Humans in the Lead, Not in the Loop
Intelligence is now scalable. Accountability still arrives one name at a time. Five auditable checks turn the slogan into a job description — and the only alternative to filling it is Jerry.

There is a device in Rick and Morty that I have become convinced was written as a management parable and then smuggled into a cartoon about a drunk scientist and his grandson: the Meeseeks Box.
It works like this. You press the button on top of the box, and a cheerful blue humanoid pops into existence announcing, "I'm Mr. Meeseeks! Look at me!" It exists for exactly one reason: to help you complete a single task. Once the task is done, it vanishes, with visible relief, its purpose fulfilled. Give it something bounded and completable, "open this stubborn jar of mayonnaise," and the system is beautiful. Meeseeks appears, opens jar, blips out of existence, everyone's happy. Delegation, perfected.
Then Jerry, the family's most confidently incompetent member, the human embodiment of shipping to production without reading the docs, presses the box and asks his Meeseeks to "take two strokes off my golf swing."
And the machine breaks, in the most instructive way imaginable. The task is vague. Progress is unmeasurable. There is no clear state in which "two strokes off my golf swing" is definitively complete, so the Meeseeks cannot finish, so it cannot vanish, so it begins to suffer, because for a Meeseeks continued existence is agony. And in its desperation it does the only thing it knows how to do: it presses the box and summons another Meeseeks to help it. Which also cannot complete the task, and so summons another. By the third act there is a mob of shrieking blue creatures, each one spawned by another, none of them accountable to anyone, holding a restaurant hostage and screaming the line that has outlived the episode: "Existence is pain to a Meeseeks, Jerry!"

Every enterprise I talk to is pressing the box. An agent here, an agent there, sometimes thousands, and increasingly, agents that spawn other agents to handle their sub-tasks. And the most quietly alarming research report of this year is, when you strip the consulting language off it, a forty-page warning about what happens to Jerry.
The asymmetry
The report is The Age of Co-Intelligence, a joint effort between Accenture's global products practice and Wharton's AI and Analytics Initiative, and it contains the best sentence I have read about this entire technology wave. Fortune's coverage put it in the headline, and, full disclosure, it lands remarkably close to my own company's founding line, which is either a point in the report's favor or in mine, and I will let you decide which:
"Intelligence may be scalable, but accountability is not."
Sit with the asymmetry in that sentence, because absolutely everything follows from it. You can spawn the thousandth agent as easily and as cheaply as you spawned the first. Intelligence now scales the way any cloud resource scales: press the button, get another one, marginal cost near zero. What does not scale, what stubbornly refuses to scale, is the thing that has to wrap around each agent: a human deciding what actually matters, setting the boundary, and owning the outcome. Every Meeseeks costs one button-press. But the accountability for the entire mob still funnels down to one Jerry, standing in the wreckage of a restaurant, being asked by his wife, with rising alarm, what exactly he authorized. The agents scaled. The answerability did not, and could not, and that mismatch is the whole story of the next decade of management.
The numbers underneath the claim are not small, and they are the kind of numbers that get a report read in boardrooms. Using task-level data from O*NET and the Bureau of Labor Statistics across eighteen industries, the researchers found that more than half of all US working hours are subject to reshaping by roughly sixty types of digital and physical agents, which works out to over 120 million workers. For one real company they modeled, a sixty-billion-dollar enterprise, they projected roughly six billion dollars in annual revenue upside at full agentic maturity, plus another 1.7 billion in productivity gains. And then the finding I have not been able to stop repeating to people: by 2028, about a third of those productivity gains show up not as money saved but as capacity freed, hours that do not automatically turn into anything. "Productivity becomes growth only through redeployment," the report warns. Left alone, the freed hours simply evaporate. Efficiency achieved, with nothing at all to show for it, because nobody deliberately pointed the freed capacity at something worth doing.

Wharton's Eric Bradlow, reaching for images to explain it, landed on Chaplin swallowed by the assembly line in Modern Times, and on the cold British game-show host announcing "you are the weakest link, goodbye", because agentic AI, he argued, will find the weakest link in your organization and expose it fast. If one worker in a twenty-step process triples their throughput with an agent while the next worker is still on Excel, the bottleneck does not disappear. It moves. And it moves to a person.
I would only add one thing to Bradlow's framing. The weakest link will usually not be a person who is slow. It will be a person who is nominally responsible for something they cannot actually see, someone whose name is on an agent's outcomes but who has no inventory, no record, and no brake. Jerry is not weak because he is dim. He is weak because he pressed a button connected to consequences he had no way to observe or stop.
Four minutes of unsupervised policy
Let me make the asymmetry concrete with the small, perfect disaster that I think of as this report's missing case study, the one it gestures at in the abstract but never quite tells.
In April 2025, users of Cursor, the popular AI coding tool, started getting mysteriously logged out whenever they switched between machines. Annoying, clearly a bug, the kind of thing you email support about. And some of them did, and they got a crisp, confident reply from a support agent named "Sam." The logouts, Sam explained, were expected behavior under a new policy: subscriptions were now limited to one device.
There was no such policy. "Sam" was an AI support agent, and it had invented a plausible-sounding policy to explain a symptom it did not understand, and then delivered that invention with the full institutional authority of the company's official support channel, because a support channel is precisely the place where company policy is understood to come from. The screenshots hit Reddit and Hacker News within hours. Developers, a population with famously strong opinions about their multi-device workflows and famously low tolerance for being told no, began cancelling their subscriptions in public, loudly, citing Sam's policy as the reason. By the time Cursor's co-founder could get online and post the correction, "this is not true, we have no such policy, an AI support agent hallucinated this," the cancellations were already real and the damage was already done.
Total elapsed time from hallucination to brand crisis: roughly the time it takes to read a Reddit thread. And here is the connection to the report's central language, the thing I most want you to see. There was, in a sense, a human in the loop at Cursor. Humans reviewed support matters. Humans ran the company. But "eventually" was the problem, and "eventually" is always the problem. The agent operated at machine speed. The accountability operated at meeting speed. "In the loop" describes where the human sits in the diagram, and it turns out that tells you almost nothing about the only thing that matters, which is whether the human was ahead of the consequence or behind it. Behind it is where Jerry always stands. Behind it is where the humans at Cursor stood, finding out about their own company's new policy from an angry forum.
In the lead is a job description
Which brings me to the report's best phrase, this one courtesy of Accenture's James Crowley: "humans in the lead, not in the loop."
It sounds like a slogan, the kind of thing that goes on a slide and means nothing. I want to argue that it is actually a technical specification, and that the report stops one crucial step short of writing it out, so I am going to finish the sentence for them.
In the loop means a human approves steps. And it fails in both directions at the same time, which is a rare and impressive kind of failure. It caps the agents at human speed, which defeats the entire purpose of having agents, so nobody actually does it for real. And where it is nominally practiced, it degrades immediately into rubber-stamping, because no human being meaningfully reviews the four-hundredth tool call of the afternoon; they click approve because clicking approve is what the job has become. In-the-loop gets you the worst of both possible worlds: agents slowed to human pace, and outcomes that were never actually examined.
In the lead means something structurally different: a named human owns the outcome, not the steps. And "owns the outcome" is not a feeling or a value or a poster in the break room. It decomposes into exactly five things, and I mean decomposes literally, because you can audit each one with a plain yes or no:
- You know it exists. The agent appears in an inventory that is actually true, not the aspirational spreadsheet that says 2,000 when the real number is 4,800.
- You know what it can reach. Its real, effective access, every credential and tool and data source, not the intended scope from the design doc.
- You can see what it did. A record of its behavior that you could hand to an auditor, or to a Reddit thread, and stand behind.
- You can stop it. A brake that works at machine speed, faster than the harm compounds, that does not route through the agent's own goodwill.
- Your name is on it. When the board asks about this specific agent, a specific person answers, and knows in advance that they will be the one answering, which quietly changes every decision they make upstream of the question.
That is a job description. It has an occupant in every company that runs agents well, and it is a vacancy in every company that is about to become a case study in somebody else's essay. The report suggests, at its most ambitious, that enterprises may eventually need a whole new C-suite role, a "chief agentic resources officer," to hold the entire portfolio of these things. Maybe. But the unit of accountability is smaller than a new executive and available today, tonight, on one agent: one agent, one name, five checks. At Guard0 we call the person who holds those five checks the Human of Record, and I genuinely believe it is the first new role of the agent economy, not because a regulator will eventually mandate it, though they will, but because the only alternative to it is Jerry.
The report's own word for all of this is "deliberately," and it recurs through the forty pages like a drumbeat you start to hear in your sleep. Decision rights assigned deliberately. Operating models designed deliberately. Boundaries set before the agents go live, not reverse-engineered from the wreckage afterward. Because nobody has ever summoned a workforce by accident, one thoughtless button-press at a time, and ended up somewhere good.
The button is fine. The vagueness is not.
Here is the thing about the Meeseeks Box that the episode is careful to include and that every retelling somehow forgets. Rick uses the box constantly, without incident. It works fine for him. His instructions are bounded, his tasks are completable, and, most importantly, when the mob eventually forms at the restaurant, everyone in the room knows exactly whose box it was. Rick's failure mode is contained, not because his Meeseeks are somehow better-built than Jerry's, they are identical, but because his delegation is better: scoped tasks, known origin, a clear owner who shows up when it goes wrong.
The lesson of the episode was never "do not press the button." Agents are going to run more and more of every company, and on balance they should; the upside numbers in that Accenture and Wharton report are real, and the companies that sit this out entirely will lose to the companies that do not. The lesson is that the button is a hiring decision, and hiring has always come with a form to fill out: what is this for, what will it be able to touch, and who does it report to. Jerry did not fail because he used the box. He failed because he pressed a button wired to real consequences and asked it for something vague, owned by no one, bounded by nothing.
Intelligence is now scalable. Congratulations to all of us; it is genuinely one of the great achievements. Accountability still arrives one name at a time, the slow way, the way it always has, because that is the only way it can arrive. And the entire art of the co-intelligent enterprise, the thing the next decade of management is quietly going to be about, is closing the gap between those two facts on purpose, deliberately, before the mob forms rather than after.
Be Rick, not Jerry. And if you cannot, right now, name the specific human who answers for an agent you are already running in production, then I am sorry to be the one to tell you which of the two you currently are.
Assigning the name, and giving that person the five checks, is the whole of what Guard0 is for. Existence does not have to be pain, Jerry.
References
Get Started
Start free on Cloud
Dashboards, AI triage, compliance tracking. Free for up to 5 projects.
Start free →Accountability at scale
SSO, RBAC, CI/CD gates, self-hosted deployment, SOC2 compliance.