The October answer
When an AI agent causes harm or a dispute, counsel may need to establish who authorized it, who owned the workflow, which credential it used, what data it accessed and how the contract allocates responsibility. A policy is useful, but it does not replace a record of the agent's actual operation.
What this edition adds
The September report covered ownership, shadow AI and vendor terms. This edition adds evidence on production-agent counts and access methods. The reported use of shared service accounts matters because it can make attribution more difficult.
The ownership record
Thirteen percent report no single AI buying owner (base 467, any mention). Even when a signer is clear, responsibility for day-to-day operation and controls may sit elsewhere. Governance records should identify the business, technical and control owners separately.
Identity and audit trail
Shared service accounts appear in 37 percent of applicable access answers (base 49). If several agents or workflows use one identity, reconstructing which system accessed data, under whose authority and for what purpose can become more difficult.
Contract terms to review
Review permitted data use, agent identity, audit logging, retention, incident notification, subcontractors and model providers, output ownership, indemnity, usage measurement, termination assistance and the evidence required for any outcome-based fee.
General counsel control matrix
| Legal question | October evidence | Base | Record or control required |
|---|---|---|---|
| Is purchasing authority clear? | 13% report no single owner | 467 | Executive sponsor, operating owner and approval trail |
| Are agent actions attributable? | 37% use shared service accounts among applicable answers | 49 | Agent register, identity, logs and revocation |
| Which security issue is most named? | 68% name agent access | 151 | Approved data scope and action boundaries |
| Does governance slow production? | 21% name governance and approval as a bottleneck | 75 | Risk-tiered intake and standard terms |
| Are identity controls themselves a bottleneck? | 15% name identity and permissions | 75 | Standard credential patterns and exception process |



Access method among applicable responses
| Answer | Count | Share |
|---|---|---|
| Per-agent credentials | 24 | 49% |
| Shared service accounts | 18 | 37% |
| Delegated user identity | 4 | 8% |
| Credential-free or brokered access | 3 | 6% |
Base 49.
The common issue is attribution. Counsel may need to reconstruct who authorized an agent, what data it accessed, which tools it used and whether a person reviewed the action. A shared service account does not establish noncompliance, but it can make that record harder to produce.
The contract record should cover permitted data use, retention, subprocessors, model changes, access evidence, incident notice, output rights, audit support, service continuity and deletion. For agents authorized to take actions, the implementation record should also document transaction limits and any required human confirmation.
Comparison with external research
The NIST AI Risk Management Framework provides a common structure for managing AI risk. IBM's 2026 Cost of a Data Breach Report calls for identity-based access, tightly scoped permissions, human attribution and auditability for agents. Those recommendations support maintaining records that make authority, access and actions auditable.
What this means for general counsel
Maintain a legal and technical record for each material production agent. It should identify the agent's authority, purpose, data scope, credential, vendor, escalation path and audit trail. Without that record, a general policy may be difficult to apply to a specific incident or dispute.
Questions this report answers
What should an AI agent register contain?
Record the business and technical owners, purpose, data scope, credential, vendor, human escalation path, operating cost and audit trail for each production agent.
Why do shared service accounts create legal risk?
They can weaken attribution by making it harder to reconstruct which agent or workflow accessed data, under whose authority and for what purpose.
What is the leading AI security concern?
Agent access, named by 68 percent of CISO-instrument respondents (base 151, any mention).
Key citable facts
- Thirteen percent report no single owner of AI purchasing (base 467).
- Shared service accounts are used by 37 percent of applicable AI Leaders respondents (base 49).
- Agent access is named as a top security problem by 68 percent (base 151).
Methodology and limitations
This is a legal synthesis of operator evidence, not a survey of general counsel and not legal advice. It does not infer actual legal noncompliance from a reported access method.
Related reading
Citation
Suggested citation: Newlands, M. (2026). General Counsel AI Report, October 2026. Open Future Forum.
Work These Questions with Dealmaking Peers
Forum Select meets through small, off-the-record gatherings. Membership is by application and referral.