Sponsorship is no longer the binding constraint: staff already use AI about as much as executives do. What leadership still owes them is an answer about what happens to the time saved, and a named person accountable for agent risk; without both, the rational move for a builder is to keep quiet.
Why this matters
Two numbers from the same survey of nearly 6,000 executives on central-bank panels. Executives use AI about 1.5 hours in a typical work week; employees, measured separately, about 1.8. And executives expect AI to reduce their firm’s employment by 0.7% over three years (1.2% in US firms) while employees expect it to increase employment by about 0.5% (Atlanta Fed WP 2026-3, fielded Nov 2025–Jan 2026).
Put those together. Adoption is flat across the hierarchy, so this is not a case of leaders pulling reluctant staff along. But the two populations hold opposite beliefs about the consequence, and only one of them has seen the board deck. An analyst deciding whether to register the agent that does 40% of their job is making a bet on which belief is right. Silence from the top resolves that bet against disclosure, which is how a firm ends up governing the agents it knows about while the interesting ones stay off the books (see shadow agents).
The cheapest observed correction is unglamorous: naming someone accountable. Organizations with an explicit owner for AI risk (a governance role, or internal audit and ethics) average 2.6 on a 0–4 maturity scale against 1.8 without one (McKinsey, n=496). Correlation in a cross-section, and naming an owner is plausibly a marker of maturity rather than its cause, but it is the largest gap in that survey attached to the smallest action.
Two calibration warnings apply before a firm assesses itself. First, executives cannot currently name the controls: asked to identify the right control for each of five AI risks, 12% of C-suite respondents answered correctly, and chief risk officers scored 11% (EY, n=975 at $1B+ firms). Second, self-assessment is probably a seniority artifact. Twice as many VP+ respondents as mid-managers say their organization is adopting faster than peers (56% vs 28%), with the same split on positive ROI (45% vs 27%); the board hears the first number, the work runs on the second (Wharton/GBK, n=801). A related gap runs on sentiment: 76% of executives believe employees are enthusiastic about AI; 31% of individual contributors say they are (HBR, n=1,400 US employees).
This dimension is genuinely contested and the disagreement is worth knowing. The citizen-development literature and every consultant deck in our sources put executive sponsorship first: six cases where adoption tracked active top-management support exactly, and a 2023 study naming sponsorship the single most important program condition. All of that evidence is 2022–2024, pre-agent. The most recent measurement points the other way: in a Dec 2025–Jan 2026 survey, lack of executive support was the least-cited barrier both to responsible-AI implementation and to scaling agents, well behind knowledge gaps and security. Our read: sponsorship was the constraint and mostly stopped being one; what replaced it is decision rights, funded review capacity, and executive fluency, so advice on this dimension is worth dating before it is taken.
One more, on tone-setting. The two celebrated 2025 CEO memos making AI use a baseline expectation are the standard example. By April 2026 one of the two firms no longer considered AI use in performance reviews. The reversal is the better lesson: a retracted mandate costs more standing than one that was never issued.
Where you stand
| Level | Looks like | Cheapest next move |
|---|---|---|
| Crawl | AI use is tolerated and unmeasured. Nobody owns agent risk. Leadership’s estimate of internal usage comes from asking around. | Name one accountable owner for agent risk in writing, with the authority to say no, and put it in the org chart. |
| Walk | A policy exists and a sponsor is named. Budget is ad hoc, no leader visibly builds anything, and the employment question is unanswered. | Answer the employment question in writing, and publish a short list of uses that are explicitly safe — a green zone beats a warning. |
| Run | A cross-functional council with real decision rights meets on a cadence. Risk appetite is written per tier. Registry growth is reported to the operating committee. | Fund the reviewer pool as a named cost rather than as volunteer time; unfunded review is where oversight decays. |
| Fly | Agent goals appear in performance evaluations. The portfolio is managed like a P&L, including retirements. Leadership reads its own telemetry rather than a survey. | Fund a second maintainer for every load-bearing agent, and require a named successor before promotion to production. |
A council without authority is worse than no council, and a body that cannot stop a build is only a meeting: Microsoft’s own adoption guidance names the paper-council as an anti-pattern because it blocks late instead of enabling early.
Concerns this dimension covers
- Shadow agents — the direct product of leadership silence on what disclosure costs the discloser.
- Oversight decay — what happens when review is mandated and never resourced. This is the failure mode leadership uniquely causes.
- Agent sprawl — the portfolio consequence of funding builds and not funding ownership.
- Resource overload and runaway cost — the one agent failure that reliably reaches the CFO first.
Controls that answer them
- Agent inventory and registry — the first thing leadership funds, because visibility precedes every other decision.
- Human approval gates — gates bind only when leadership backs the reviewer who says no, in public, at least once.
- Cost controls — the budget lever that is also a containment control.
Sequencing
- Day 3 sequencing — the canonical order of investment. Leadership’s job is holding the order when someone wants to skip to the platform.
- Build vs buy — the decision that actually consumes executive time in a 40-person fund.
- 90 — including why internal ROI self-reports run high and what to measure instead.
Where this is checked
- Registry review cadence — the recurring meeting where leadership sees the actual portfolio rather than the reported one.
- Promotion gates — where the risk appetite leadership wrote becomes a decision someone has to make.
Open questions
- Does an amnesty-plus-incentive program actually surface hidden agents? The mechanism is practitioner consensus; nobody has published a before/after. See open questions.
- Has the barrier really moved from sponsorship to capability, or is the 2026 survey measuring executives who have stopped noticing they never resourced anything? A firm-level answer would come from tracking review capacity against build volume for four quarters.