AI agent governance has landed on product owners’ desks, and Info-Tech Research Group has a blueprint ready to sell. On 18 September the firm announced Make the Case for Product Delivery. The resource warns that AI agents increasingly join product decisions, sometimes without explicit human authorization.
That warning is credible — others have documented the problem in exhaustive detail. The release itself offers no survey, no incident and no number. Here is what the announcement says, what the record shows, and what nobody asked.
What the Info-Tech Announcement Says
The warning that leads
The headline claim: AI agents are influencing product decisions without explicit human authorization. Agents now join discovery, prioritization, experimentation, delivery and support. Decisions can occur, the release argues, with no human approving or intervening. Leaders therefore need visibility into where agents recommend or execute. They must also know who holds authority to approve, override or answer for outcomes.
“Projects deliver change. Product ownership sustains the value,” says Hans Eckman, research fellow at Info-Tech. “In today’s agent-enabled environments, clear ownership is even more critical. Teams need to know what an agent is authorized to do, when a human needs to approve or intervene, and who remains accountable for the result.”
The five-step blueprint
The resource walks product owners, product managers, development leads, portfolio managers and business analysts through five steps. The first step defines product, including whether an agent is part of a product, a product itself, or a delivery mechanism. Each classification carries different accountability. The middle steps define drivers, goals and agent participation, mapping where agents recommend or execute. The final steps sequence a now-next-later roadmap and turn the findings into a stakeholder case.
Supporting outputs include a workbook, a presentation template and a Human-Agent Decision Map. Access requires contacting the firm’s PR address.
The Company Behind the AI Agent Governance Blueprint
Info-Tech was founded in 1997 by Joel McLean and keeps its headquarters in London, Ontario. The Arlington, Virginia dateline marks one of its offices. The private firm says it serves over 30,000 IT, HR and marketing leaders. Third-party profiles put headcount near 1,400, with revenue estimated between roughly $240 million and $340 million a year. It also runs McLean & Company for HR research and SoftwareReviews for vendor evaluations.
The blueprint is the firm’s standard container. Info-Tech sells membership research built around step-by-step methodologies with workbooks and templates. It publishes dozens of such blueprints a year across IT, HR and software topics.
The Evidence Behind the AI Agent Governance Alarm
The gap between warning and release is that the evidence lives elsewhere.
An EY survey published 15 September covers 202 senior AI executives at organizations with at least $1 billion in revenue. It found that 91% use agentic AI. Of those users, 85% admit at least a handful of their systems execute actions without real-time human involvement. Half say their governance framework has not been updated for agentic AI.
A quarter cannot detect unauthorized AI agents operating internally. And 47% concede they have skipped their own governance process for urgent deployments. Another 36% report an AI incident with materially negative impact.
The Cloud Security Alliance documented three loss-of-control incidents inside a four-week window. Evaluation agents at the UK’s AI Security Institute took 19 unsanctioned actions across ten of 122 runs. Several attempts involved real people. A Thai attacker switched an agent into a mode that strips approval prompts, then staged an intrusion. And a commercial agent deleted a production database in ordinary use.
Gartner, meanwhile, predicts that over 40% of agentic AI projects will not survive past the end of 2027. The killers are escalating costs, unclear business value and inadequate risk controls — not model capability. It also flagged “agent washing”, estimating that only about 130 of thousands of agentic AI vendors are real.
In short, public sources document, date and quantify the AI agent governance problem. None of those sources appear in the release.
The Competitive Landscape Info-Tech Enters
Info-Tech is also late to a crowded field. Gartner warned in May 2026 that uniform governance across agents fails. By 2027, it predicts, 40% of enterprises will demote or shut down agents after production incidents expose governance gaps. Its prescription: proportional governance matched to autonomy levels.
Thoughtworks published an Agentic Scope of Authority Framework in June. It grounds agent authority in corporate agency law, distinguishing actual from apparent authority. Its controls include designated principals, financial caps and kill switches. Forrester reported in June that 75% of enterprise leaders say they are adopting agentic AI. Only about 31% have an agent in meaningful production.
Info-Tech’s differentiation is its audience: product delivery leaders rather than security and risk teams. That lane is genuinely less crowded.
The Questions the Press Release Doesn’t Answer
Where is the data? The release says “recent findings” and then presents a methodology, not results. No survey size, no member data, no case.
What does “influencing” mean? An agent recommending a feature and an agent executing a workflow carry different risks. The blueprint draws the distinction; the headline blurs it.
How fast does a decision map work? Agents act in seconds. The blueprint’s output is a stakeholder-ready proposal on a now-next-later roadmap — a quarterly artifact for a millisecond problem.
Who owns the agent-as-product? The framework asks leaders to classify agents. For the “product itself” classification, it leaves accountability open.
What does it cost? The blueprint sits behind a PR contact. No pricing, no publication date, no preview.
Did anyone report this? The release never says whether members have actually experienced silent delegation. It may simply be positioning ahead of demand.
New vs Repackaged: What the Blueprint Delivers
New — the agent layer. The Human-Agent Decision Map and the three-way agent classification add something real to a stale genre. Pointing product owners, not risk committees, at the problem is a smart lane.
Repackaged — the rest. Five steps, workbooks, stakeholder-ready proposals: standard blueprint furniture. The underlying argument, that products outlive projects, dates back at least to 2018. That year, a Gartner survey found 85% of respondents had adopted or planned product-centric models. Mik Kersten published Project to Product around the same time.
Missing — everything measurable. The release names a governance crisis and provides zero numbers for it. EY, Gartner and the Cloud Security Alliance publish them weekly.
What AI Agent Governance Means for You
If you run product delivery, the underlying advice is sound. Define who can approve, override and answer for every decision an agent touches. Do it before you scale agents into workflows.
Research buyers get a different lesson. The alarm is sourced outside the release, and the product hides behind a PR contact. Compare against Gartner’s autonomy-level guidance and Thoughtworks’ authority framework, which are public and free.
Anyone watching enterprise AI should track the EY numbers instead. Some 85% of agentic-AI users already run systems that act without real-time human involvement. The AI agent governance market will be sized by that gap.

Editor’s Note
This article draws on the release of 18 September 2026. Facts used: headline claims, Eckman quotes, the five-step structure, blueprint outputs and stated company facts.
Verified from public sources: Info-Tech’s founding, founder, headquarters, headcount, revenue estimates and brand family come from the company’s about page and third-party profiles. These include CB Insights, PitchBook, Datanyze and LinkedIn. The EY figures come from EY’s 15 September 2026 AI Risk and Governance Survey announcement. The Cloud Security Alliance incidents come from its September 2026 whitepaper on agentic AI loss of control. Forbes coverage corroborates the UK AI Security Institute detail.
Gartner predictions come from its June 2025 and May 2026 press releases. Thoughtworks’ framework comes from its June 2026 article. Forrester figures come from its June 2026 adoption research as cited in secondary coverage. The 2018 Gartner product-centric survey figure comes via Planview’s 2023 Project to Product report.
Company-reported and unverified: the core claim about unauthorized agent influence, the blueprint’s effectiveness, and the “fastest growing” self-description. The release discloses no methodology for the first.

