Strategy

70% say they run marketing agents. Governance has not caught up.

A control room of identical consoles still running, every operator chair empty

In Kana's survey of 225 US enterprise leaders, 70% said their companies run custom marketing agents in production. The same survey found disagreement over which executive function should own them. It did not measure whether those systems have named day-to-day operators, a distinction this article examines.

Two disclosures before the argument. The study comes from Kana, a vendor selling agentic marketing software, so it deserves directional trust rather than decimal-point trust. And this publication is produced with support from Docket, which sells software in this category; the argument below is ours, but you should weigh it knowing that.

Ownership is three jobs, not one

The survey reports that 40% of respondents think a Chief AI Officer should own agentic marketing strategy and execution, rising to 52% among AI leaders, while marketing executives favor keeping it in marketing or sharing it.

Read as a disagreement about org charts, that is a turf war. Read more carefully, it is a category error. "Ownership" is bundling three different jobs that belong to different people:

Business accountability. Who answers for the outcome the agent affects: pipeline, cost, customer experience. This belongs with the leader who already owns that number.

Technical operation. Who runs the thing day to day: monitors it, edits its rules, handles exceptions, stops it. This is an operational role, often marketing ops, and it is the one most likely to be unassigned.

Risk governance. Who sets shared standards, model risk policy, procurement rules, and audit requirements across every agent in the company. This is a legitimate central function, and a Chief AI Officer is a reasonable home for it.

Most of the argument in that survey dissolves once you separate these. Marketing should own the outcome and the operating decisions. A central AI or security function should own standards, shared infrastructure, and model risk. Those are complements, not competitors.

What the survey cannot tell us, and what we would want to know, is how many of those production agents have a named person in the second row. Our inference, offered as inference, is that this is the row most often empty, because it is the one no existing job description covers. It is also worth asking how many of those deployments are in production at all, since the adoption numbers in circulation measure something looser.

An unowned agent is a liability wearing a productivity badge

No serious company runs a payments system or a data warehouse without a named operator. Someone is on call, someone can roll it back, someone answers for it when it breaks.

Marketing has put revenue-touching automation into production: systems that talk to prospects, spend budget, and publish content. Where the operating row is empty, the failure mode is not that the agent fails. Everything fails. It is that the failure has no owner either: nobody notices quickly, nobody is authorized to stop it, and nobody is accountable for preventing a repeat.

The four-name audit

Whatever the org chart says, ownership is held by whoever holds four artifacts. This is our framework, not a survey finding. They are the same four objects an agent needs before it can own a loop with an end state.

The rulebook. A written, versioned statement of what the agent may do, what it may never do, and what evidence its outputs require. If the rules live in a prompt someone pasted eight months ago, nobody owns the agent.

The approval gate. A precise definition of what a human signs off on and what invalidates that sign-off. Approving "the campaign" means nothing; approving an exact, versioned artifact means something.

The exception queue. The single place the agent's uncertainty lands: ambiguous claims, novel situations, boundary cases. If exceptions go nowhere, the agent is resolving them silently.

The kill switch. A named person who can stop the system, plus written tripwires for when stopping is automatic. Not a Slack thread. A switch.

List every agent your team runs in production. For each one, write four names: who edits its rulebook, who approves its output, who reads its exception queue, who can turn it off.

If you can fill all four, you own that agent. If you cannot, you host it, and the gap is usually in the operating row rather than the org chart. Hosting is also what happens by default when the agent lives in someone else's hub.

Confidence is running ahead of testing

The same survey reports 76% of leaders calling their governance model ready for supervised AI decision-making, and 82% expecting agents to handle at least a third of routine marketing decisions within two years.

Those are self-assessments of readiness, collected largely before these systems have been stress-tested by real failure, and the study's own authors concede that confidence levels have not been tested in production. Our inference: a meaningful share of that 76% describes a governance document rather than a governance practice. The difference shows up the first time something goes wrong at an inconvenient hour.

That is not an argument against deploying agents. It is an argument for filling in the second row before the first incident, rather than after it.