The operating-model mandate
The Modern COO: How Agentic AI Is Forcing Boards to Rethink Governance
When AI stops being a tool the organisation uses and starts performing its work, the binding question is no longer who owns AI. It is who owns the redesign of the company.
By Christopher Hughes
Personal views of Christopher Hughes, independent of any employer, customer, or third party.
AI capability should not be owned by the technology function. It is an operating capability wearing a technology title.
When a board debates whether AI should be driven by the CIO or the CEO, it is answering a downstream question, because the reporting line sits beneath a mistake no reporting line can fix.
The mistake is simple. AI gets treated as a technology, so its ownership routes to the technology function. That was defensible while AI was an analytical tool the technology function provisioned, and it stopped being defensible the moment AI systems began to execute work, make bounded decisions, call enterprise systems, and coordinate multi-step processes. At that point the binding question changes from “who owns AI?” to “who owns the redesign of the company when part of its work is performed by software rather than people?”
That is operating territory. The capability belongs to the executive whose primary mandate is how work gets done, whether that person carries the title Chief Operating Officer, the title Chief AI Officer, or an enlarged remit under another name. The CIO still owns the technology platform, and that remit grows rather than shrinks. One view says AI is infrastructure, so the CIO should own it. That is where most boards land, and it is the wrong place, because owning the platform is not the same as owning the redesign of the work performed on it.
The gap that no reporting line has closed
McKinsey's 2025 global research found that 78% of organisations use AI in some form, yet only 21% have fundamentally redesigned even some workflows, and only 1% describe their deployment as mature.[1][2] Adoption is near-universal and redesign is rare. Something structural stops the adoption from becoming impact.
Bain's 2026 survey of global companies measuring AI cost savings found that 37% targeted savings of 11% to 20% but only 29% achieved that level, and that 44% plan to fund the next wave of AI from savings that have not yet arrived.[3] Bain names the cause directly: responsibility for AI outcomes is split almost evenly between IT, business functions, and central teams, with no clear owner in most organisations.[3] The returns gap is the ownership gap, and it will be the leading cause of failed agentic AI programmes in the next two years.
Gartner puts a forward number on the same failure, forecasting that more than 40% of current agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls.[4] None of those is a technology failure. The work was never redesigned, the value was never modelled, and the authority was never bounded. Who owns closing that gap is the question everything below turns on.
What changed when AI started doing the work
The familiar complaint is that firms deploy AI on top of broken processes. That is true, but the shift underway is larger. AI stopped being a tool the organisation uses and became a capability that performs the organisation's work.
Digital business changes what the organisation does; autonomous business changes how it does it.[5] Gartner's 2026 survey found that 80% of CEOs expect AI to force a high or medium degree of change to their operational capabilities, and while 54% say automation is currently limited to specific tasks, only 13% expect to remain at that level by the end of 2028.[5] The centre of gravity is moving from what technology the firm provisions to how its work is performed.
An AI agent is a focused tool built to solve a specific problem, handle a routine workflow, or make a decision within a defined scope. Agentic AI is the broader capability framework that lets these agents plan, decide, and coordinate as systems rather than one-shot prompts. The distinction is load-bearing: a chatbot answers a question while an agent executes a chain of work, and the leadership questions diverge sharply at that boundary.
MIT Sloan Management Review and BCG found in 2025 that 76% of executives view agentic AI as more like a coworker than a tool, and concluded that the traditional separation of technology and strategy becomes untenable, because agentic AI reshapes process design, role structure, decision-rights allocation, and accountability culture at once.[6] A coworker is not something a technology function provisions and walks away from. A coworker is something an operating function manages.
The mistake in the reporting-line debate
The default wiring is technology, and the data shows it. Foundry's 2025 survey found that 14% of organisations employ a Chief AI Officer, of whom 40% report to the CEO and 24% report to the CIO, with the COO not cited as a meaningful reporting line.[7] The same survey finds the role only now stepping out from the CIO's shadow towards the CEO, which leaves it wired to the technology function or the top of the house, never to operations.[7] The role is proliferating fast, and IBM's 2026 study records uptake across surveyed organisations rising from 26% to 76%, but the wiring beneath it has not been rethought.[8]
The implicit logic runs: AI is technical, technical things belong to the CIO, therefore AI belongs to the CIO. Each step is reasonable. The conclusion is still wrong, because it confuses the technology platform with the work performed on it. The platform an agent runs on is technical. What the agent is authorised to do, to whom, with what recourse, is not.
Air Canada is the small, early illustration of what the platform view misses. In November 2022 the airline's customer-facing chatbot told a passenger he could buy a full-price bereavement fare and claim a retroactive discount, which the airline's policy did not permit.[9] When the passenger sought the refund, Air Canada argued the chatbot was a separate legal entity responsible for its own statements, and in February 2024 the British Columbia Civil Resolution Tribunal rejected that argument, holding the airline liable for negligent misrepresentation by its own AI system.[9] The failure was not a bad model. No-one had decided what authority the chatbot held over binding representations about policy.
Scale that from a chatbot answering a question to an agent executing a chain of work across enterprise systems. If an unbounded chatbot could create binding legal liability from a single wrong sentence, an agent that raises a credit memo, adjusts a forecast, or actions a customer request makes the authority-boundary question acute rather than optional. Deciding what an agent may do, and where a human must stand, is the design of how work is done. That is operating work, and it is the first of four things the modern operating leader owns.
What the operating leader actually owns
Whether the title is Chief AI Officer or an enlarged COO matters less than the accountability set beneath it. That accountability set is the operating-model mandate: ownership of the redesign of how work is performed once part of the workforce is software. Drawing its edges precisely keeps it from being confused with the two functions on either side of it.
The mandate is bounded on three sides, not two. On one side sits AI strategy, the decision about what to build and where to aim, which in many firms lives with a Chief Data and Analytics Officer; Gartner found that 70% of CDAOs hold primary responsibility for AI strategy and the AI operating model.[10] On the other side sit the platforms, security, integration, and architecture the CIO owns. The operating-model mandate is neither. It decides which work is rebuilt, who holds authority within it, how the mixed workforce runs, and what controls make it safe in production.
The distinction from the CDAO matters because the two are routinely conflated. Choosing which model to deploy is a strategy decision. Choosing that a credit memo will now be drafted by an agent and reviewed by a named human with the authority to reject it is a work-design decision. When a board hands both to a strategy or analytics function, the aiming gets done and the rebuilding does not.
Work redesign is the first part of the mandate: deciding which workflows are rebuilt around human-agent collaboration rather than having agents bolted onto the existing process. Intelligent Ops is the operating model that closes the adoption-impact gap by rebuilding processes rather than deploying AI on top of them. DBS Bank runs it as a named programme. Its Operating Model Transformations rebuild specific domains of work around human and AI collaboration, and in 2025 the bank exceeded its target of six, with credit memos now drafted by more than 70 agents and reviewed by credit managers.[11]
Group COO Derrick Goh, appointed in April 2025 with a remit covering both operations and transformation, is directly accountable for that delivery, and DBS attributes roughly S$1 billion of economic value from AI and analytics in 2025, up from S$750 million in 2024.[11][12] The work was owned as operating redesign, not a tooling rollout.
Authority reallocation is the second part: deciding who decides what across people and agents. Human-on-the-Loop Oversight routes human judgement by consequence severity, reversibility, and model uncertainty rather than inserting an approval gate at every output. The UK Information Commissioner's Office sets the standard the reallocation must meet, requiring meaningful review by reviewers with the knowledge, authority, and independence to actually challenge an outcome.[13] That is different from traditional Human-in-the-Loop review, which more often than not becomes a ceremonial sign-off. Deciding which decisions an agent makes and which escalate to a human with real authority is a design of accountability, and it changes who is answerable when work goes wrong.
Running a mixed workforce is the third part: managing capacity, coordination, and accountability when some of the workers are software. Salesforce shows the shape. Deploying its own agent internally for customer support, the company reports it handled more than 1.5 million requests within a year with 83% resolved without human escalation, took roughly $100 million of cost out of the support function, and moved many support staff into professional services, forward-deployed engineering, and sales roles as it rebalanced the function.[14] Harvard Business School published the deployment as a case study, which lends the direction independent weight even where the vendor's own figures cannot be audited.[15]
The binding question was not “deploy the agent” but “redesign the work so humans do what only humans can do, and decide who is accountable for the people whose work changed.” That is span-of-control design, and part of the span is now software.
The fourth part is the operating controls that make the workforce safe to run in production. AgentOps is the lifecycle discipline of observability, evaluations, drift detection, incident classification, threshold governance, change governance, and safe rollback that is to AI agents what DevOps is to software. It is owned in partnership with the CIO, who provides the platform on which it runs, and it aligns to standards such as the NIST AI Risk Management Framework.[16] The operating leader should own the metrics that sit on top of AgentOps. The controls are shared work. The other three parts of the mandate are not, and that is where the boundary with the CIO has to be drawn honestly.
Scale is not the same as owned redesign
JPMorgan is the case that shows the risk. The bank rolled out its LLM Suite to 140,000 employees by late 2024 and past 200,000 within eight months, and it now runs more than 450 AI use cases in production.[17] At the Barclays financial services conference in September 2024, then COO Daniel Pinto put a number on the ambition, projecting $1.5 billion to $2 billion in annual business value from AI.[17] By February 2026, CEO Jamie Dimon confirmed the bank already had large redeployment plans for employees whose work AI was changing.[18]
That is deployment at a scale few firms will match, and it is exactly why the risk is worth naming. The $1.5 to $2 billion is a disclosed target, a forward projection from a named executive, not a delivered and audited outcome. Deployment of the tool does not convert into that value on its own. The value comes from redesigned workflows, reallocated authority, and a mixed workforce that has learned to run, and none of those follows automatically from putting the LLM Suite on 200,000 desks.
The public disclosures describe the scale and the target but not the owner. They set out the deployment count and Pinto's value projection, and they record Dimon's redeployment plans, without naming who holds the redesign as a single operating-model mandate: who owns the redeployment decisions, who sets the authority boundary for the LLM Suite, and who is answerable when an agent acts on a customer.[17][18] This is not a claim that JPMorgan is failing or that no-one owns the work; a bank operating at this scale plainly has capability and intent. It is an observation about what the disclosed structure names and what it leaves unnamed, and that unnamed ownership is where a large ambition can stall.
The contrast with Target and DBS sharpens the point. Both placed the redesign inside a named operating leader's remit, so scale and redesign advance together. JPMorgan has placed enormous capability into production while the ownership of the redesign of work as a whole remains publicly unnamed, which is the precise condition under which a firm reaches deployment scale without reaching the operating redesign that turns it into the disclosed target. A board that reads the deployment count as evidence the ambition is secured has mistaken the easier achievement for the harder one.
What the CIO still owns, and why it matters more
BCG argues, correctly, that governing how a company uses AI to build solutions, at what cost, and for what purpose demands a stronger CIO, not a displaced one.[19] Platforms, infrastructure, integration, security, architecture, model controls, and technical governance are engineering disciplines, and they concentrate more risk as AI moves into operations, not less. Shadow AI, where business units deploy AI outside central oversight, is controlled only through CIO-level technical governance. That remit grows.
The concession is real and it is also insufficient. Flawless platforms, airtight security, and clean integration are necessary for AI to work and they are not sufficient for AI to pay, because none of them redesigns a workflow, reallocates authority, or runs a mixed workforce. A firm can have all three and still sit inside the 21% redesign figure. BCG's own framing puts the split at roughly 30% technology and 70% people and organisation.[20]
The failure mode is not the CIO owning too much. It is the two mandates confused or fused. When the platform and the redesign are held by the same function, the redesign is starved, because a technology function optimises the systems it understands and under-invests in the operating change it was never built to lead. Keeping the two distinct and partnered is the design choice that determines whether the gap closes, and it is a choice only the board can make.
The mixed workforce is an operating problem, not an HR one
Handing the workforce question to HR fails because the questions are operating questions. What is the throughput of a process that is 60% agent and 40% human? What is the escalation path when an agent hits the edge of its authority, and who is accountable for its output when the span of control a manager holds is now part software? None of that is answered by a headcount plan.
The trust data shows how far the reallocation lags the capability. Only 6% of companies fully trust AI agents to handle core business processes, with 43% trusting them only for limited or routine tasks and 39% restricting them to supervised work.[21] Bain finds only 7% of organisations run fully autonomous agents in production, while 38% require human approval and 32% use guardrails with exceptions.[3] The capability is running ahead of the authority design, and closing that distance safely is active operating management.
Forty per cent of enterprises will demote or decommission autonomous AI agents by 2027, driven by governance gaps found only after production incidents, because governance was applied as a binary of locked-down or fully trusted regardless of the agent's autonomy level or the consequence of its failure.[22] This is distinct from the cancellation figure earlier: cancellation kills the project before value, demotion pulls back a live agent after an incident. The demotion figure is the cost of running a mixed workforce without designing its authority first.
Klarna reduced headcount from a peak of around 7,000, on the chief executive's own account, to roughly 3,000, replacing much of its customer support with an AI agent it said did the work of 700 people, before its CEO acknowledged to Reuters ahead of the firm's September 2025 listing that it had “over indexed a little bit” on cost and was working to “course correct” back towards service quality.[23] Klarna did not fail because AI cannot do customer service. It automated before it had designed the operating model that distinguishes what the agent handles unilaterally from where human judgement is required, and the course correction was an operating-model decision, not a technology one.
Designing the mandate: the board agenda
The board's first job is to refuse to leave the redesign unowned. Whether the mandate lives with a titled Chief AI Officer or an enlarged COO is secondary; getting the accountability whole and placing it with the executive who owns how work is done is primary. Target is the clearest signal. Its multi-year Enterprise Acceleration Office, launched in 2025 under COO Michael Fiddelke, was framed explicitly around speed, agility, reduced complexity, and faster decisions rather than tools, and Fiddelke was subsequently elevated from COO to CEO.[24] The leader accountable for the operating-model redesign was promoted to run the company.
The platform genuinely is CIO territory and it is growing, but the platform is not the value, and the redesign of work performed on it is a different accountability the technology function is not structured to hold. In many firms the CDAO owns AI strategy and the analytics operating model; folding the operating-model mandate into that remit would be a mistake, because owning what the firm builds is not the same as owning how the firm's work is rebuilt around it. Gartner forecasts that by 2027 three-quarters of CDAOs not seen as essential to AI success will lose their C-level position, which describes a role under exactly this pressure: the market is beginning to ask whether AI leadership delivers business outcomes or manages a function.[10]
The third objection, that the COO role is itself being disrupted by AI, argues the opposite conclusion from what its proponents intend. IBM finds that 77% of leaders expect talent and technology roles to converge.[8] When AI takes over the execution layer, someone must own the enterprise as a system of work precisely because part of the work is now software. The remit is enlarged, not dissolved.
The board should scope the mandate around four decisions and one metric. The four decisions are the parts of the mandate: which workflows are redesigned, how authority is reallocated between people and agents, how the mixed workforce is run, and how the operating controls are shared with the CIO. The one metric is impact, not deployment. A mandate measured on agents shipped will ship agents and miss the 21%; a mandate measured on workflows redesigned and value delivered will close the gap the deployment metric hides.
The durable advantage is operating-model authority itself. A competitor can buy the same models in weeks and stand up the same platform in a quarter. It cannot replicate two years of redesigned workflows, calibrated authority boundaries, and a mixed workforce that has learned to run, because that is accumulated operating discipline rather than purchased capability, and it compounds.
So the Monday-morning question for the board is not who owns AI. When an agent in your company next executes a chain of work, calls your systems, and makes a bounded decision, who is accountable for what it was authorised to do, and is that person the one who owns how your work is done? If the honest answer is that the redesign sits inside a function built to run the platform, or a function built to set the strategy, then the mandate is unowned, and the gap between adoption and impact is where it will stay.
Sources
- [1] McKinsey & Company, “The State of AI: How Organizations Are Rewiring to Capture Value,” March 2025.
- [2] McKinsey & Company, “Superagency in the Workplace: Empowering People to Unlock AI's Full Potential at Work,” 28 January 2025.
- [3] Bain & Company, “Your AI Budget Is Growing. Your Returns Aren't. Here's Why,” 1 June 2026.
- [4] Gartner, “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,” press release, 25 June 2025. Analyst: Anushree Verma.
- [5] Gartner, “Gartner Survey Reveals 80% of CEOs Say Artificial Intelligence Will Force Operational Capability Overhauls,” press release, 23 April 2026.
- [6] MIT Sloan Management Review and Boston Consulting Group, “The Emerging Agentic Enterprise: How Leaders Must Navigate a New Age of AI,” November 2025.
- [7] Foundry / CIO, “State of the CIO Survey 2025,” February 2025.
- [8] IBM Institute for Business Value and Oxford Economics, “CEO Study 2026,” 4 May 2026.
- [9] Moffatt v. Air Canada, 2024 BCCRT 149, British Columbia Civil Resolution Tribunal, February 2024.
- [10] Gartner, “Gartner Survey Finds 70% of CDAOs Are Responsible for Artificial Intelligence Strategy and Operating Model,” press release, 12 May 2025.
- [11] DBS Bank, Operating Model Transformations and 2025 AI outcomes, DBS 2025 Annual Report.
- [12] DBS Bank, “Group COO appointment (Derrick Goh, effective 1 April 2025)”; DBS 2024 Annual Report, CIO Statement.
- [13] Information Commissioner's Office, “Human Review,” Data Protection Audit Framework: Artificial Intelligence Toolkit, accessed 2026.
- [14] Salesforce, “From Pilot to Playbook: What We Learned from Our First Year Using Agentforce,” 2025.
- [15] Harvard Business School, “Salesforce Agentforce: The Limitless Workforce,” HBS Case 125-096, April 2025.
- [16] National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” January 2023, and Agentic Profile extensions.
- [17] Matt Ashare, “JPMorgan Chase Rolls Out Generative AI Assistant to Employees,” CIO Dive, 2024 (with Barclays Global Financial Services Conference remarks by Daniel Pinto, September 2024, on the $1.5bn–$2bn AI value projection).
- [18] Hugh Son / CNBC, “JPMorgan CEO Jamie Dimon Says AI Is Reshaping the Bank's Workforce,” 24 February 2026.
- [19] Boston Consulting Group, “Why We Still Need a CIO in the AI-First Era,” June 2026.
- [20] Boston Consulting Group, “Design Your Company for AI, Not AI for Your Company,” 2026.
- [21] Harvard Business Review Analytic Services and Workato, “Enterprise Agentic AI: The Foundations of Trust,” December 2025.
- [22] Gartner, “Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure,” press release, 26 May 2026.
- [23] Supantha Mukherjee and Echo Wang, “Sweden's Klarna shifts AI focus from cost cuts to growth,” Reuters, 10 September 2025.
- [24] Target Corporation, “Target Corporation Announces Multi-Year Enterprise Acceleration Office,” press release, 21 May 2025.
Put this paper to work
Discuss what this changes for your organisation