arrow_back

Back

Keeping AI agents from going rogue: lessons from AI Agenda 2026

02 October 2026
schedule

5 min read

Add as a preferred source on GoogleAdd as a preferred source on Google

“Humans are lazy,” said technologist Rob Price. That’s a problem when we’re supervising AI, including agentic AI, because it means we’re poor at staying in the loop: we lose focus, skip alerts and rubber-stamp outputs. So organisations have to work out how to govern agentic AI responsibly and ethically. They also have to keep people watching closely enough that agents don’t ‘go rogue’.

Price is co-founder of Futuria, a platform for multi-agent workflows. He spoke on the “Agentic AI and the New Frontiers” panel at our AI Agenda conference in London, alongside JJ Shaw (Partner, Lewis Silkin), Sagar Shah (Associate Partner, McKinsey) and Sarah Murphy (Senior Legal Counsel, Colossyan Inc). The panel looked at the governance and operational questions that agentic AI forces every organisation to confront.

Three ways to keep a human in the picture

One question kept coming back. How closely should humans stay involved in what their agents are doing, given Price’s verdict that we’ll always find the path of least resistance? In other words, organisations need to know when it’s safe to flick the autopilot switch and let the machine fly the plane.

Shah set out three models of human involvement:

  • human in command;
  • human in the loop (HITL); and
  • human on the loop (HOTL).

Human in command puts the human firmly in charge of the process from start to finish. The person keeps the final say. The agent can prepare the work, but it doesn’t take a binding action without sign-off. Shah’s example was agents negotiating contracts.

HITL is the middle option and probably the best known. The person is in the decision with the agent and can redirect it while it is working.

HOTL is where the agent runs the repeatable task. The person supervises and steps in when needed, rather than approving each output.

Oversight needs to be engineered

Whichever model an organisation chooses, Murphy said that “we need to create architecture which works”. Oversight of agentic AI can’t rest on good intentions or on people trying harder. Human attention is scarce and it fades, so governance has to be built around that fact.

Kate Jones, CEO of the Digital Regulation Cooperation Forum, made a similar point in the AI Agenda opening keynote. She suggested we think of AI, and agentic AI in particular, less as software and more as a new member of staff:

At first it behaves like an apprentice: you give it tightly defined tasks, you check everything, and mistakes are expected. Then it becomes a colleague, helping with meaningful work. And increasingly, with agentic systems, it starts to look more like an employee operating independently within a defined remit.

On governance, Jones said that “the governance challenge is obvious”, adding:

We would never hire thousands of new employees, give them access to customers, data and purchasing authority, and then worry about supervision, accountability and training afterwards. Governance is the discipline that ensures we recruit, supervise and manage our digital workforce as carefully as we do our human one.

Buying agentic AI: read past the label

The area is complex and changing fast, but plenty stays the same, including how you buy. Murphy warned that organisations “should be wary of marketing claims”. The panel agreed that the field is thick with jargon and, in Price’s words, “misused terms”. A product sold as ‘agentic AI’ may not be agentic at all. Find out exactly what you’re buying, and don’t be shy about asking awkward questions.

Murphy also called for a “risk-based approach” to agentic AI, with due diligence to match. That starts with knowing your non-negotiables. A single large language model (LLM) aggregator can sit on top of several underlying model providers, each with its own terms of service. That can mean hundreds of legal terms, and they can change often and with little notice. So don’t try to negotiate every clause. Set your red lines at the start and focus your review on them.

The overlooked risk: other people's agents

Price raised the risk that rarely gets discussed. Talk about agentic AI tends to focus on the active side: what organisations need to do to use AI agents and set them loose, internally and externally. The passive side gets far less attention. “How are you going to protect your business when other organisations are using AI agents?” he asked, thinking of agents that interact with your enterprise architecture. “You need to look at the two angles.”

And things are moving quickly. Shah noted that the “advanced models are already out there”. This means that over the next six to 12 months, most live use will still have a person either signing off a consequential action or sitting in the decision where judgment is needed.

Over the timeframe of 24 to 36 months, however, more repeatable work can move to supervision, where a person steps in when something looks ‘off’, rather than that person approving every step.  

How fast this all happens will depend on the risk of the workflow.

From apprentice to employee

Agentic AI is moving from apprentice to employee faster than many organisations are ready for. The basics still apply: understand what you’re buying, take a risk-based approach, know your non-negotiables and protect your business from other people’s agents. The difference is that oversight has to be engineered, not assumed. As Murphy put it, we need “architecture which works”. Good intentions won’t be enough.

Explore more from AI Agenda 2026

On 16 September 2026, we hosted AI Agenda 2026 for senior leaders, legal experts and innovators exploring what it takes to deploy AI safely, strategically and at scale. Explore all the insights from other sessions - covering topics from agentic AI and governance to IP, procurement, litigation and leadership.