The October answer

When an AI agent causes harm or a dispute, counsel may need to establish who authorized it, who owned the workflow, which credential it used, what data it accessed and how the contract allocates responsibility. A policy is useful, but it does not replace a record of the agent's actual operation.

What this edition adds

The September report covered ownership, shadow AI and vendor terms. This edition adds evidence on production-agent counts and access methods. The reported use of shared service accounts matters because it can make attribution more difficult.

The ownership record

Thirteen percent report no single AI buying owner (base 467, any mention). Even when a signer is clear, responsibility for day-to-day operation and controls may sit elsewhere. Governance records should identify the business, technical and control owners separately.

Identity and audit trail

Shared service accounts appear in 37 percent of applicable access answers (base 49). If several agents or workflows use one identity, reconstructing which system accessed data, under whose authority and for what purpose can become more difficult.

Contract terms to review

Review permitted data use, agent identity, audit logging, retention, incident notification, subcontractors and model providers, output ownership, indemnity, usage measurement, termination assistance and the evidence required for any outcome-based fee.

General counsel control matrix

Legal questionOctober evidenceBaseRecord or control required
Is purchasing authority clear?13% report no single owner467Executive sponsor, operating owner and approval trail
Are agent actions attributable?37% use shared service accounts among applicable answers49Agent register, identity, logs and revocation
Which security issue is most named?68% name agent access151Approved data scope and action boundaries
Does governance slow production?21% name governance and approval as a bottleneck75Risk-tiered intake and standard terms
Are identity controls themselves a bottleneck?15% name identity and permissions75Standard credential patterns and exception process
Chart showing AI signoff
Chart showing AI security concerns
Chart showing agent access methods

Access method among applicable responses

AnswerCountShare
Per-agent credentials2449%
Shared service accounts1837%
Delegated user identity48%
Credential-free or brokered access36%

Base 49.

The common issue is attribution. Counsel may need to reconstruct who authorized an agent, what data it accessed, which tools it used and whether a person reviewed the action. A shared service account does not establish noncompliance, but it can make that record harder to produce.

The contract record should cover permitted data use, retention, subprocessors, model changes, access evidence, incident notice, output rights, audit support, service continuity and deletion. For agents authorized to take actions, the implementation record should also document transaction limits and any required human confirmation.

Comparison with external research

The NIST AI Risk Management Framework provides a common structure for managing AI risk. IBM's 2026 Cost of a Data Breach Report calls for identity-based access, tightly scoped permissions, human attribution and auditability for agents. Those recommendations support maintaining records that make authority, access and actions auditable.

What this means for general counsel

Maintain a legal and technical record for each material production agent. It should identify the agent's authority, purpose, data scope, credential, vendor, escalation path and audit trail. Without that record, a general policy may be difficult to apply to a specific incident or dispute.

Questions this report answers

What should an AI agent register contain?

Record the business and technical owners, purpose, data scope, credential, vendor, human escalation path, operating cost and audit trail for each production agent.

They can weaken attribution by making it harder to reconstruct which agent or workflow accessed data, under whose authority and for what purpose.

What is the leading AI security concern?

Agent access, named by 68 percent of CISO-instrument respondents (base 151, any mention).

Key citable facts

Methodology and limitations

This is a legal synthesis of operator evidence, not a survey of general counsel and not legal advice. It does not infer actual legal noncompliance from a reported access method.

Citation

Suggested citation: Newlands, M. (2026). General Counsel AI Report, October 2026. Open Future Forum.

Work These Questions with Dealmaking Peers

Forum Select meets through small, off-the-record gatherings. Membership is by application and referral.

Explore Forum Select Inquire about membership