Essay · August 2026

Your Management System Is Your AI Strategy

Why agentic AI will reward the organizations whose operating teams own their management systems, and widen the gap for those that treat them as compliance programs.

Read the White PaperOn LinkedInOn X

Why agentic AI will reward the organizations whose operating teams own their management systems, and widen the gap for those that treat them as compliance programs

Over the past three decades, disciplined industries have invested heavily in writing down how they work. Pipeline operators built safety management systems around API RP 1173. Process facilities built PSM programs under OSHA 1910.119. IT organizations codified ITIL, and finance teams built COSO controls. The vocabularies differ, but the structure is the same everywhere: documented procedures, measurable outputs with defined tolerances, root cause analysis when something fails, and proactive audits to find gaps before they become events.

For most of those thirty years, that discipline was treated as a compliance cost. Something you funded because the regulator required it.

I believe agentic AI has just made it the most valuable asset on the balance sheet that never appears on the balance sheet.

The multiplier requires a foundation

Agentic AI systems, autonomous agents that plan, act, observe, and adapt against a defined objective, are past the proof-of-concept phase. McKinsey's State of AI survey reports that 88% of organizations now use AI in at least one function and that 23% are scaling agentic systems somewhere in the enterprise. Equinor disclosed $130 million of AI-created value in a single year. The technology question is settled.

Which organizations will capture the value is a different matter, and I would argue the deciding variable receives almost no attention: who owns your management system.

An agent is, structurally, a Plan-Do-Check-Act loop running at machine speed. Its planning step references a standard. Its actions run against tools and data. It checks observed output against a tolerance and proposes a correction. That is precisely the loop every mature management system already runs, except that the management system runs it episodically, on a human cadence, with a compliance audit every three years. The agent runs it continuously, against live data, every day.

This means your management system is the substrate your agents run on. A documented standard with a defined output, a defined measurement, and a defined tolerance is the technical interface through which an agent operates. Organizations that spent decades building that substrate are AI-ready almost by accident. A 2025 survey of 2,200 knowledge workers found that only 16% describe their workflows as extremely well documented. Disciplined operators solved that problem a generation ago.

Ownership decides the outcome

Throughout my career I have watched one distinction determine performance outcomes more reliably than any other, and it is the same distinction that will determine agentic outcomes.

In some organizations, the management system is operationally owned. The people who run the equipment write the procedures, own the measurements, audit their own work, and close their own corrective actions. The system is how they run the business.

In others, the system is compliance-owned. It lives with an ESH, quality, or audit function, and operations becomes the subject of the standard rather than its customer. Findings are issued from outside, corrective actions compete with operating priorities for attention, and the documented practice quietly drifts away from field practice. The OSHA citation record has told this story for decades: the most frequently cited process safety failures are documentation and verification failures rather than equipment failures. The work was done and the verification was not, because verification was never the operating organization's work to begin with.

Now place an agent on top of each model.

In the operationally-owned organization, the agent detects drift, drafts the corrective action into the CMMS, and routes consequential decisions to the operations leader who owns the standard. The loop closes, because the person receiving the finding holds both the authority and the incentive to act. Every cycle leaves the system sharper, and the improvement compounds like a flywheel.

In the compliance-owned organization, the same agent generates the same findings into a backlog. Deployed against a paper substrate that no one in the operating line owns, the agent becomes a very expensive way to document that the binder does not match the operation.

The technology is identical in both cases. The outcomes are opposite, and ownership is the variable.

The gap is opening during the catch-up

This asymmetry has a time dimension that should concern every executive team.

Building an operationally-owned management system from scratch is a multi-year program even when it goes well, and the transformation literature suggests it usually does not go well. Roughly 70% of large-scale transformations fail, overwhelmingly because programs installed from outside the operating line never embed in daily management. Documenting standards, defining measurements, and embedding audit discipline into an operating culture takes years of sustained leadership attention.

Adopting agentic AI on top of a mature management system, by contrast, is a matter of quarters.

The organization starting both efforts today is therefore running the slow program while competitors who finished the foundation years ago compound through the fast one. The gap widens during the catch-up itself. AI tooling can compress the drafting of procedures, but it cannot compress the embedding of ownership. That work remains leadership work, and the market is not giving that time back.

What I would tell any operating leader to do this quarter

First, answer the ownership question honestly. Five markers reveal the truth: who chairs the management review; who writes and approves procedure revisions; who closes corrective actions and how long they stay open; whether the audit cadence exceeds the regulatory minimum; and where findings route first. If the answer to most of those questions is operations, the foundation is in place. If the answer is ESH, quality, or compliance, the organization owns a binder, and moving ownership to the operating line is the real AI-readiness program. That is a leadership move, not a documentation move.

Second, pilot where the data is rich and the consequences are low. Continuous procedural-compliance monitoring, automated drafting of Management of Change packages for human review, and drift surveillance on process variables between audit cycles are all strong candidates. The objective is to demonstrate an order-of-magnitude improvement in audit frequency and verification fidelity at a fraction of the human cost, with the loop closing inside the operating organization. Showcasing technology proves nothing.

Third, keep humans exactly where the management system already places them. Consequential, irreversible, and safety-critical decisions remain with the operations authority who would have made them in any case. The agent prepares the evidence, and the human decides. Nothing in this model asks a regulator to accept an agent as a responsible party, and nothing needs to.

Fourth, build agentic fluency in the operating function rather than walling it off inside IT. The person who runs the work is the person who knows what an agent should watch for and when the agent is wrong. IT stands up the platform and the security model, and the operating function builds and supervises its agents. This is the same division of labor that has governed spreadsheets for forty years.

The bottom line

Safety, reliability, throughput, environmental performance, and cost discipline were never separate programs. They are what an operating organization produces when it runs its own management system to standard. Agentic AI does not change that truth. It raises the cadence from triennial to continuous, and when the cadence rises, every output rises with it.

The operators who spent thirty years building operational discipline were buying more than compliance. They were building the substrate for the next era of competitive advantage.

Whether your organization will use AI is already settled. Whether your management system, and your ownership model, is ready to multiply it deserves your attention this quarter.

I develop this argument in full, with the supporting evidence, a readiness matrix, and an implementation roadmap, in my white paper "AI: A Case for Safety & Operational Excellence," available at https://bryangmcmurray.com. I welcome perspectives from leaders who see it differently. Feel free to reach out.