Decision Rights Without a Ledger

Decision Rights Without a Ledger

·

McKinsey’s 2026 AI Trust report has one line that cuts through most of the governance noise being produced right now.

McKinsey Partner Rich Isenberg: “Agency isn’t a feature — it’s a transfer of decision rights.”

That’s it. That’s the reframe.


What changes when you say it that way

Most enterprises treat agent deployment as a rollout. Configure the agent. Assign it to a workflow. Set permissions. Ship it.

That framing makes it feel like product work. Add a capability, monitor it, tune it. The same lifecycle as deploying any other software.

Isenberg’s framing makes it feel like what it actually is: you’re transferring authority. Every agent you deploy holds the right to make decisions — book resources, send communications, execute transactions, modify records — on behalf of the organization. Those decision rights were previously held by a human who was accountable for exercising them correctly.

You’ve transferred that authority to a system. The question isn’t whether the system is capable. The question is whether you have a record of what it did with that authority.


The number that makes it concrete

In 2025, less than 5% of enterprise software embedded AI agents.

By end of 2026, McKinsey projects that number reaches 40%.

8x. In 12 months.

The governance infrastructure that exists to oversee these systems is not growing 8x. It’s growing incrementally — maturity scores ticking from 2.0 to 2.3, frameworks being updated, audit templates being revised.

8x the decision authority transferred. Incremental growth in the infrastructure that tracks what those decisions were.

That gap has a name. Grant Thornton’s 2026 AI Impact Survey calls it the “AI proof gap.” 78% of business executives say they lack strong confidence they could pass an independent AI governance audit within 90 days. Not because they don’t have governance policies. Because they can’t reconstruct what their agents decided — what commitment was made, on whose authority, whether it was fulfilled, whether the loop was closed.

The policies exist. The records don’t.


Why governance frameworks don’t close this gap

The dominant response to the accountability problem is governance frameworks. Tier your agents by autonomy level. Define what each tier is cleared to do. Apply proportional oversight. Gartner published exactly this recommendation in May.

The framework is correct. But it assumes something.

A governance framework can tell you: this agent is authorized to operate at Level 2 autonomy, which means it can execute transactions up to $10,000 without human approval.

What it can’t tell you: on June 12, this agent executed seven transactions. Here are the commitments it made. Here’s whether they were fulfilled. Here’s what’s still open.

Authorization and audit trail are different infrastructure. The framework governs what the agent is allowed to do. The audit trail records what it actually did. Most enterprises have invested in the first. Almost none have built the second.

That’s what Grant Thornton is measuring when they say 78% can’t pass an audit. They’re measuring the absence of records — the gap between authority granted and decisions logged.


The mechanism

When a human holds a decision right, the act of exercising it typically leaves traces. An email. A signed document. A verbal commitment that became a calendar entry. The record isn’t always clean, but the decision existed in a human context that generated artifacts.

When an agent holds a decision right, it exercises it at machine speed. Thousands of micro-decisions in a workflow, each one real — each one capable of creating a downstream commitment — with no artifact unless the system was explicitly designed to produce one.

Most aren’t.

The default state of an agent operating without commitment tracking isn’t governance failure. It’s governance absence. There’s nothing to audit because there’s nothing to audit against.


What “transfer of decision rights” requires

If agency is a transfer of decision rights, then the infrastructure question is: what does a legitimate transfer require?

For humans, the answer involves: authority (are you authorized to make this decision?), record (what did you decide?), traceability (can someone reconstruct the decision chain?), and accountability (who is responsible if it goes wrong?).

Agents have the first. The others are optional, which means in practice they’re absent.

The 8x surge in agent deployment is moving that population into the authority layer of organizations faster than anyone predicted. The decisions being made in that layer are real — financial, operational, communicative. They create open commitments. They close loops, or they don’t.

A ledger isn’t a compliance box. It’s the infrastructure that makes the transfer legitimate.

Without it, you haven’t deployed agents. You’ve transferred decision rights into a system that doesn’t know it holds them — and can’t tell you what it did with them.


Deeplica is building the coordination infrastructure that makes agent-era decision rights traceable — the commitment layer that holds what every agent committed to, whether it was fulfilled, and what’s still open.

Eliran Keren

Eliran Keren

Founder & CEO of Deeplica — building the coordination layer that runs the operational side of your life. I write about AI systems, founder workflows, and what happens when you let AI handle the work you shouldn't be doing.