What is agent governance?
This is the layer that keeps an individual running AI agent accountable for what it does. It works underneath the bigger rules set by the organization; it doesn't replace them. The organization's policies still decide what is allowed and who is allowed to do it. This layer is the machinery that makes sure each individual agent follows those rules and can show proof that it did.
The distinction from the wider discipline comes down to two things, and both matter operationally.
| Question | AI governance | Agent governance |
|---|---|---|
| The unit | A system or a use case, assessed and approved | One agent instance, of which there are many and more each week |
| The cadence | Periodic. Assessment, sign-off, review | Continuous. The agent is acting while you are reading this |
| The artefact | A register of decisions, risk classifications and standards mapping | A live inventory, scoped permissions, and a trace of every action |
| The failure | A system deployed without appropriate assessment | An agent nobody registered, doing something nobody authorised |
Neither replaces the other and confusing them is expensive in a specific way. An organisation can hold a mature governance programme, correctly mapped to the standards, and still have no idea how many agents are running. The frameworks, the regulatory timeline and the decision-rights question are covered at AI governance. This page is the operational layer beneath it.
Why does the Agent population break the approval model?
Approval works fine when new things show up now and then. Building an AI model used to be a big project, needing a team, months of work, real budget. So, it made sense to check every model carefully before launch.
Agents are different. Making one does not take a big project anymore. Any skilled engineer can build a working agent over a given afternoon.
So, a process built to check a few big, rare things now has to deal with a flood of small, easy ones. The approval process was not built to handle that many, which is why it breaks down. You cannot check every agent as carefully as you once checked a full model.
The arithmetic is what breaks, not the intent.
- Creation is decentralised, approval is not. Many teams can create; one body approves. That asymmetry compounds every month rather than settling.
- The reasonable response makes it worse. Tightening approval slows delivery, so teams route around it, and the agents you least know about become the ones with the least oversight. This is the mechanism described at agent sprawl.
- Agents change after approval. A model assessed in March is the same model in September. An agent given a new tool in September is a different agent, and nothing in a point-in-time assessment notices.
- Most agents are small. Individually they do not merit a committee, and collectively they hold real reach. Governance sized for the consequential ones ignores the population that actually carries the risk.
Which leads to the conclusion that shapes everything else on this page. You cannot govern a growing population through a process that runs on a calendar. The controls have to be in the path the agent takes, applied automatically, with human judgment reserved for the cases that genuinely need it.
What are the three questions it has to answer?
What exists, what may each one do, and what did each one actually do. Every agent governance conversation reduces to those three, and an organisation that cannot answer all three for any given agent does not have agent governance regardless of what its policy documents say.
Each maps onto a different control, and they are usually built in this order because each depends on the one before it.
- 01
What existsA live inventory with an owner against every entry, discovered rather than self-declared. Why it comes first: the other two controls can only be applied to agents you know about, so this is the prerequisite rather than the paperwork. See agent registry.
- 02
What may it doScoped tools and data, its own credential, a spend ceiling, and approval required on anything irreversible. Why it matters more than accuracy work: it bounds the worst case rather than shifting its probability. See AI guardrails and agent identity.
- 03
What did it doEvery model and tool call recorded with the agent, the model, the human it acted for, and the cost. Why the human matters: without it you can show what happened and not on whose authority. See AI audit trail.
The useful property of this framing is that it is testable rather than aspirational. Pick an agent at random, ask all three questions, and time how long the answers take. A governance programme that cannot answer them in minutes will not answer them during an incident either, and an incident is when the questions actually get asked.
Why must Agent Governance run at runtime?
Because the thing being governed is acting continuously, and a control that only operates before deployment governs a snapshot. The shift is from assessing whether a system should be allowed to a position where permitted behaviour is enforced as the system runs.
Three consequences follow, and each replaces a familiar practice rather than supplementing it.
- Assessment becomes a gate rather than the control. Pre-deployment review still matters and it stopped being sufficient once the output space became unbounded, which is the argument at generative AI. The control is what holds while the agent runs.
- Policy has to compile into configuration. A rule stating that customer data may not leave the region is governance when it is a network constraint and a preference when it is a sentence in a document. If a policy cannot be expressed as a scope, a gate or an alert, it will not be enforced.
- Evidence is produced rather than assembled. Gathering evidence after the fact is expensive and incomplete. A trace that already records agent, model, actor and cost turns an audit into a query.
Who owns an agent?
Someone in the business must be named responsible for the agent, not the engineering team that built it. This question usually goes unanswered.
Engineering can explain what an agent does but cannot own the consequences of what it decides. Those consequences land in a business process that engineering does not run.
Four roles, and the second is where programmes stall.
| Role | Accountable for |
|---|---|
| Builder | What the agent does, how it is tested, what it is permitted to reach. Usually well defined already |
| Business owner | The outcome of the actions it takes, and the decision to keep running it. The role most often vacant |
| Risk | Whether the controls match the exposure, and what triggers escalation |
| Whoever can stop it | Holding the authority and the access to halt it, on a weekend, without an engineering cycle |
The two marked rows are the ones to fill first. An agent with no business owner is an agent nobody will retire, because retirement requires somebody to accept that the work it was doing now needs doing another way. That is the quiet reason agent estates only grow, and it is a governance failure rather than a technical one.
How do you start?
By finding what you already have, before writing anything. Most organisations discover more agents in use than anyone recorded, and the unrecorded ones hold the credentials nobody rotates. Policy written before that discovery describes an estate that does not exist.
Five steps, ordered by what each one makes possible.
-
Discover, do not survey
Ask the platforms rather than the people. Self-declaration misses exactly the agents you most want to find, because the ones nobody registered are the ones nobody will remember to mention.
-
Put an owner against every entry, even a provisional one
A name in a field is worth more than an accurate but empty register. Provisional owners get corrected quickly; absent owners stay absent.
-
Bound before you assess
Scope what each agent can reach and cap what it can spend, ahead of any quality or risk review. A bounded agent that is sometimes wrong is manageable; an unbounded one that is usually right is not.
-
Turn three policies into controls as a test
Take three rules from your existing AI policy and express each as a scope, a gate or an alert. The ones that will not compile are the ones that were never going to be enforced, and finding that out early is the point.
-
Run the three questions as a drill
Pick an agent at random each month and time how long it takes to answer what it is, what it may do and what it did last week. The trend in that number is the most honest governance metric available.
One note on sequencing that runs against how these programmes are usually sold. Standards conformance is a consequence of having the controls, not a route to them. A management system standard tells you which controls to hold and evidence; it does not build the inventory, scope the permissions or produce the trace. Teams that certify first and instrument second end up with documentation describing an estate they still cannot see.