The CIO Job Is Now Where Agents Are Allowed to Act

Gartner says 40% of enterprise apps will embed agents by year end. PagerDuty's CIO says the job is deciding where that software may move without a person.

Conference room whiteboard split into allowed and not-allowed columns, a laptop and printed runbook on the table, no logos

Gartner’s line for 2026 is easy to repeat and hard to staff. By the end of this year, 40 percent of enterprise applications will have AI agents embedded, up from under 5 percent in 2025. Hexaware’s Siddharth Dhar walked through that forecast in a Digital Journal Q&A. The number is not a product review. It is a statement that “the app” now includes something that can take a step without waiting for a ticket.

On September 11, CIO Dive ran a guest post from Eric Johnson, CIO at PagerDuty. His version of the job is blunter than a transformation slide. When agents act in workflows, they make decisions, sit in ambiguity, and move without a human in the loop. Most CIOs, he wrote, are only now dealing with what that means. The title is no longer “keep the lights on on a timetable.” It is “where is autonomy allowed, and where is it banned.”

We already argued that autonomous AI is eating the transformation roadmap. This week’s news is not another tour of the architecture. It is the org chart catching up.

40 percent is a coverage number, not a success number

Dhar’s reading of Gartner is operational. If agents sit inside the apps people already open, IT spends less time walking humans through screens and more time watching outcomes, catching exceptions, and changing the process when the agent keeps failing the same way. That is a different on-call. It also needs interoperability and a live view of why a decision happened, not a quarterly deck.

None of that says the 40 percent will be good agents. We have a separate piece on why a different 40 percent of agent projects may be cancelled by 2027. Do not mash the two statistics. One is embedding. One is survival. You can embed a bad agent in a lot of software.

Channel Dive’s September 8 roundup, “AI deployments got expensive in 2026”, collected the receipts that transformation teams keep skipping. An SAP survey found enterprises saying AI helps with insights and customer interaction, not necessarily with saving money or time. A WitnessAI survey put IT and infrastructure as the top source of shadow AI for 47 percent of enterprise decision-makers. If the official program is expensive and the unofficial tools are coming from IT itself, the CIO is not looking at a user rebellion. They are looking at their own org bypassing the process they wrote.

Johnson’s actual claim

Strip the guest-post padding and Johnson is making three points.

First, well-documented processes are what agents need as context and constraints. If your incident policy lives in a slide and a wiki from 2019, the agent will improvise. People already hated that when the intern did it. An agent will do it at 2 a.m. across 400 accounts.

Second, the calendar changed. He contrasts an 18-month systems project whose benefits were hard to measure with agentic work that can launch and change inside a quarter, with results showing up fast. That speed is the feature and the failure mode. A quarter is enough time to automate a bad approval path into muscle memory.

Third, the CIO becomes an orchestrator who has to know the business well enough to say where autonomy is worth the blast radius. A wrong agent in a marketing draft is a mess. A wrong agent in production access is a different class of event. Those are not the same “AI use case.” Treating them as one program is how you get a single governance PDF that nobody can apply.

This is closer to safety engineering than to a tools bake-off. The question is not “do we have Copilot.” The question is “which workflows may close a ticket without a person.”

What “orchestrator” means on a Tuesday

It does not mean the CIO writes prompts. It means someone with budget and blame owns a list.

Allowed: agents that draft, classify, summarize, and queue. They can be wrong in ways a human still catches. Not allowed, until the runbook is real: agents that change IAM, move money, send legal mail, or page customers. In between: agents that act inside a sandbox with a hard spend cap and a rollback.

Dhar said teams will supervise outcomes instead of clicking through the workflow. Supervision is a job. If you fire the clickers and do not hire the reviewers, you have not transformed. You have removed the people who used to notice the weird invoice.

Accenture’s pitch this month is a thousand engineers in your office. That is another way of saying most companies cannot staff the review layer. Buying bodies does not write the allowed/not-allowed list. It just means someone else will write it in your templates.

The expensive part Channel Dive is circling is that companies still cannot say what one AI feature costs to run. If you cannot price a token path, you cannot decide whether an agent should retry. Retries are how a “helpful” classifier becomes a bill.

Shadow AI inside IT is a process smell

WitnessAI’s 47 percent figure is the one I keep coming back to. Security teams have spent two years talking about marketers pasting customer data into chatbots. The survey says leadership should look at infrastructure first. That matches what it feels like in shops where the official agent project is stuck in legal and the platform team already wired a model into the runbook because the pager would not stop.

Johnson’s “documented processes” line is the adult response. If IT needs shadow tools to do the job, the official process is too slow or too fake. Banning the tools without fixing the process just trains people to hide better. Putting the tools in a sanctioned sandbox with logging is slower to announce and faster to live with.

Gartner’s embedding forecast will make this worse, not better, because the agent will show up inside Salesforce and ServiceNow whether your architecture review finished. “We didn’t buy an agent product” stops being a defense when the vendor ships one into the app you already pay for.

A quarter is not a strategy

Johnson likes the quarterly loop. Fair, if the loop includes a kill switch. A 90-day agent pilot that cannot be turned off is not a pilot. It is a deployment with better branding.

Use the quarter to answer four questions in writing. What action is allowed without a human. What data is in scope. What the spend cap is. Who gets the transcript at 7 a.m. If you cannot answer those, you are not in the agentic era. You are in the demo era with production credentials.

The 18-month ERP hangover is real. People are right to want faster loops. They are wrong if they treat speed as proof. SAP’s “insights yes, savings maybe” finding is what you should expect when you add a layer that talks well and still needs reviewers.

What to tell the board without a transformation poem

Say the 40 percent number. Then say embedding is not ROI. Say the CIO role is now a permissioning job: which systems may act. Say IT showing up as the top shadow-AI source means the control plane is leaking from the inside. Say you will publish an allowed list, a banned list, and a cost per action for the three workflows that already have agents, before you fund the next ten.

That is digital transformation in the boring sense. Not a new operating model poster. A list of where software is allowed to move, written by someone who will still be there when it moves wrong.

Three workflows to permission this month

Pick workflows that already have volume, not greenfield demos.

Incident triage. An agent can cluster alerts, fetch the last similar incident, and draft the first comment. It should not page a customer or close a Sev-1. Johnson’s “process as constraint” belongs here: if severity definitions are tribal knowledge, the agent will invent a severity. Write them down first. Then let it draft.

Vendor intake. An agent can read a SOC 2 PDF and fill the questionnaire you already use. It should not sign the exception. Legal still owns the exception. This is the kind of embedding Gartner is counting: the agent lives inside the GRC app you already pay for, not in a new chatbot tab.

Finance close assistance. Summarize anomalies, not post journals. If your ERP vendor ships an agent that can post, that is a banned-list item until you have a dual-control flag. Embedding will arrive as a checkbox in a release note. Your allowed list has to exist before the checkbox does.

For each of the three, write the cost cap in dollars per day and the log destination. If finance cannot see the token bill, you will learn about it in a quarter when Channel Dive could have told you this year: people cannot say what one AI feature costs.

What not to copy from the guest posts

Do not copy “orchestrator” onto a LinkedIn banner and stop. Orchestrator without a list is just a nicer word for unaccountable. Do not copy Gartner’s 40 percent into a board slide as if it were your roadmap. It is a vendor-weighted forecast of where agents will appear, including places you did not choose.

Do not merge Johnson’s quarterly loop with Accenture’s thousand-engineer offering and call that transformation. One is a change cadence. The other is staff augmentation. You can use both. You still need the banned list.

Extreme’s Agent ONE Coworker for network teams, which showed up in IT press this week, is the pattern: every vendor will ship a coworker. If you accept all of them, you have a coworker sprawl problem that looks exactly like the shadow-AI problem WitnessAI measured inside IT. One sanctioned coworker with logs beats six with cute names.

The CIO job, this week, is still a list. Allowed. Banned. Priced. Logged. Everything else is a keynote.