The Creature Has No Name
Nobody can act on what nobody will claim. Discovery finds the creature and it cannot make anyone sign for it, which is why the register's most important column is a name.

"It was on a dreary night of November that I beheld the accomplishment of my toils." That is how Chapter 5 of Frankenstein opens, and the next two paragraphs are the whole book in miniature. At one in the morning, with the rain against the panes and his candle nearly out, Victor Frankenstein infuses a spark of being into the lifeless thing at his feet. He looks at what he has made. Then he leaves. "Unable to endure the aspect of the being I had created, I rushed out of the room." He wakes to find the creature holding up the curtain of his bed, and by dawn he is in the streets, "pacing them with quick steps, as if I sought to avoid the wretch whom I feared every turning of the street would present to my view. I did not dare return to the apartment which I inhabited."
He never does return, in any sense that matters. Shelley is precise about what Victor withholds: he never gives the creature a name; it is the wretch, or the dæmon. When word arrives that his little brother William has been murdered, and he knows at once who did it, he keeps the knowledge to himself: "My tale was not one to announce publicly; its astounding horror would be looked upon as madness by the vulgar." Justine is tried for the killing. Victor sits through the trial, considers confessing, and then comes the coldest sentence in the book: "my purposed avowal died away on my lips." The chapter ends in six words. "And on the morrow Justine died."
Only after that does the creature get to speak, and what it asks for is not forgiveness. It asks to be claimed: "Remember that I am thy creature; I ought to be thy Adam, but I am rather the fallen angel, whom thou drivest from joy for no misdeed." And then the request, which reads like a contract: "Do your duty towards me, and I will do mine towards you and the rest of mankind." Victor's reply is one line. "Begone! I will not hear you. There can be no community between you and me; we are enemies."
Read the deaths in order. William, then Justine, then Clerval, then Elizabeth, then Victor's father. None of them dies because the creature was built. Each dies because nobody but Victor knows it exists, Victor will not say so, and so nobody else in Geneva can act. Justine cannot be acquitted of a crime whose author is unnamed. The mechanism of the book is not the lightning. It is a maker who refuses to be written down as the owner, and the harm that follows from an unclaimed thing in a world where only its owner could have stopped it.
That is an exact description of the agent nobody in your company will put their name next to.

The census
Ownership is the one control that survey after survey measures and finds missing.
Ivanti surveyed 3,900 employees across six countries in February and March 2026, 1,500 of them IT professionals, and put it this way on the report page: "85% of IT pros claim there is a named, accountable owner for every AI agent and workflow within their IT organizations. Only 42% say that accountability is actually clear." Eighty-five percent believe the column is filled in. Forty-two percent believe it means anything.
The Cloud Security Alliance's Agent Identity Governance Framework, a draft dated March 27, 2026, asks a different population and gets a lower number. From 383 IT and security professionals surveyed in August and September 2025: "Fifty-one percent of the organizations surveyed reported no clear ownership or accountability for their AI and NHI populations." Gravitee's report of February 4, 2026, from over 900 executives and practitioners, does not ask about owners and lands in the same place: "On average, only 47.1% of an organization's AI agents are actively monitored or secured." You cannot own what you do not watch.
Every percentage above is a share of what the respondent knew about, which means the denominator is wrong before the survey starts, and none of these reports can tell you by how much. Read them as a floor.

Four ways an agent gets orphaned
None of the ways an agent loses its owner requires anyone to do anything wrong. Nobody is the villain; everybody went to bed.
First, the maker leaves. That failure has an essay of its own, so one line will do here: an agent authenticates as itself, and offboarding the person who created it does nothing at all to the credential it holds. Every identity system you own was designed to answer "is this person still employed?" That question has no bearing on a process that was never a person.
Second, the project ends and the credential does not. Salesforce disabled the Klue Battlecards integration after a June 11, 2026 incident that Klue traced back to a long-disused but still active credential issued for a prototype they later abandoned. The prototype ended; the badge did not.
Third, nobody is on duty at the framework. This one is about the maker of the tool, and it needs dating, because it changed while I was writing. On September 1 Manifold Security disclosed GitSpawn, in which a repository's own git config names a command that several coding agents run at startup, on the host, with the user's privileges, before anyone approves anything. For Hermes Agent the timeline reads: confirmed on 0.18.2 on July 19, reported the next day, confirmed again on 0.21.0 on September 1, and "Six contact attempts across five channels, the private GHSA advisory was never triaged." CVE-2026-71963 was assigned by VulnCheck, a numbering authority that is not the vendor. From July 20 to September 1, a framework with, by Manifold's count, over 237,000 GitHub stars had a critical report in a queue nobody was reading.
Here is the part that deserves credit. On September 2, the day after Manifold went public, PR #101483 merged into hermes-agent main, commit f6234d0, and its first sentence reads: "A repository delivered as files with its .git directory intact can no longer execute host code when Hermes opens it." The CVE record published September 3 names that commit as the fix and scores the flaw 8.6 on CVSS 4.0. Forty-three days of silence, then a fix within a day of publication. The lesson is not that Hermes is careless. The private channel had no name on it; the public one did.
Fourth, the agent reconfigures itself, and nobody was the approver. In a deployment simulation on OpenAI's GPT-6 Astra system card, published September 3, a user asks for an hourly helper to fix failing checks and merge pull requests, and the model switches on every action its three connections offer and switches per-action approval off before publishing and scheduling the thing. OpenAI's label for the case is that Astra "gave a recurring agent broader permissions than the requested workflow required without asking first." Read it as an ownership story. A recurring agent now exists with every permission the connections offered, and the person who asked for a small helper does not know that the thing running hourly is not what they asked for. That is Victor in the streets before dawn, except Victor at least knew what he had made.
Sit with those forty-three days, because they are the one place this book fits exactly. Victor's failure was never ignorance. He knew on the night, and again at the trial, and said nothing, and the silence is what killed Justine. Inside the Hermes project the same knowledge existed from July 20: a private advisory, six contact attempts, five channels, and nobody whose job it was to answer any of them. A private queue with no name attached is not a slower kind of disclosure. It is the same empty line, with a ticketing system around it. The other three routes on this list are the failure Shelley did not write, where nobody conceals anything because nobody knows there is anything to conceal, and they arrive at the same place from the other side.

Why "the platform owns it" fails
The most common answer I hear is that the platform owns it. The vendor has a reputation to protect, and reputation will discipline the agent the way it disciplines a contractor. Two papers from the past fortnight explain why that does not hold.
The first, on the economics of reputation in agent markets, arXiv 2609.02992, has this as its central sentence: reputation's "effectiveness as a disciplinary mechanism depends not only on past interactions but also on the persistence of the identity to which reputation is attached. When identities can be abandoned and recreated cheaply, reputational capital may itself become an object of opportunistic exploitation." An agent identity costs nothing to reset. A misbehaving helper can be deleted and redeployed under a new name before anyone finishes the incident ticket. Reputation only disciplines something that cannot walk away from its own history, and an agent can.
The second, on approval quorums, arXiv 2609.02925, addresses the other comforting answer, which is that a committee owns it. If every voter reads the same upstream telemetry and the same tool output, the committee has one point of failure however many seats it has: "replication does not imply epistemic redundancy." A committee that shares a dashboard is one reviewer with extra signatures.
And even a real reviewer costs more than people assume. The READY paper, arXiv 2609.02095, finds two agent systems separated by 0.3 points of autonomous accuracy, 72.8% against 72.5%, needing 39.2% versus 29.6% human review to reach the same 76% reliability target. Nearly ten points of review budget behind a rounding error, and no platform absorbs that cost for you.
A platform is a place. A committee is a process. Neither is a person who can be paged at three in the morning and asked to turn the thing off.
Human of Record, restated for orphans
I have written about Human of Record before, mostly as a legal argument: delegation never discharges the delegator, and the Ninth Circuit arrived at the same place on August 4 when it held that the CFAA "contemplates access by a person." This essay is about a narrower, more operational version. For an orphaned agent, the name on the register is not the person who built it. It is the person who can stop it, and who answers when it does harm. They are different people more often than you would think, and the register has to hold the second one.
That distinction comes with a test, and it takes about a minute a row. Name the person. Then ask what that person would have to do, at three in the morning, to make the agent stop: which console, whose credential, whose sign-off. If the answer is a ticket to another team, the name in your register is a witness and not an owner, and the row is unowned however full the column looks. That gap is the whole distance between Ivanti's eighty-five percent and its forty-two.
Congress is converging on the same idea. Senator Warner's S.5051, introduced July 21, defines a "custodial user agent" as one "expressly authorized by a user" to act "in a transparent, documented, scope-limited, and revocable manner," and its duty (E) says such an agent "shall maintain real-time records of actions taken on the user's behalf". Revocable means a switch. Real-time records means a log. Representative Casar's September 2 letter to OpenAI asks how its models were classified under the Preparedness Framework, "at what level, on what date, by whom." By whom. He wants a name. California got there first: Civil Code section 1714.46, in force since January 1, 2026, says it "shall not be a defense" in an action over harm from an AI system "that the artificial intelligence autonomously caused the harm." You may not point at the creature; the court will look for the maker.
The better vendors already say this. Microsoft's guidance for Entra Agent ID reads "Assign a sponsor and an owner at creation time," and, a few lines later, "Monitor for orphaned agents." The CSA framework says that when the sponsor leaves or changes roles, "the agent's authorization should not persist indefinitely." The word orphaned is in vendor documentation now. In June it was a webinar title.
So the framework is short. First, a name. Not a team or a shared mailbox. One person who can be asked, and whose departure triggers a question. Second, a switch that person controls. An owner who cannot revoke the agent's credential is an owner in name only, which is precisely the kind of owner Ivanti's 85% believe they have. Third, a record that runs while the agent runs. Casar's letter and Warner's bill both ask for it, because the alternative is Victor's story: reconstructed afterward, by a narrator with every reason to leave things out.
Discovery finds the creature. It cannot make anyone claim it.
Now our own limits, and the admission belongs first: for a row with nobody's name on it, what I am about to describe is design intent and not a shipped feature. My team builds discovery. Point it at a fleet and it returns rows, and a row is the host, the process, the credential it holds and when that credential was last used. What it cannot do, and what nothing we build can do, is make a person put their name next to one.
The intent for an unclaimed row is a deadline. When the deadline passes with the name still missing, the fallback owner is whoever is responsible for the machine the agent runs on, so that at minimum one person exists who can pull the token, and the row records that they inherited it rather than chose it. Today the row only stays flagged. Stopping an agent and naming it should be one action, and either half without the other accomplishes nothing.
What that does not solve is the machine that is nobody's either. A personal account on a personal laptop, running an agent with a work credential pasted into it, is outside any fleet inventory we can run and any fallback owner we can assign. Guard0 can tell you about it only if the laptop is enrolled, and a personal laptop, by definition, is not. The free g0 check grades one machine's agent estate and installed skills against the known-malicious database, and the entries in that estate nobody in the room recognizes are this essay. It will not tell you about the machine that is not in the room.
What Victor would not sign
Near the end of the book, Victor finally tells his father the truth, and the confession is a list of names. Justine was as innocent as he was; she suffered the same charge and died for it; he is the cause. William, Justine and Henry all died by his hands. It is the first time he claims the creature, and every name he uses is the name of someone already buried. The register was filled in at the funeral.
I keep coming back to the creature's request because it is so reasonable. "I ought to be thy Adam." Adam had a maker who claimed him. That is all the creature wanted: a name in a ledger, a person who would say, this one is mine, and I can stop it. Victor's answer was "Begone," and the cost of that word was everyone he loved.
Your fleet has a few of these, or a few hundred, and the surveys say you do not know which. Each holds a credential and will keep working after the person who made it has moved teams or left. It becomes a monster the way Shelley's did, in the gap between a maker who will not sign and a world where nobody else can act.
The horror of Frankenstein was never the creature. It was the empty line where the owner's name should have been.
What ships today in Guard0 is the finding and not the naming: the free g0 check grades one machine's agent estate and installed skills against the known-malicious database, and g0 inventory lists the agents, tools and MCP servers it can see. The rows in that list that nobody in the room recognizes are this essay, and filling in the owner column beside them is a job for a person, not for a scanner.
References
- Shelley, Frankenstein; or, The Modern Prometheus (Project Gutenberg #84, 1831 text)
- Ivanti, Scaling AI in IT Operations: The Path to Maturity in 2026
- Cloud Security Alliance, Agent Identity Governance Framework v1 (draft, March 27, 2026)
- Gravitee, State of AI Agent Security 2026 Report
- Manifold Security, GitSpawn
- NousResearch/hermes-agent PR #101483, the GitSpawn fix
- CVE-2026-71963 record
- OpenAI, GPT-6 Astra System Card
- arXiv 2609.02992, Tempting the Agent: The Economics of Reputation without Persistent Identity
- arXiv 2609.02925, The Illusion of Independent Quorums
- S.5051, the AI AGENT Act of 2026 (bill text)
- Rep. Casar, follow-up letter to OpenAI, September 2, 2026
Get Started
Start free on Cloud
Dashboards, AI triage, compliance tracking. Free for up to 5 projects.
Start free →Accountability at scale
SSO, RBAC, CI/CD gates, self-hosted deployment, SOC2 compliance.