Companies are starting to use AI agents to complete real work.
An AI agent is software that can take several actions to complete a task.
These agents can:
- Read files
- Search databases
- Send messages
- Update software
- Speak to customers
- Process requests
- Complete tasks
- Use other digital tools
This can save time and help employees work faster.
But it creates a serious question.
Who is responsible for these agents?
On 28 July 2026, Oasis Security said it had signed a letter of intent to be acquired by Cyera.
The companies said the transaction was still being completed.
It should therefore be understood as a proposed acquisition, not a completed deal.
Cyera helps companies find and protect sensitive data.
Oasis Security helps companies find and control non human identities.
A non human identity is a digital identity used by software rather than a person.
These identities can include:
- AI agents
- Bots
- Service accounts
- Automated software
- API connections
- Machine credentials
The proposed deal shows that businesses are no longer protecting data only from people.
They must also understand which machines can access it.
Companies Have More Identities Than Employees
Most organisations know who their employees are.
Each employee normally has:
- A name
- A job title
- A manager
- A work email address
- A list of systems they can use
- A clear starting date
- A clear leaving date
AI agents do not always have the same structure.
An agent may have access to important company systems without having a clear name, owner, purpose, manager or end date.
The agent can still take actions.
But employees may not know that it exists.
Introducing the Invisible Organisational Community
The Invisible Organisational Community is the group of AI agents, bots and automated systems working inside a company without being visible to most employees.
The visible organisation includes employees, managers, teams, contractors and leaders.
The invisible organisation may include:
- Customer service bots
- Sales agents
- Marketing tools
- Coding agents
- Finance automation
- Service accounts
- Background software
- Systems created by former employees
These machines are part of how the company operates.
But they do not appear on the normal company chart.
An Identity Is More Than a Login
Giving an agent a username or password does not fully explain who it is.
A company must also know:
- Why the agent exists
- Who created it
- Who owns it
- What information it can access
- What actions it can take
- Whether it can speak to customers
- Whether it can give work to another agent
- When its access should end
Without this information, the organisation may know that an account exists but still not understand what it does.
The Agent Ownership Gap
The Agent Ownership Gap happens when an AI agent has power but no clearly responsible human owner.
For example, an AI agent may be able to read customer records, change prices, send emails or update a database.
But when it makes a mistake, employees may not know who should answer for it.
The security team may say the agent belongs to marketing.
Marketing may say it was created by an outside supplier.
The supplier may say the company approved its settings.
Responsibility becomes unclear.
Every important AI agent should have a named human owner.
Permissions Can Remain After the Work Ends
A company may create an automated account for one project.
The project ends.
The employee who created it leaves.
The account remains active.
It may still have access to customer information, internal documents, cloud services, payment systems or company software.
This is Dormant Authority Risk.
The account is no longer being actively used, but it still holds power.
The organisation may forget that it exists until something goes wrong.
Agents Can Give Work to Other Agents
AI agents may not complete every task themselves.
One agent may send a job to another agent, an outside AI model, a software tool, a database or an automated workflow.
This creates a chain:
Employee → Agent A → Agent B → Outside tool → Business result
The longer this chain becomes, the harder it can be to understand who made the decision.
This is the Recursive Accountability Gap.
Responsibility becomes weaker each time the work is passed on.
Security Visibility Is Not the Same as Employee Understanding
A cybersecurity team may be able to find an AI agent inside the company's systems.
That is useful.
But employees may still not understand:
- What the agent is for
- Why it has access
- Whether it is watching their work
- Whether it could replace part of their role
- Whether its decisions are checked
- Whether they can challenge its actions
Technical control does not automatically create organisational trust.
Employees need clear explanations.
Every AI Agent Needs a Biography
Companies should create an Agent Biography for every important automated system.
The biography should explain:
Agent Name
Give the agent a clear name that people can recognise.
Purpose
Explain the job it is meant to complete.
Human Owner
Name the person responsible for its behaviour.
Systems Accessed
List the files, tools and databases it can use.
Actions Allowed
Explain what it can and cannot do.
Delegation Rights
State whether it can send work or data to other agents or outside services.
Review Date
Set a regular date to check whether the agent still needs its access.
Retirement Date
Explain when the agent should be removed or replaced.
This makes the invisible workforce easier to understand.
Employees Must Know Who They Are Working With
Employees may receive messages, reports or instructions created by an AI agent.
They may not always know that a machine produced them.
This can damage trust.
People should know when:
- An AI agent is speaking to them
- An AI agent is reviewing their work
- An AI agent is making a recommendation
- An AI agent has changed a record
- A human has approved the final decision
Transparency does not require explaining every line of code.
It requires explaining what role the agent plays.
Customers Also Need Clear Answers
AI agents increasingly speak directly to customers.
They may answer questions, recommend products or deal with complaints.
Customers should know whether they are speaking to an AI agent and whether a human can take over.
They should also understand how their information is being used and how they can challenge a mistake.
A hidden AI agent may save the company time.
But it can create distrust when customers discover that important decisions were made without clear human oversight.
The Real Problem Is Organisational Understanding
The rise of AI agents is often described as a technology or cybersecurity issue.
It is also a community issue.
A company is a community of people working together.
Trust depends on people understanding who participates, who has authority and who is responsible.
AI agents are becoming participants in that community.
If they remain invisible, employees may feel that important decisions are happening around them rather than with them.
This is why Community Intelligence must be part of AI adoption.
What Companies Should Measure
Companies should not only count how many agents they use.
They should understand:
- Which teams know that agents are operating
- Whether every agent has a human owner
- Whether employees trust the agents
- Which decisions require human review
- Whether unofficial agents are being used
- Whether old machine accounts still have access
- Whether employees understand how agents affect their jobs
- Whether customers know when they are dealing with AI
- Whether responsibility is clear when an agent makes a mistake
Community Intelligence helps companies understand how people experience AI adoption, not only whether the software is working.
Our analysis of outside oversight for AI agents explores why internal records may not show the whole effect of an autonomous system.
The Community Intelligence Lesson
Businesses are building an AI workforce that does not appear on the organisational chart.
The security problem is making sure these agents have the correct access.
The Community Intelligence problem is making sure people understand why the agents exist, what they can do and who owns them.
An AI agent does not become a trusted part of a company simply because it has login details.
It becomes a legitimate participant when the human community understands its role and boundaries.


