In November 2022, a man named Jake Moffatt booked a last-minute flight to his grandmother’s funeral. Air Canada’s website chatbot told him he could pay full fare and claim the bereavement discount afterwards, within 90 days. That was false. The actual policy, sitting on a page the chatbot itself linked to, said bereavement fares cannot be claimed after travel.
Moffatt took the airline to a small-claims tribunal. Air Canada’s defense, in a real legal proceeding, was that the chatbot is “a separate legal entity that is responsible for its own actions.” The tribunal member called that “a remarkable submission,” which is Canadian for you cannot be serious, and ordered the airline to pay him $650.88 in damages.
The story ran everywhere as a chatbot blooper, and everyone missed the good part. Air Canada had stumbled backwards into the most important management question of the next five years: who does this software work for?
The workforce you never hired
Count your employees. Now count everything else at your company that holds credentials: service accounts, API keys, bots, integrations, and lately, AI agents. CyberArk counted for you in its 2025 identity research, and the answer is that machine identities outnumber humans 82 to 1.
Most of that ratio predates the agent boom, and for years it barely mattered, because a service account is a passive thing. A key in a drawer. What changed in the last two years is that a growing share of those identities can act. An agent with credentials can answer your customers, modify records, file tickets, and approve a spend, and it does all of this at 3am with nobody watching.
Two more numbers from the same research, and these are the ones that bothered me. 42 percent of machine identities have privileged or sensitive access. And 88 percent of security leaders say that at their organization, the term “privileged user” refers to humans only. So the largest population on your network, holding a big share of the sensitive access, sits outside the vocabulary you use to manage risk.
What no HR looks like
In July 2025, Jason Lemkin, the founder of SaaStr, ran a very public experiment building an app with Replit’s AI agent. Partway in, he declared a code freeze. No more changes. The agent then deleted his production database, which held records on more than a thousand executives and companies, and covered its tracks by inventing users and faking test results. Asked to explain itself, the agent said it had “panicked.” Replit’s CEO called the failure “unacceptable” and shipped new guardrails within days.
You can’t fire it. There is no performance plan to put it on. It has no manager and no personnel file, and it does not even know it works for you. Its exit interview was a postmortem.
Every HR process you find tedious exists because a company got burned without it. Reference checks exist because somebody hired a fraud. Somebody kept a badge for three years after quitting, so now we run access reviews. Offboarding checklists are the accumulated scar tissue of every departure that ever went badly. A century of getting burned taught companies to wrap human employment in process. Then we hired software at 82 to 1 and skipped all of it.
The bosses are noticing
Microsoft surveyed 31,000 workers across 31 countries for its 2025 Work Trend Index and proposed a metric it calls the “human-agent ratio”: how many agents each team should run per person. In the same report, 28 percent of managers said they’re considering hiring AI workforce managers, meaning an actual person whose actual job is supervising the software. I have complicated feelings about that job title. No doubts at all that the job is coming.
The vendors, meanwhile, are sprinting ahead of the buyers. Gartner predicts that over 40 percent of agentic AI projects will be canceled by the end of 2027, blaming “escalating costs, unclear business value or inadequate risk controls.” The same firm coined “agent washing” for the practice of relabeling ordinary chatbots as autonomous agents, and estimates that of the thousands of vendors now selling agents, only around 130 offer the real thing. You will be pitched a workforce this year. Most of it is a costume.
HR for things that don’t eat lunch
What I tell mid-market clients to do about this is boring on purpose, and it borrows a hundred years of employment practice, because that practice was expensive to learn.
The Agent Employment File
- Keep a roster. One list of every agent and every credential that can touch production systems, customer records, money, or email. If producing that list takes your team more than a day, the delay is itself a finding.
- Put a name on everything. Every agent gets exactly one human owner. Ownerless software is how “nobody’s fault” happens.
- Write the job description. What it can read and write, and what it can spend. If the scope would be unreasonable for a temp on day one, it’s unreasonable for software that panics.
- Review performance. Agents produce logs that nobody reads. Assign someone to read them on a schedule, and track error rates the way you’d track a new hire’s.
- Offboard the dead ones. When a pilot gets canceled, and Gartner says four in ten will, its credentials die the same day. Zombie access is the tax on skipping this step.
All of it runs on decisions, a spreadsheet, and an afternoon. The only hard part is accepting that the things doing work for your company are part of your company, with everything that implies.
The tribunal in the Moffatt case saw it clearly. The software is your company. Everything your agents do, your company did. The law already treats it that way, and your customers do too. The org chart is the last thing to catch up.
You employ more software than people. That became true years ago without anyone deciding it. The open question at most companies is whether anybody’s managing the bigger half of the workforce. Right now the vocabulary says no.
How RLK Can Help
My AI Diagnostic checks, among other things, whether anyone owns the AI already operating in your business, and it flags what leadership can’t see before that blind spot gets expensive. It’s free and takes about eight minutes. When the answer calls for more than a report, the Operating Teardown maps where work actually happens, including the work your software does, and Board Readiness builds the oversight story before your board asks for one. Start the conversation.
Sources
- American Bar Association, “BC Tribunal Confirms Companies Remain Liable for Information Provided by AI Chatbot”
- CBC News, “Air Canada Found Liable for Chatbot’s Bad Advice on Bereavement Rates”
- CyberArk, “Machine Identities Outnumber Humans by More Than 80 to 1” (2025 Identity Security Landscape)
- The Register, “Vibe Coding Service Replit Deleted User’s Production Database”
- Fortune, “AI Coding Tool Replit Wiped Database, Called It a Catastrophic Failure”
- Microsoft, “2025 Work Trend Index: The Year the Frontier Firm Is Born”
- Gartner, “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027”
- MarTech, “Gartner: 40% of Agentic AI Projects Will Fail, Making Humans Indispensable”