{"id":136915,"date":"2026-02-19T14:40:45","date_gmt":"2026-02-19T14:40:45","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=136915"},"modified":"2026-02-19T14:40:45","modified_gmt":"2026-02-19T14:40:45","slug":"why-cios-should-think-like-hr-leaders-to-onboard-agentic-ai","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2026\/02\/19\/why-cios-should-think-like-hr-leaders-to-onboard-agentic-ai\/","title":{"rendered":"Why CIOs should think like HR leaders to onboard Agentic AI"},"content":{"rendered":"\n<p><em>As Agentic AI shifts from experimental technology to operational backbone, CIOs are being forced to rethink governance, access control and accountability at enterprise scale. Mike Anderson, Chief Digital and Information Officer at Netskope, tells us why AI agents must be managed like digital employees \u2013 with defined roles, strict access boundaries and continuous oversight \u2013 if organisations are to scale innovation safely across the Middle East and beyond.<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"595\" height=\"597\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/02\/Mike-Anderson_Netskope.webp\" alt=\"\" class=\"wp-image-136916\" style=\"width:356px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/02\/Mike-Anderson_Netskope.webp 595w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/02\/Mike-Anderson_Netskope-300x300.webp 300w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2026\/02\/Mike-Anderson_Netskope-150x150.webp 150w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><\/figure><\/div>\n\n\n<p>AI is no longer just supporting business processes; in many cases, it now runs them. For CIOs, this shift isn\u2019t about tools; it\u2019s about trust, control and strategy.<\/p>\n\n\n\n<p>The rapid evolution of artificial intelligence, particularly Agentic AI, presents both unprecedented opportunities and significant management challenges for Chief Information Officers (CIOs). Unlike generative AI, which primarily creates content, agentic AI operates autonomously, making decisions and executing tasks to achieve set goals.<\/p>\n\n\n\n<p>This capability demands a new approach to integration and governance, moving beyond purely technical considerations to embrace principles traditionally found in human resources (HR). The focus, especially within the rapidly expanding Middle Eastern markets like Saudi Arabia and the United Arab Emirates, shifts towards managing these AI agents with the same diligence and foresight applied to human employees. This means CIOs need a mindset shift\u2014from technical oversight to workforce-style governance.<\/p>\n\n\n\n<p><strong>The new hire no one interviewed<\/strong><\/p>\n\n\n\n<p>Inside a major bank&#8217;s operations centre last period, an AI agent quietly processed 800 loan applications overnight. It cross-checked credit histories, flagged inconsistencies and routed approvals to human underwriters. No one hired this agent. No one trained it on company policy. It simply appeared because a developer connected an API to an internal system.<\/p>\n\n\n\n<p>The agent worked perfectly until it didn&#8217;t. On day three, it approved a high-risk application that violated lending standards. The fallout? Regulatory headaches and a scramble to explain how automation bypassed human oversight.<\/p>\n\n\n\n<p>This is the reality CIOs across the Middle East face in 2026. 84% of organisations in the region now use AI in some form, up from 62% just two years ago. But that adoption masks a control problem. These aren&#8217;t passive tools anymore. They&#8217;re autonomous actors making real decisions inside live workflows.<\/p>\n\n\n\n<p><strong>From tools to actors<\/strong><\/p>\n\n\n\n<p>Generative AI gave us writing assistants and chatbots. Agentic AI gives us something more: systems that plan, act and learn without constant human input.<\/p>\n\n\n\n<p>Globally, almost one quarter of organisations are now scaling agentic AI, with another 39% in the experimental phase. The pace is even faster in the Gulf. The UAE has committed $200 billion to AI infrastructure, while Saudi Arabia&#8217;s 70% of strategic goals now involve data and AI.<\/p>\n\n\n\n<p>These agents are already embedded in operations. Contact centres in the UAE are seeing headcount reductions by as much as 20-30% as agents handle routine inquiries in Arabic and English. Saudi German Health Group has deployed chatbot-driven appointment scheduling, cutting response times by almost two-thirds, while Abu Dhabi invests US$3.54 billion to automate all government processes by 2027.<\/p>\n\n\n\n<p>The difference between task automation and agentic systems is agency. A task-level bot follows scripts. An agent decides which tasks to perform and in what order and adapts when conditions change. That flexibility is powerful. It&#8217;s also dangerous if you skip the onboarding.<\/p>\n\n\n\n<p><strong>The CIO playbook breaks here<\/strong><\/p>\n\n\n\n<p>Traditional IT governance assumes systems behave predictably. You define inputs, code logic, test outputs. Agentic AI doesn&#8217;t work that way. It makes contextual decisions that weren&#8217;t explicitly programmed. That creates a governance gap most CIOs aren&#8217;t ready for.<\/p>\n\n\n\n<p>With 13% of organisations already reporting breaches involving AI models or applications, almost every instance has the same root problem: a lack of proper AI access controls. Shadow AI alone adds an average of US$670,000 to breach costs, and one in five Middle East organisations has already suffered a shadow AI incident.<\/p>\n\n\n\n<p>The real risk isn&#8217;t the AI failing. It&#8217;s the AI succeeding at something it shouldn&#8217;t be doing. Access is the new attack surface.<\/p>\n\n\n\n<p><strong>Why HR thinking suddenly matters<\/strong><\/p>\n\n\n\n<p>Here&#8217;s where CIOs need to borrow from HR. When you hire a person, you don&#8217;t give them the master key on day one. You define their role. You set boundaries. You review performance. You grant access based on need and you revoke it when they leave or change roles.<\/p>\n\n\n\n<p>Agentic AI requires the same discipline. The World Economic Forum estimates non-human and agentic identities will exceed 45 billion by the end of 2025, more than 12 times the global workforce. Traditional identity systems built for human logins can&#8217;t scale to this. Static permissions, manual reviews and quarterly audits collapse under the volume and velocity of machine behaviour.<\/p>\n\n\n\n<p><strong>Agentic AI as a co-worker: onboarding basics<\/strong><\/p>\n\n\n\n<p>Think of each agent as a new employee. It needs a job description, training, probation and ongoing review.<\/p>\n\n\n\n<p>Job description: Define what the agent can access and what actions it can take. A procurement agent doesn&#8217;t need HR data. A customer service agent doesn&#8217;t need financial write access.<\/p>\n\n\n\n<p>Training: Feed the agent on company policies, compliance rules and edge cases. Don&#8217;t assume it knows your internal standards just because it&#8217;s trained on public data.<\/p>\n\n\n\n<p>Probation: Start with read-only access or human-in-the-loop approval for high-risk actions. Let it prove competence before granting autonomy.<\/p>\n\n\n\n<p>Performance review: Monitor what the agent actually does, not what it&#8217;s supposed to do. Drift happens. Models change. Context shifts.<\/p>\n\n\n\n<p>Least privilege: Grant access just-in-time for specific operations, then revoke it. Token lifetimes should be ultra-short. Every inter-agent communication should be authenticated and audited.<\/p>\n\n\n\n<p>In practice, this means technical controls. Zero-trust architecture isn&#8217;t optional anymore.<\/p>\n\n\n\n<p><strong>The cost of skipping onboarding<\/strong><\/p>\n\n\n\n<p>As almost half of organisations now see AI-automated attack chains as their top concern, 85% already believe traditional detection is becoming obsolete. Attackers are onboarding their agents faster than defenders.<\/p>\n\n\n\n<p>In the Gulf, where GenAI is expected to generate over $23 billion annually by 2030, the financial stakes are massive. The opportunity cost of not deploying agentic AI is real. But the actual cost of deploying it badly is worse.<\/p>\n\n\n\n<p><strong>Metrics over myth<\/strong><\/p>\n\n\n\n<p>CIOs should measure what matters: containment rate (what percentage of agent actions stay within defined boundaries), escalation accuracy (when does the agent correctly hand off to humans), access drift (how permissions change over time) and incident response time (how fast you detect and stop a rogue agent).<\/p>\n\n\n\n<p>In the UAE, 34% of organisations have scaled AI in IT\/digital functions, 32% in strategy and 29% in operations. Those leading the pack are tracking these metrics weekly, not quarterly.<\/p>\n\n\n\n<p><strong>Start small, expand safely<\/strong><\/p>\n\n\n\n<p>The GCC model for agentic AI deployment should mirror how the region is building physical AI infrastructure: deliberate, measured and tied to national strategy. Pick one high-value workflow. Define clear boundaries. Deploy with monitoring. Measure results. Then scale.<\/p>\n\n\n\n<p>Saudi Aramco built a 250-billion-parameter genAI model using decades of operational data to analyze drilling plans. That&#8217;s scaled AI done right because it started with clear use cases, defined access and iterative expansion.<\/p>\n\n\n\n<p><strong>Governance is workforce management<\/strong><\/p>\n\n\n\n<p>The Middle East is racing to lead the global AI economy. That&#8217;s the right ambition. But leadership requires control. The same discipline that built successful organisations in oil, finance and logistics now applies to digital workers.<\/p>\n\n\n\n<p>CIOs who think like HR leaders in 2026 will build agentic systems that scale safely. Those who treat AI as just another IT deployment will spend the next decade cleaning up the mess. The choice is onboarding or incident response. There is no middle ground.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As Agentic AI shifts from experimental technology to operational backbone, CIOs are being forced to rethink governance, access control and accountability at enterprise scale. Mike Anderson, Chief Digital and Information Officer at Netskope, tells us why AI agents must be managed like digital employees \u2013 with defined roles, strict access boundaries and continuous oversight \u2013 [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":136579,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[18927,139,15994,12449,14960,9961,13],"tags":[19142,19962,3355,155,562,21971,1453,6498],"class_list":["post-136915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expert-opinion","category-industry-expert","category-middle-east","category-north-america","category-strategy","category-thought-leadership","category-top-stories","tag-agentic-ai","tag-ai-governance","tag-artificial-intelligence","tag-cio","tag-middle-east","tag-mike-anderson","tag-netskope","tag-zero-trust"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=136915"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136915\/revisions"}],"predecessor-version":[{"id":136917,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/136915\/revisions\/136917"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/136579"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=136915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=136915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=136915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}