AI agents change more than the technology inside a workflow. They change the work itself.
A person who once completed a task may become the person who delegates it. Someone who previously exercised judgment throughout a process may now review the result at the end. A manager can retain formal accountability while having less direct visibility into how the work was performed. Teams may spend less time executing routine activity and more time dealing with exceptions, ambiguities and situations the agent could not resolve.
Those changes are already arriving alongside rapid progress in the technical governance of agents. NIST launched its AI Agent Standards Initiative in February 2026, with work spanning security, interoperability, identity and the broader standards needed for agents that can operate across real systems. Its security research recognizes that agents introduce distinct challenges because they can plan and take autonomous actions using external tools and data. OWASP is moving in a similar direction through its Agent Control Standard, which focuses on making agents inspectable, traceable, instrumentable and controllable at runtime.
The human side of that system requires comparable design attention.
Agentic work depends on people deciding what can be delegated, understanding what remains their responsibility, recognizing when an agent has reached the edge of its authority or competence, and intervening when the situation departs from the expected path. As the volume and autonomy of agentic work increase, those responsibilities become part of the control architecture.
Human Resilience Engineering gives organizations a way to design that human contribution deliberately.
Human Resilience Engineering for agentic AI is the deliberate design and testing of the human roles, capabilities, workflows, decision rights and organizational conditions that allow people to work effectively with autonomous or semi-autonomous AI systems.
It applies resilience engineering, human factors and Human Risk Management to questions created by agentic work: how delegation should operate, where human judgment adds value, what people need to see before approving an action, how uncertainty should be escalated, how oversight behaves at scale, and which human capabilities need to remain strong as agents perform more of the underlying work.
The design unit is the human-agent working system. The agent's identity, permissions and technical controls remain important, while the human side contributes another set of conditions that influence whether the system performs safely and adapts well when something unexpected occurs.
With conventional software, the boundary between user and system is usually fairly clear. A person initiates actions through defined interfaces, the software executes them, and responsibility maps reasonably well to what the person chose to do.
Agentic systems complicate that relationship because the software can perform a sequence of actions after the person's original instruction. An agent may interpret a goal, decompose it into tasks, gather information, invoke tools, make intermediate decisions and interact with other systems before returning to the human.
The person has therefore moved further from the execution.
That distance can be extremely useful. It is one of the reasons agents promise meaningful productivity gains. The same distance changes what human control requires.
NIST's AI Risk Management Framework already treats human-AI configurations as variable. Systems can range from highly autonomous to heavily human-directed, and different configurations create different implications for oversight, interaction and risk. NIST also notes that human-AI performance depends on how those teams are organized rather than assuming that adding a human automatically improves the result.
Agentic AI makes those design choices more concrete.
A human may remain responsible for the outcome while no longer observing most of the intermediate work. Another person may supervise several agents simultaneously. A subject-matter expert may become an exception handler, receiving only the cases the system could not resolve. An approver may encounter agent-generated requests for access, authority or actions that are difficult to reconstruct from the approval screen alone.
The job has changed even if the person's title has not.
Human Resilience Engineering starts by taking that change seriously enough to design for it.
Agent security is making rapid progress on identity and delegated authority.
NIST's current work on agent identity and authorization is concerned with how software agents should be identified, what rights they can exercise and how authority delegated from people should be constrained and audited. These are foundational controls because an agent capable of acting through enterprise systems needs clear boundaries around what it is permitted to do.
There is a parallel workforce question: what does the person believe they have delegated?
A manager may ask an agent to “prepare everything needed to onboard this supplier.” The technical system can determine which applications and data the agent may access. The human side still depends on a shared understanding of the task boundary. Does preparation include contacting the supplier? Updating a record? Accepting contractual terms? Requesting credentials? Initiating a payment workflow?
As agents become better at translating broad goals into action, the gap between an instruction and its operational consequences can widen.
Human Resilience Engineering therefore needs delegation to be intelligible to the person assigning the work. The workflow should make consequential boundaries visible at the point where they matter, particularly when the agent moves into actions that create external commitments, affect sensitive data or alter systems.
This is partly an interface problem, partly a governance problem and partly a capability problem. People need enough understanding of the agent's capabilities and operating boundaries to delegate appropriately. The surrounding system needs to make those boundaries usable during real work rather than leaving them buried in configuration or policy.
Human oversight has become one of the most common answers to AI risk, and it is an important one. The European Commission's current AI Act guidance requires deployers of relevant high-risk AI systems to assign human oversight to people who are sufficiently equipped and enabled to perform it. The language is useful because it treats oversight as a capability with operating conditions rather than as simple human presence.
The same logic applies to enterprise agentic systems even when a particular use case falls outside those regulatory requirements.
A person expected to review an agent's recommendation needs enough information to understand what is being proposed. If the judgment requires subject-matter expertise, the reviewer needs that expertise or access to someone who has it. If intervention can delay a business process, the reviewer needs enough authority to tolerate that delay. If an unusual situation cannot be resolved locally, escalation needs somewhere useful to go.
These conditions determine whether the oversight stage contributes meaningful judgment.
Cybermaniacs explores this problem in more depth in What Makes Human Oversight Effective When Employees Work With AI Agents? Read the Human Oversight guide That article focuses closely on oversight as a control. Human Resilience Engineering widens the lens by examining how that oversight role fits into the rest of the working system and how the design should change as the agent becomes more capable.
That distinction matters because the human role rarely stays still. Early deployments may send frequent decisions back to people while the organization builds confidence. Later versions may automate more of those decisions. The remaining human workload then becomes concentrated around unusual, ambiguous or consequential situations.
The design has to evolve with the work.
One of the most useful pieces of current NIST guidance on agentic systems concerns something quite ordinary: people get tired of approving things.
In August 2026, NIST warned that heavy dependence on human-in-the-loop access approvals can create consent fatigue. If an agent repeatedly asks for permission while moving through a complex workflow, people can become conditioned to click through requests in much the same way that repeated authentication prompts created the conditions for MFA fatigue attacks.
The example illustrates a wider engineering problem.
A human control needs to be evaluated at the volume, pace and complexity at which it will operate.
A security analyst may make an excellent judgment on five unusual agent actions during a working day. The same analyst may make much poorer judgments if the deployment scales until hundreds of requests arrive, many of them routine and most of them approved. Nothing about the formal control has changed. The operating environment has.
The same issue appears with managerial review. A manager who receives occasional agent-generated analysis can examine it thoughtfully. If every decision now arrives with a machine-generated recommendation, continued attention cannot be assumed simply because the approval field remains mandatory.
Human Resilience Engineering needs to consider the attention economics of the control. Routine cases may need stronger technical boundaries so human attention can be reserved for conditions where judgment genuinely adds value. Interfaces may need to emphasize the information relevant to the exception rather than reproduce the agent's entire history. Escalation thresholds may need to change as deployment volume grows.
This is familiar territory in human factors. MITRE's human-machine teaming work identifies observability, calibrated trust, common ground, directability, attention management and information presentation among the design concerns that shape effective human-machine teams. Agentic AI brings those long-standing issues into everyday enterprise workflows.
As agents become more capable, the work they leave behind for people may become systematically harder.
Routine cases are attractive candidates for automation because their patterns are easier to recognize and their outcomes easier to specify. Ambiguous cases, conflicting objectives and unfamiliar conditions are more likely to reach a person.
The result can be a form of exception concentration. The human handles fewer cases overall, while a larger share of those cases require judgment.
That shift has implications for capability.
Consider an experienced procurement professional whose agent handles supplier research, routine documentation and preliminary risk checks. Over time, the employee may spend less time performing those tasks directly and more time resolving unusual supplier conditions. The role has become more cognitively demanding in one sense, even though the total manual workload has fallen.
The organization now depends on the person retaining enough underlying knowledge to understand why an exception matters.
Skill development therefore has to follow the redesigned role. Training designed for the pre-agent workflow may spend time teaching activities the agent now performs while giving relatively little practice in the difficult situations where human intervention has become most valuable.
This is one area where Human Resilience Engineering and AI workforce enablement naturally meet. Capability design should reflect the work people are expected to perform after automation, including the judgment required at the boundaries of the agent's competence.
Skill erosion has been discussed around automation for decades, and agentic systems give the issue new practical relevance.
When a person performs a task less often, their fluency can decline. Whether that matters depends on the role the person is expected to play later.
If an agent permanently removes a low-value administrative task and nobody needs the underlying skill, the loss may be entirely acceptable. If a person is expected to take over during failure, verify the agent's reasoning or resolve exceptional cases, retained capability becomes part of the resilience design.
The organization needs to know which human abilities remain essential.
This is particularly important in high-consequence or operational environments where contingency arrangements assume human takeover. A procedure that says “escalate to the operator” carries little value if the operator has spent two years outside the work and no longer possesses the fluency required under pressure.
Human Resilience Engineering can address this through workflow design as well as training. People may remain involved in selected tasks, rotate through manual practice, review significant decisions or participate in exercises designed around realistic failure modes. The specific mechanism should reflect the consequence of capability loss and the practical role humans are expected to retain.
The measure of success is not whether people preserve every pre-AI skill. The organization needs enough human capability to support the future operating model it has actually chosen.
Agentic systems will encounter situations that neither the agent nor the first human reviewer can resolve confidently.
Many governance designs handle this poorly because escalation is framed around obvious violations or clear technical failure. Real work produces a large middle ground where somebody has incomplete information, competing signals or a sense that the situation does not fit the normal pattern.
Those are precisely the conditions where adaptive capacity matters.
A resilient human-agent workflow gives uncertainty somewhere to go. That may involve another subject-matter expert, security, privacy, legal, a process owner or a designated decision authority. The route needs to be usable within the time and operational constraints of the work.
The design also needs to account for organizational culture. Escalation becomes weak when employees believe that raising uncertainty will be interpreted as lack of competence, resistance to AI adoption or unnecessary obstruction. A formally available escalation channel can therefore coexist with very little actual escalation.
This is part of the reason Cybermaniacs treats culture as an operational risk condition. Shared assumptions about speed, challenge, experimentation and authority affect whether the controls described in governance operate as intended.
In agentic systems, that culture can determine whether a person stops an unfamiliar sequence or allows it to continue because the organization has strongly rewarded autonomous execution.
Agentic AI creates an uncomfortable governance problem when accountability remains with a person whose actual control over the work has progressively diminished.
Organizations understandably want clear human accountability. Someone should own the process, understand the intended outcome and remain responsible for the way the system is used.
That responsibility is strongest when the person also has meaningful agency.
A manager who can inspect the relevant information, alter instructions, constrain the agent, interrupt actions and escalate unresolved risk occupies a very different position from a manager who receives a completed result generated through a process they cannot meaningfully observe or influence.
The accountability model should recognize that difference.
This issue becomes especially significant as agents interact with other agents or operate across systems. NIST's current agent standards work highlights the need to understand chains of trust, agent identity and delegated authorization precisely because agency can travel through a workflow rather than remaining attached to one user action.
The human governance model needs similar clarity about where authority resides and when responsibility passes between roles.
Human Resilience Engineering contributes by examining the practical decision rights in the workflow. Who can stop the process? Who can change the agent's goal? Who owns an exception? Who decides that the operating conditions have moved outside the approved use case? Those responsibilities need to remain understandable as the system evolves.
Consider an organization introducing an agent to support supplier onboarding.
The agent gathers corporate information, checks documents, compares sanctions and risk information, requests missing material, drafts a recommendation and updates the procurement platform. Low-risk suppliers can move through much of the process with limited human involvement, while unusual cases are referred to a procurement specialist.
The technical governance is reasonably mature. The agent has a defined identity, constrained access, logged activity and approved tools. Significant actions require authorization.
The human side evolves more gradually.
During early deployment, procurement specialists receive many referrals because the thresholds are conservative. They examine the cases closely and develop a good understanding of the agent's behavior. As confidence grows, thresholds change and the volume of routine referrals falls.
Six months later, the human workload looks different. The agent now handles most ordinary cases, while specialists see suppliers involving unusual ownership, conflicting information, difficult jurisdictions or ambiguous documentation. The average case arriving at a human is considerably harder than it used to be.
A conventional readiness program might have trained the team before launch and considered the workforce transition complete.
Human Resilience Engineering treats the six-month point as another design stage.
The specialists may need stronger investigative capability because their remaining work is more complex. The interface may need to expose enough of the agent's path to explain why the case was escalated. The escalation route beyond the procurement team may need improvement if sanctions, legal or security expertise is regularly required. Metrics used to assess employee productivity may need revision because case volume is no longer a sensible proxy for workload.
The system also creates new evidence.
Human overrides can show where the agent's decision boundary needs adjustment. Repeated escalation around one supplier type can reveal a weakness in the workflow. A decline in human ability to conduct a full manual review may matter if the contingency plan still assumes that capability exists.
The engineering process continues because the work continues to change.
Agentic systems generate a considerable amount of technical telemetry, and much of it will be valuable for security engineering.
Human Resilience Engineering needs a related but different evidence base. The question concerns how the human-agent system is actually performing.
A useful program may need evidence about where humans intervene, which decisions are escalated, whether approvals are becoming increasingly automatic, how long meaningful review takes, where people repeatedly change agent recommendations, and whether particular roles have the capability required for the exceptions reaching them.
Qualitative evidence is also valuable. Interviews, observation and structured feedback can surface forms of friction that event logs cannot explain. A recurring override might reflect an agent weakness, a policy ambiguity or a manager who has quietly told the team to apply a different standard.
The evidence should be proportionate to the risk and governed appropriately. Workforce intelligence does not improve simply because every employee interaction with an agent has been captured at maximum granularity.
The design aim is enough visibility to understand whether the system continues to work as intended.
AI testing is becoming more mature, including the evaluation of agentic systems themselves. NIST's August 2026 draft TEVV-Athlon framework explicitly covers agentic systems within a broader approach to test, evaluation, verification and validation of AI.
Organizations should extend that testing mindset to the combined operating configuration.
An agent can perform well in isolation while the human-agent workflow performs poorly. The issue may appear in the handoff, the volume of approvals, the information shown to the reviewer, the escalation path or the practical distribution of authority.
Testing should therefore include realistic working conditions where appropriate. A human reviewer can be asked to respond to ambiguous outputs, unusual access requests or conditions where the agent appears confident but is wrong. Teams can exercise what happens when the agent is unavailable, when human takeover is required, or when the person supervising the system cannot resolve the issue.
These exercises produce more than assurance evidence. They help organizations discover whether their assumptions about the human role survive contact with the actual workflow.
Agent governance defines the boundaries within which agents can operate. Identity and access controls determine what agents can reach. Runtime security and observability help organizations understand and constrain agent behavior. Standards such as OWASP's Agent Control Standard are rapidly strengthening that technical control plane.
Human Resilience Engineering deals with the part of the operating system expressed through people and work.
It helps specify which decisions should remain human, what those people need to know, what information they need at the moment of judgment, what volume of intervention remains realistic, how responsibility and authority should line up, and how capability should evolve as the agent takes on more of the task.
These layers are complementary.
A well-designed technical agent can still sit inside an ineffective human workflow. A capable workforce cannot compensate indefinitely for agents with excessive permissions, poor observability or weak technical constraints .The design target is the relationship between them.
That broader relationship is the focus of Cybermaniacs' Guide to AI Agent Governance in 2026: The Missing Human Risk Layer. Read the AI Agent Governance guide Human Resilience Engineering develops the next part of that argument by treating the workforce side as something organizations can deliberately design, test and improve.
Human Resilience Engineering for agentic AI spans systems that will usually sit outside the Human Risk Management platform. Agent identity, runtime enforcement, model evaluation and technical authorization belong in the AI and security architecture.
HRM contributes a different layer of visibility.
It can help the organization understand whether the people occupying agentic roles possess the required capability, whether reliance and supervision are changing, where intervention patterns cluster, how organizational conditions affect behavior and whether targeted changes improve the human side of the system.
That becomes particularly useful across multiple agent deployments.
A single workflow may be understandable to its local product team. Enterprise adoption creates patterns across roles, departments and technologies that are harder to see from inside one implementation. Workforce Risk Intelligence can reveal populations where oversight responsibilities are expanding, where skill requirements are shifting or where escalation patterns suggest a broader organizational condition.
A Human Risk Management platform supporting this work should preserve role and workflow context, distinguish different kinds of human-agent responsibility, track change over time and connect interventions with their outcomes. It should also support governance that prevents workforce-risk measurement from becoming indiscriminate surveillance.
For organizations evaluating how HRM fits into agentic governance, the relevant question is whether the system can help make human control observable and improvable.
Cybermaniacs has been developing this area through the intersection of Human Risk Management, AI workforce risk and agentic readiness.
Our existing HRM work provides models for competency, psychology, behavior, culture and organizational context. AI-enabled work introduces additional questions around reliance, verification and changing capability. Agentic systems extend that research further into delegation, supervision, intervention, override, escalation and the distribution of authority across human-agent workflows.
We make those concepts public because organizations need a stronger vocabulary for the problem. The detailed taxonomies, evidence relationships and measurement mechanisms underneath them remain part of the Cybermaniacs system and research program.
Our Agentic Readiness & Change service is built around this broader operating transition. It examines how agents alter roles, workflows, accountability, supervision and workforce capability, then helps organizations determine where controls and enablement need to change as deployment develops.
The purpose is to help organizations reach the point where agents can take on meaningful work without quietly hollowing out the human capabilities, decision structures and adaptive capacity the organization will still need when conditions become difficult.
Agentic AI will remove a great deal of routine human activity from workflows. That is part of its value.
The human contribution that remains may become more consequential precisely because it appears at boundaries, exceptions and moments of uncertainty. People will supervise systems, decide what to delegate, interpret ambiguous outcomes, intervene when assumptions fail and make judgments that are difficult to encode completely in advance.
Those responsibilities deserve deliberate design.
Human Resilience Engineering gives organizations a way to examine whether the person performing that work has the capability, context, authority and organizational support required for the role. It also keeps attention on how those conditions change after deployment, when agents become more capable and work gradually reorganizes around them.
The technical systems around agentic AI are already acquiring stronger identity, authorization, observability and runtime controls. The human system needs an equally serious engineering discipline.
That is how agentic readiness develops from a launch requirement into an enduring organizational capability.
Human Resilience Engineering for agentic AI is the deliberate design and improvement of the human roles, capabilities, workflows, decision rights and organizational conditions that allow people to work effectively with autonomous or semi-autonomous AI systems.
Agents can perform multi-step work between the human's original instruction and the eventual outcome. People may therefore supervise work they did not directly perform and may see only selected parts of the process. Effective oversight depends on whether the human has sufficient context, capability, attention and authority for the responsibility assigned to them.
The design should reflect the consequence and complexity of the task, the information available to the reviewer, the volume of decisions, the reviewer's capability, and the practical ability to intervene or escalate. Human approval is most useful where human judgment adds meaningful control rather than serving as a routine confirmation step.
Consent fatigue occurs when people receive enough repeated authorization or approval requests that they begin responding habitually rather than evaluating each request carefully. NIST has warned that excessive use of human-in-the-loop access approvals for agents can create a pattern similar to MFA fatigue.
Agents can remove routine work while increasing the proportion of human work devoted to exceptions, ambiguity and supervision. Organizations may need to strengthen the judgment required for those remaining tasks while also considering which underlying skills humans need to retain for verification, takeover or recovery.
Escalation provides a route for situations that the agent or first human reviewer cannot resolve confidently. Effective escalation requires clear ownership, accessible expertise and organizational conditions that allow uncertainty to be surfaced without unnecessary friction or penalty.
Accountability should reflect the person's actual ability to understand, influence and intervene in the work. Organizations should define decision rights, delegated authority, escalation responsibility and the conditions under which responsibility passes between human and agentic roles.
Relevant evidence can include role-specific capability, intervention and override patterns, escalation, review quality, approval behavior, workload, reliance, retained skill and changing workflow conditions. The measures should reflect the particular human responsibility the organization is trying to evaluate.
Agent governance establishes policies, accountabilities and technical boundaries for agents. Human Resilience Engineering focuses on the human and organizational conditions required for those systems to work effectively in practice, including delegation, supervision, intervention, capability and escalation.
Human Risk Management helps organizations understand and improve the workforce side of agentic adoption. It can provide evidence about capability, behavior, reliance, culture, organizational context and human-agent interaction, then connect those findings to targeted interventions and continued measurement.