Attribution drift in enterprise monitoring: Governance, employee monitoring, and cybersecurity risk in the age of agentic AI
Agentic artificial intelligence is blurring the boundary between human work, automated work, and delegated digital action in enterprise environments. Enterprise monitoring systems, including endpoint detection and response, extended detection and response, security information and event management platforms, and user behavior analytics, have relied on the assumption that observed activity can be connected to a human user, service account, or system process with reasonable confidence. Agentic AI complicates this assumption because agents may operate under human credentials, through delegated permissions, as background services, or through additional accounts that are difficult for users and administrators to interpret. This paper introduces attribution drift as a conceptual construct describing the erosion of confidence that observed digital activity can be reliably attributed to intentional human conduct when semi-autonomous AI agents operate under, alongside, or near human credentials. Using a conceptual governance framework, this paper synthesizes literature on workplace monitoring, insider threat, socio-technical systems, agentic AI, and algorithmic accountability. The paper proposes a taxonomy of human-agent activity and develops governance propositions related to attribution confidence, employee monitoring, cybersecurity risk, and forensic readiness. The paper argues that full AI autonomy is not required for these risks to emerge. The more immediate challenge is partial, delegated, and opaque automation within enterprise systems. Recommendations include agent identity tagging, transparent disclosure of background services or accounts, permission separation, agent-specific audit trails, updated acceptable use policies, and incident response procedures that preserve attribution confidence while limiting unnecessary surveillance of human workers.
