How Should Companies Position AI Agents?

The number of AI agents a company runs is not a measure of its digital maturity. I saw this clearly at the start of 2026, at a 312-person insurance brokerage in Ankara that had simultaneously invested in two separate SaaS AI agent platforms to automate its policy renewal process. Six weeks in, the agent system was sending customers incorrect premium quotes, and nobody in the organisation could say which system had generated which decision. The technology itself was not the problem. The problem was that nobody had asked: ‘What is this agent authorised to decide, and what requires a human?’ This article argues a single position: companies must position AI agents not as tools, but as organisational accountability units. Every deployment that skips this step does not improve performance — it accelerates errors at machine speed.Most organisations still approach agents as automation layers: define a task, connect a data source, run it. This is partly valid — but only when the agent operates within a narrow, easily reversible scope. The difficulty is that by 2025 and into 2026, agent systems have matured well beyond that boundary. A customer service agent no longer just retrieves information; it initiates applications, sets priority queues, and in some configurations produces refund decisions. At a mid-scale machine manufacturer in Eskisehir, an agent deployed for export quotation ran for 11 months with an incorrect currency parameter embedded in its pricing logic. The error went undetected precisely because the assumption was ‘the agent is running, so it must be working.’ That assumption is the most dangerous thing in an enterprise AI programme. When accountability is diffuse, automation becomes a polished way of eliminating oversight.The EU AI Act entered phased enforcement in 2025, and for Turkish companies it has created a concrete compliance question tied to commercial relationships in European markets. Agent applications that fall within the Act’s ‘high-risk AI system’ definition — those operating in employment decisions, credit assessments, healthcare triage — now carry technical documentation, human oversight, and logging obligations. Turkey’s domestic regulatory framework does not yet fully mirror this architecture, but any company exporting to Europe or serving EU-based clients faces real exposure. In a conversation last month with management at an automotive tier-two supplier in Bursa, I found that the team had no clarity on which risk category their machine vision quality-control agent fell into under the Act. The question ‘how would you measure compliance?’ had no answer. Risk categories left undefined accumulate remediation cost every quarter — defining them at the start is always cheaper than retrofitting after an audit.Turkey’s data sovereignty debate has moved from policy circles to the boardroom table by mid-2026. Cloud-based agent platforms are genuinely attractive: faster deployment, lower upfront cost, expanding capability sets. But the agent activity running on these platforms may route company data through infrastructure outside Turkey’s jurisdiction. Article 9 of KVKK prohibits transferring personal data abroad without adequate safeguards, yet in most deployments neither the IT team nor the business unit has mapped exactly what data the agent processes or whether that data feeds the platform provider’s model infrastructure. Working with a medical device distributor in the health sector, I found that CRM agents handling patient appointment data were operating under a vendor contract that contained no explicit clause on training data exclusion. That is not only a legal exposure — it is a trust deficit that compounds. A data flow the company cannot explain to its own customers should not be inside its production systems. Beginning an agent deployment without a data sovereignty audit is not strategy; it is deferred liability.The ‘what do I do Monday morning?’ question deserves a concrete answer, and the sequence matters. First: map the decision boundary for every agent currently running or planned. For each agent, the questions ‘which decisions fall within its authority?’ and ‘which require human confirmation?’ must be answered in writing — not by the technical team alone, but validated and signed off by the relevant business unit. Second: define a measurement protocol before go-live, not after. ‘Is it running?’ is not a useful metric. ‘How often does it produce the correct output, how quickly is an error detected, and who owns the correction?’ — these three questions, left unanswered, mean the system is operating in a blind spot. Returning to the Ankara insurance brokerage: had those three questions been asked at the outset, the incorrect policy quotes would have been caught within 48 hours rather than six weeks. Third: if your business has any commercial relationship with EU-market customers or partners, determine your agent system’s EU AI Act risk classification with legal counsel — external if necessary. This is not a compliance formality; it is a competitive risk decision with a defined cost if ignored.The management at that Ankara insurance firm did not shut down their platforms. They selected one, built a decision boundary map, designed a human-in-the-loop workflow for higher-stakes policy actions, and established a weekly agent activity review. The system stabilised within four months. Their comment was direct: ‘If we had built the boundaries first instead of the system, we would not have lost six weeks.’ Positioning AI agents correctly is not a technology procurement question. It is a management discipline question. If you do not know which decisions you are delegating to an agent, the agent will make all of them — and often get them wrong.

This article was originally published in Turkish by Gökhan MERCANOĞLU on July 1, 2026. The English edition has been reviewed and edited by the author.


analytical modeling should be designed not to record the company’s past, but to strengthen its future decisions. The right architecture creates visibility, speed, control, and learning capacity. Otherwise, data is collected and reports multiply, while decision quality remains unchanged.


Gökhan Mercanoğlu
Büyük Veri ve Veri Bilimi