inferred)
      Identitysingle sign-on, domain capture (claiming every account on the company’s email domain) Reachedcompany sign-in enforced PartlyClaude Enterprise domain capture means “no non-Enterprise accounts can exist on your verified domain”; Team plans can only block new ones Not reached (inferred)a private email address sits outside the company’s domain
      Company apps and dataapp-side controls, managed accounts Reachedthe company’s own tenants: Microsoft Purview flags sensitive data shared with registered ChatGPT Enterprise workspaces Reachedthe work account is the company’s Partly (inferred)only when the personal agent uses company credentials to reach company data
      Policy, training and lawacceptable-use rules, the EU AI-literacy duty on deployers; overseer duties cover high-risk uses only AppliesApplies Appliesthe only lever left

      Companies are licensing, not banning

      Only 16% of organisations block public generative AI by default, according to Gartner (2025). The 2023 bans were narrower than they sounded: Samsung’s covered “company-owned devices as well as internal networks”. On the company paths that vendors can see, personal-account use of AI apps fell from 78% to 47% of users in a year while approved accounts rose from 25% to 62%.

      is unlikely to disappear completelyUK National Cyber Security Centre on shadow AI, 7 September 2026

      Inside firms, it is a security job

      In our job postings, duties to find, monitor or block unapproved AI sit mostly in security roles: about 19 of 31 such duties, at 14 employers. Elsewhere, postings only ask staff to use approved AI tools, and annual reports mostly name the risk of unapproved tools without a control.

      discover unsanctioned AI tools, browser extensions, and API-level agentsAlphaSense job posting, security role, 2026

      Control features have documented gaps too: Anthropic notes that one Claude Code sign-in route can create a credential in a different organisation.

      What firms can do. Offer a good sanctioned AI account so staff have a reason to use it; enforce company sign-in where the company owns the email domain; put controls on the company apps and data that any agent, personal or not, has to touch; and rely on clear rules and training for the rest.

      What to do

      Set a standard for agent controls, name its owner, and reserve sign-off for exceptions

      In most products the change itself is already an admin permission. What firms need is a written standard that says which changes are routine and which need a named reviewer. Four moves follow from the findings; the deadlines apply to high-risk uses. Select one.

      Talk to us about agents in your firm

      Protocol Vision Advisory meets firms to talk through agent adoption and control. Request a meeting and we’ll be in touch to set one up.

      Don’t hire one senior “protocol lead”: no such posting exists among 25,512, and lasting roles in the past did not start senior. And don’t let vendor consoles hold the only copy of an agent’s rules.

      Try this in your firm

      Public sources show who edits an agent’s rules but not who approves a change; you can find out inside your own firm in an afternoon

      Pick one agent that matters, such as a support, finance or sales agent, and work through five checks, in order. Each one tests a finding in this report against your own records.

      0 of 5 done

      Your ticks stay in this browser only.

      If you’d like to discuss this research, come to the Protocols for Business research group: open sessions every other Monday, with readings, observations and case studies.

      How we know

      Across 300,000 job duties, only one kind of AI work recurs consistently: security review of AI systems

      We read postings the way a labour economist reads tasks: by duties, not titles. Step through the method on real data.

        Fork the data and analysis on GitHub: designs, scripts, codes, cluster assignments and reviews. The results are under results/rerun-2026-10-10/.

        118,526postings crawled from 218 employers
        305,533duty statements extracted
        1,167company filings read
        771statements from 30 practitioners
        111legal provisions coded
        31products and protocols audited
        What these findings rest on
        • Public sources only: postings, filings, recordings, laws and vendor documentation. Rule changes agreed informally inside firms do not appear.
        • 59% of employers in scope have no crawlable job board, including Alphabet, Apple, Meta, Microsoft, Amazon, Goldman Sachs and JPMorgan.
        • Speech extraction catches about half of what is said, and the statements about changing agents in tools rest mainly on two speakers.
        • Product documentation shows what products allow, not what firms do; four products’ documentation could not be retrieved.
        • No time series: the job-board crawl is one point in time.
        Checks
        • Tests, thresholds and refutation rules were fixed before any data were read.
        • Duty statements were checked against their source postings: precision 0.97, recall 0.89.
        • A red team and fresh reviewers checked every result.
        • Every quote on this page is checked by script against the stored source.
        • Personal AI: the 16% blocking figure is Gartner’s (2025). The fall in personal-account use is Netskope telemetry as reported in the press, and covers only company network paths that vendors can see.
        Sources quoted on this page