The Account Operators group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit.
Another option, if you want to grant even fewer permissions, is to create a new group and delegate control for your computers OU to that group only for the "Create, delete, and manage user accounts" permissions.
So the first option grants permissions in all of the OUs and the second option only grants for specific OUs.