Governance

Agentic AI Governance: Do Your Controls Keep Pace with Your AI Agents?

Radar chart of six agentic AI governance control domains compared with a target

Most AI governance programmes were built for models that answer questions. Agents are different. An agent plans a task, picks tools, and acts: it updates a CRM record, sends an email, files a ticket, runs code or moves money. When it gets something wrong, the consequence is an action in the real world, not a bad paragraph.

That changes what governance has to do. This article explains how to think about agentic AI governance, the six control domains that matter, the red flags that should pause a rollout, and how to check where you stand with our free agentic AI governance assessment.

Take the assessment

18 questions, about 8 minutes, instant results, no sign-up. Start the agentic AI governance assessment. For the organisation-wide view, use the AI governance maturity assessment.

Why Governing Agents Is Different

Three properties make agents harder to govern than a model behind a chat window.

  • They act. Risk comes from what the agent can do, not only from what the model can say. Two agents on the same model can carry very different risk if one only reads documents and the other can issue refunds.
  • They read untrusted content. Web pages, emails, documents and tool results can contain instructions. An agent that acts on what it reads can be steered by whoever wrote it.
  • They are easy to create. Agents can be started inside SaaS tools, low-code platforms and developer environments. Many organisations do not know how many they have.

The practical consequence is that the questions move from "is the model accurate?" to "who is this agent, what is it allowed to touch, who approves what it does, can we stop it, and can we prove what happened?"

The Autonomy Ladder: Controls Must Scale with Freedom

The most useful idea in agent governance is simple: the more freedom an agent has, the stronger the controls around it need to be. It helps to name the rungs.

LevelWhat the agent doesWhat it needs
AssistiveDrafts or suggests. A person takes every action.Basic inventory, data handling rules, staff awareness
SupervisedActs, but a person approves each consequential step.Distinct identity, scoped permissions, approval gates, action logs
Autonomous within limitsActs without per-action approval inside set limits.All of the above, plus a tested stop control, anomaly detection, adversarial testing
Multi-agent or long-runningAgents coordinate, delegate or run for extended periods.End-to-end traceability, central policy enforcement, independent assurance

Reach matters as much as autonomy. An agent that only reads data is a different proposition from one that sends messages to customers or spends money, even at the same level of autonomy. Our assessment takes both into account when it sets your targets.

Six Control Domains for AI Agents

These are the areas the assessment scores, each with the question it answers and a typical way it fails.

DomainThe question it answersA typical failure
Accountability, inventory and risk contextWhich agents exist, who owns each one, and how risky is it?A team's agent in a SaaS tool that nobody in security knows about
Identity, access and least privilegeDoes each agent have its own identity and only the access its task needs?Agents running on a shared service account with broad standing access
Tools, data and supply chainAre the tools and data an agent touches vetted, and is it defended against injected instructions?A connector added without review that exposes more data than intended
Human control and autonomy boundariesWhich actions need approval, can we stop the agent, and is oversight real?Approvals that are rubber-stamped, or no way to pause a runaway agent
Observability, detection and responseCan we reconstruct what an agent did, spot odd behaviour and respond?No record of the tool calls behind a bad outcome
Assurance, guardrails and adaptationAre guardrails enforced consistently, tested adversarially and improved over time?Each team writing its own prompt-level guardrails, with no testing

If you already run a three-lines-of-defence model for AI, as described in our EU AI Act timeline guide, agents slot into it: product teams own the controls, a second line sets standards and challenges, and an independent party checks the evidence.

Seven Red Flags That Should Pause a Rollout

The assessment raises a red flag when a gap in one control meets a profile that makes it dangerous. These are the ones to look for in your own estate.

  1. No dependable way to stop an autonomous agent. Without a tested pause control and a way to reverse actions, a fault keeps running.
  2. Agent actions cannot be attributed. Shared or personal credentials mean you cannot tell which agent did what, or revoke one agent on its own.
  3. External or financial actions without approval gates. Nothing decides which outward-facing actions need a person first.
  4. Untrusted content can steer the agent. If instructions hidden in a document or web page can change what an acting agent does, anyone who can put text in front of it has influence.
  5. Broad standing permissions. More access than the task needs turns every mistake into a bigger incident.
  6. Agent actions are not reliably logged. You cannot investigate an incident or evidence oversight without records.
  7. Agents you do not know about. No register means no control.

How the Assessment Works

  1. Describe your agents. Pick the highest autonomy you run or plan to run in the next 12 months, how far your most capable agent can reach, and whether you are regulated or EU-facing.
  2. Answer 18 questions. Three per domain, each on a five-step scale from "not in place" to "optimized", with a short explanation of why it matters.
  3. Get your results immediately. You see your overall maturity, a radar chart of the six domains against the target for your profile, any red flags, and tiered next steps for each domain.

The headline result is the level of autonomy your controls currently support. It is limited by the weakest of three domains: identity, human control and observability. If you run more autonomy than that, the tool tells you so plainly. Your answers are not sent to a server, and the results page has a link you can share.

Take the agentic AI governance assessment or compare with your organisation-wide position using the AI governance maturity assessment.

What to Do with Your Results

Whatever the scores say, the order of work is usually the same.

  1. Find your agents. Build a register with owner, purpose, tools, data and autonomy level. Ask teams what they run in SaaS and low-code tools, not only what they built.
  2. Fix identity and permissions. Give each production agent its own identity, remove standing access it does not need, and move secrets out of prompts.
  3. Decide what needs a human. List the irreversible, financial, external-facing and sensitive-data actions and require approval for them, enforced in the platform rather than in a prompt.
  4. Make agents observable and stoppable. Log actions in a protected, searchable form and build a pause control you have actually tested.
  5. Test adversarially. Try injected instructions, requests to exceed permissions and attempts to leak data, before release and after every significant change.
  6. Review on a schedule. Feed incidents and near misses back into the controls, and widen an agent's autonomy only as evidence supports it.

A self-assessment shows where to look. It does not verify the evidence. If you want an independent check of your register, permissions, logs and test results, see our AI governance services.

Where the EU AI Act Fits

The EU AI Act regulates AI systems by use case and by your role, not by architecture. An agent is therefore covered if what it does falls into a regulated category. Several of the control domains line up with obligations that apply to high-risk systems:

  • Human control supports human oversight (Article 14) and deployer duties (Article 26).
  • Observability supports record-keeping (Article 12) and incident reporting (Article 73).
  • Identity, tools and testing support the robustness and cybersecurity expectations in Article 15.
  • Accountability and inventory support risk management (Article 9) and the AI literacy duty in Article 4.

Annex III high-risk obligations apply from 2 December 2027, and transparency rules in Article 50 already apply to agents that interact with people or generate content. The full list of dates is in our EU AI Act timeline. The assessment measures governance and security maturity. It is not a compliance determination, and whether an agent is high-risk needs its own classification.

Frequently Asked Questions

What is agentic AI governance?

Agentic AI governance is the set of accountability, security, oversight and monitoring controls that let an organisation use AI agents, which plan and take actions through tools, without losing control of what they do. The controls need to scale with the autonomy and reach of each agent.

How is governing an AI agent different from governing a chatbot?

A chatbot produces text that a person then uses. An agent can act: change records, send messages, spend money or run code. That makes identity, permissions, approval gates, the ability to stop the agent, and action-level logging central, where for a chatbot content quality and data protection dominate.

What is the biggest risk with AI agents?

The risks that matter most are agents holding more access than their task needs, untrusted content steering what they do (prompt injection), and no reliable way to stop them or see what they did. These compound as autonomy rises, so the assessment sets a higher target for more autonomous agents.

Does the EU AI Act cover AI agents?

The Act regulates AI systems by use case and role, not by architecture, so an agent is covered if it falls into a regulated category. Human oversight (Article 14), record-keeping (Article 12) and deployer duties (Article 26) apply to high-risk systems, with Annex III obligations due from 2 December 2027. Transparency rules in Article 50 already apply to agents that interact with people or generate content.

Is the assessment free and private?

Yes. It is free, needs no sign-up, and scoring runs in your browser, so your answers are not sent to a server.

This article is general information and not legal advice.

Read More