They read email, query databases, execute code, call APIs, and take actions in external systems based on goals set by users or other automated systems. The governance frameworks that most organizations have built for AI — focused on model transparency, bias assessment, and explainability of individual outputs — were designed for a different kind of system. Agentic AI requires a different kind of governance.
What Makes Agents Different
The core governance challenge of agentic AI is autonomy at depth. A language model that generates text for a user to review produces an output that a human evaluates before any action is taken. An AI agent that is given access to email, calendar, and CRM systems to manage customer communications operates in the world. It takes actions. Those actions have consequences in external systems, in vendor relationships, in data records. The human oversight model that works for reviewed outputs does not work for autonomous actions in the same way.
Agents also operate across tool boundaries in ways that single-model systems do not. An agent orchestrating a customer onboarding workflow might access an identity system to create an account, a CRM to create a customer record, a document management system to generate contracts, and an email system to send communications — all within a single task execution. Each tool access creates a data flow. Each data flow creates a governance event. The agent's orchestration layer connects these events into a single workflow that no individual governance mechanism was designed to observe.
The third distinction is persistence. Agents that maintain state across interactions accumulate context about users, preferences, and prior decisions. That accumulated context is data. It has privacy implications. It has security implications. It may be shared across sessions in ways the user did not understand when they initiated the first interaction. The governance of what an agent knows, for how long, and what it does with that knowledge is a privacy challenge that most AI governance programs have not addressed because it did not exist in the systems those programs were designed for.
An AI agent with access to your email, your CRM, and your customer database is not a chatbot that sometimes takes action. It is a system with broad data access, autonomous decision authority, and persistent state. Govern it accordingly.
Where Existing Governance Frameworks Fall Short
The EU AI Act's Gaps for Agents
The EU AI Act was designed primarily around AI systems that make or assist in making discrete decisions. High-risk classifications focus on systems used in specific regulated domains: employment, credit, law enforcement, education. AI agents that orchestrate workflows across enterprise systems may not fall cleanly into these categories, even as they exercise significant decision authority over consequential processes. The Act's transparency and documentation requirements were designed for explainable outputs, not for explainable multi-step action chains.
ISO 42001 and Agent Lifecycle
ISO 42001's AI management system framework addresses the AI system lifecycle: development, deployment, monitoring, decommissioning. For agentic systems, the lifecycle question becomes more complex because agents can be modified dynamically — new tools added, permissions changed, goals updated — without a formal model update that would trigger a lifecycle governance event. The agent that was assessed at deployment and the agent operating six months later may have materially different capabilities and data access. The ISO 42001 lifecycle model was not designed for this kind of continuous capability evolution.
NIST AI RMF and Emergent Behavior
The NIST AI Risk Management Framework emphasizes testing and measurement of AI system behavior as a core governance mechanism. For agentic systems, the behavior that matters is not only the behavior of the agent in isolation — it is the behavior that emerges from the agent's interaction with the tools, data, and external systems in its environment. Emergent behavior in complex tool environments is difficult to characterize through pre-deployment testing because the test environment does not replicate the full complexity of the production tool environment.
What Governing Agents Actually Requires
Action Authorization, Not Just Output Review
Agent governance requires defining what actions an agent is authorized to take, under what conditions, and with what approval requirements. This is an authorization framework for agent behavior, analogous to the access control framework that governs human user behavior. An agent with access to the CRM and email systems should have a defined authorization policy that specifies what data it can read, what records it can modify, and what communications it can send — and under what conditions human approval is required before action.
Tool Access Governance
Every tool an agent has access to is an access control question. The agent's tool access should be governed with the same rigor as human user access: minimum necessary access for the defined task, time-bounded access where appropriate, logging of all tool use, and regular review of whether the agent's tool access remains appropriate. Most organizations that have deployed AI agents have provisioned their tool access for capability rather than for governance — giving agents the access needed to perform their tasks without applying the least-privilege analysis that would apply to a human user with the same access.
Audit Trails for Action Chains
When an agent executes a multi-step workflow, the audit trail must capture the full action chain — not only the inputs and outputs of individual model calls, but the sequence of tool uses, the data accessed at each step, the decisions made at each branch point, and the external actions taken. This is a different audit logging requirement than the logging designed for single-model inference. Building it requires instrumenting the agent's orchestration layer, not only its model calls.
Prompt Injection as a Security Threat
AI agents that read external content — email, documents, web pages — are vulnerable to prompt injection: malicious instructions embedded in external content that cause the agent to deviate from its intended task. An agent that reads customer email and encounters a message containing instructions to forward all future emails to an external address may follow those instructions if its instruction-following architecture does not distinguish between legitimate user instructions and malicious injected instructions. Prompt injection is an attack vector that is specific to agentic AI and that most security programs have not included in their threat models.
The Governance Posture Organizations Need
Governing agentic AI well requires treating agents as operational systems with access rights, not as conversational tools. The agent has an identity in your environment. It has access to systems and data. It takes actions. Those identity, access, and action dimensions require governance that mirrors the governance applied to human users and automated service accounts — because in operational terms, that is exactly what an agent is.
The organizations that are ahead on this have started by inventorying what their agents can access and do, applying access governance to agent credentials with the same rigor as human access, and building audit logging at the orchestration layer. They have not waited for the governance frameworks to catch up. The frameworks are behind the technology. Waiting for the frameworks means operating ungoverned agents in production environments for an extended period.
Govern the agent like the operational system it is. Its access, its actions, and its data trail all require the same governance discipline you apply to everything else in your environment.
The AI governance framework you built for inference systems will not govern agentic systems. Build what the new architecture requires before the new architecture creates the incident that demonstrates why.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
