When an organisation says that its AI agents have human oversight, a great deal remains unexplained. The supervisor might approve the task before it starts, inspect selected outputs afterwards, or simply receive a summary of what happened. Those arrangements provide different opportunities to detect a mistake and prevent its consequences.
Read State of Agentic Security: Governing the AI Workforce (PDF)
Fenko’s 25-page report examines how organisations can make those responsibilities explicit. It brings together public research on agentic threats, published technical analysis and Australian and New Zealand guidance. Its central proposal is to identify the AI execution owner of delegated work while assigning a named human accountable owner before execution begins.
A signature does not explain what was checked
In October 2025, the Associated Press reported that a Deloitte report for the Australian government contained nonexistent references and a fabricated judicial quotation. A revised version disclosed generative-AI use, and Deloitte agreed to a partial refund. Institutional accountability existed, but defective material had still reached the client. Read the AP report.
That case concerns AI-assisted drafting, rather than demonstrated autonomous agent control. Its relevance is the gap between accepting responsibility for a document and independently verifying what it contains. As agents take on longer sequences of work, organisations need to establish how that verification happens at each consequential handoff.
The report separates execution, accountability, verification and release authority. An agent’s record should show which task it performed, under what instructions and permissions, and with what result. The human owner authorises the delegation and remains responsible for its controls. Verification checks the evidence against agreed criteria before the result is accepted for use.
A person using Claude Code can work within that arrangement. So can a service involving several agents. Neither arrangement establishes effective control merely by naming a supervisor.
Independent review requires independent evidence
If a reviewer receives only the producing agent’s summary, the review may inherit its omissions. Adding a second agent does not necessarily resolve the problem when both rely on the same incomplete material.
Verification therefore needs access to original sources and direct tests where they are available. It also needs enough time to investigate exceptions. When agents produce work faster than it can be checked, management has to address that constraint through narrower scope, lower volume or additional review capacity.
The report follows these questions into prompt injection, agent configuration, coding benchmarks and the conditions required to reproduce a security finding. These examples help explain why a convincing output and a verified outcome are different claims.
Applying the guidance in Australia and New Zealand
The joint Careful adoption of agentic AI services guidance published by Australia’s ACSC addresses the difficulty of tracing responsibility across agents. It recommends audit records and clear accountability, alongside restricting agentic AI to low-risk, non-sensitive tasks.
New Zealand’s NCSC asks government entities to confirm executive accountability and address material security gaps in its Cyber readiness in the Frontier AI era guidance. Established controls, including least privilege and incident response, remain part of that work.
The report’s discussion of consequential workflows does not extend autonomous authority to their high-impact actions. Delegating bounded analysis or preparation is separate from authorising execution. Human review is not treated as an exemption from the cited low-risk restriction.
Fenko’s responsibility model is a proposal to evaluate against real tasks. Its value depends on whether it makes errors easier to detect, decisions easier to reconstruct and intervention more effective. The report sets out the evidence needed to assess those benefits without assuming that an organisation chart delivers them.
Read the full report on Google Drive — released September 2026, with references linked in the PDF.
