Back to briefings
    Briefing

    Governing AI and agents: who decides what

    AI governance as a table of decision rights: the three objects, a five-question test, who decides what an agent may do, and the evidence each decision leaves.

    Governance5 Sept 20269 min read

    ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 42001:2023NIST AI 100-1NIST CSWP 29OWASP Top 10 for LLM Applications 2026Regulation (EU) 2024/1689
    On this page

    What it is

    Ask who owns AI and the answer is usually a document. A policy exists, a committee meets, and the questions have no owner: may we adopt this model, may the assistant send that message, who signs off when it fails.

    AI governance is a table of decision rights before it is a policy. Three objects need separate answers. A model is adopted. A system is put into use for a stated purpose. An agent acts: in GRCIDE's working definition it calls tools, holds permissions, and takes steps between instruction and result. The agent changes the question, because content reaches it. OWASP places prompt injection first in its 2026 list 1. It adds hidden context exposure, recovering instructions and tool schemas behind an assistant 2.

    One loop, not three silos. Deciding who may say yes is governance. Judging what could go wrong, and accepting what an agent may do, is risk. The records, oversight and literacy evidence are what compliance shows.

    Who is in scope (decision test)

    Five questions in order. The written answer is the record.

    1. Is an AI system or model in use, and in which role? Use the scope test in EU AI Act for security governance. Role is not permanent; the table below carries what moves it.
    2. Does anything act on the organisation's behalf? An agent with tools, or an assistant permitted to write rather than draft. If yes, the row needs a permissions answer.
    3. What permissions does it hold, and whose? One shared high-privilege identity is no answer; least privilege follows below.
    4. Is a human oversight duty in force? A high-risk system is designed so natural persons can effectively oversee it in use, with measures matched to risk, autonomy and context of use. The deployer assigns oversight to persons with the necessary competence, training and authority 3.
    5. Who has accepted the residual risk of this use? Named, dated, with an expiry. The method is in Risk acceptance and residual risk; the record is the risk acceptance record, linked from the AI use-case triage form row.
    OutcomeWhat it meansNext step
    DecidedEvery question has a role and a dated recordOperate; review on a calendar
    UndecidedSomething runs that no table coversGrant nothing more; fill the rows
    Needs legal inputRole, class or a rights duty is unclearWritten question, use case attached

    The decision-rights table

    The three disciplines meet here. The decides column is governance; the permissions, autonomy and acceptance rows are risk decisions inside agreed criteria; the evidence column is what compliance produces. The security equivalent is The security operating model.

    DecisionProposesDecidesConsultedEvidenceThe requirement behind it
    Adopt a modelAI governance ownerTop managementSecurity, legal, procurementAdoption record, role decidedArt. 25(1), re-branding, substantial modification or a new high-risk purpose makes the deployer a provider 4
    Approve a use caseBusiness ownerAI governance ownerSecurity, legal, privacyTriage row closed: proceed or stopArt. 26(1), use per the instructions 5
    Grant an agent a permissionRequesting teamOwner of the target systemSecurity, identityApproval with scope and expiryControl 8.2, privileged rights restricted and managed 6
    Let an agent act unsupervisedDelivery leadRisk owner, within criteriaSecurity, legal, oversightAction class and reversibility, datedArt. 14(4)(d) and (e), override, reverse or interrupt 7
    Accept a residual AI riskSecurity functionRisk owner, within criteriaAI governance ownerAcceptance in the register, with expiryArt. 9(1) to 9(2), lifecycle risk management 8
    Disclose to usersAI governance ownerProduct ownerLegal, communicationsThe disclosure as built, and testedArt. 50(1), people are told they interact with AI 9
    Stop a systemAny role, on evidenceThe accountable business roleSecurity, provider, businessSuspension record, notification sentArt. 26(5), inform and suspend on an Art. 79(1) risk 10

    Two rules keep it honest: one role decides per row; a decision not in the table is escalated.

    Four duties sit under the table. Apart from Articles 4 and 50, the articles cited bind only for high-risk systems. Providers and deployers owe AI literacy to staff and others operating systems for them 11. A deployer controlling input data keeps it relevant and sufficiently representative, and employers tell workers' representatives and affected workers before workplace use 12. A fundamental rights impact assessment precedes deployment of an Article 6(2) system by public bodies, public-service providers and Annex III 5(b) and 5(c) deployers. Annex III point 2 systems are excepted 13. Providers run post-market monitoring on a documented plan and report a serious incident within 15 days of awareness, the outer limit 14.

    Agents in particular

    An agent is a new subject inside an old control domain, the reading in Agent governance is a permissions problem. Four decisions carry the exposure.

    The identity. An agent connecting as its installer inherits all that person can reach. Access rules come from business and information security requirements 15, and access is restricted in line with it 16. An agent needs its own scoped identity.

    The tool list. OWASP gives excessive functionality, excessive permissions and excessive autonomy as the root causes of excessive agency 17. An approved allow-list is the governance form of that finding: written, reviewed, shortened when a tool stops earning it. Third-party tools and models are their own supply-chain question 18.

    The loop. Whether an action class needs a person is a governance choice, not an engineering default. GRCIDE's working view is that the line worth drawing is reversibility: what can be undone may auto-approve, what cannot goes to a named human. The statutory floor is the overseer's powers.

    The record. Logs of activity, exceptions, faults and relevant events are produced, stored, protected and analysed 19. High-risk systems record events automatically over their lifetime, and deployers keep those logs for at least six months 20. Cost belongs here too. Unbounded consumption is its own 2026 entry 21. An agent that loops is a budget event before it is a breach.

    Dates (verified)

    Three Article 113 rows matter; the AI Act briefing carries the rest.

    DateWhat happensSource
    2026-08-02General application22
    2027-12-02Chapter III Sections 1 to 3, Article 6(2) systems, less Article 6(5)23
    2028-08-02The same for Article 6(1) systems24

    Mapping to NIST AI RMF and ISO/IEC 42001

    Identifiers and names as published 25, clause titles as logged 26.

    DecisionNIST AI RMF 1.0ISO/IEC 42001:2023ISO/IEC 27002:2022Gap
    Adopt a modelGOVERN 1.6 inventory; GOVERN 6.1 third-party4.4 AI management system5.2 Information security roles and responsibilities 27No legal role test
    Approve a use caseMANAGE 1.1 whether deployment proceeds8.2 AI risk assessment5.2 as aboveNo class or date
    Grant an agent a permissionGOVERN 2.1 roles, communication lines5.3 Roles, responsibilities and authorities8.2 Privileged access rights; 8.3 Information access restrictionAgent identities named nowhere
    Act unsupervisedGOVERN 3.2 human-AI configurations5.2 AI policy5.3 Segregation of dutiesReversibility not a category
    Accept a residual AI riskMANAGE 1.3 responses; MANAGE 1.4 residual risks8.3 AI risk treatment5.2, as aboveNo acceptor or expiry
    Disclose to usersGOVERN 4.2 impacts communicatedNo logged clause covers disclosure or its timing
    Stop a systemMANAGE 2.4 deactivate; GOVERN 1.7 decommissioning9.1 Monitoring, measurement, analysis and evaluation8.15 LoggingWho pulls the switch

    Two anchors sit outside them. The management system carries clauses 5.3, 6.1.2, 6.1.3 and 9.1 28. NIST CSF 2.0 carries Roles, Responsibilities, and Authorities; Cybersecurity Supply Chain Risk Management; and Identity Management, Authentication, and Access Control 29. In GRCIDE's working view, as in GRC automation patterns, an agent estate is a new population inside them.

    Next 90 days

    WeekActionOwnerOutput
    1-2List models, systems and agents separately; draft the tableAI governance ownerInventory; draft
    2-3Approve the table; the AI governance stand-up is the escalation routeTop managementApproved table
    3-4Give each agent a scoped identity and a tool allow-listIdentity managementAllow-lists
    4-6Classify actions by reversibility; set which need a personRisk ownerAction classes
    5-7Set logging and retention per Article 12 and 26(6)Platform engineeringRetention tested
    6-8Record oversight assignments, competence, literacy planAI governance ownerOverseers; training
    8-12Re-run risk assessment over the agent estate; rehearse a stopSecurity functionAcceptances; log

    References

    ISO/IEC 27002:2022 controls are paraphrased from a licensed copy.

    1. European Parliament and Council. Regulation (EU) 2024/1689, consolidated text of 27 July 2026. CELEX 02024R1689-20260727. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
    2. NIST. AI Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
    3. NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
    4. OWASP GenAI Security Project. OWASP Top 10 for LLM Applications 2026. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
    5. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en
    6. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html
    7. ISO/IEC 42001:2023. https://www.iso.org/standard/42001

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST, OWASP or any other standards body.

    Sources

    1. 1OWASP Top 10 for LLM Applications 2026, LLM01, genai.owasp.org · verified 2026-09-05
    2. 2OWASP Top 10 for LLM Applications 2026, LLM08, genai.owasp.org · verified 2026-09-05
    3. 3EU Publications Office CELEX 02024R1689-20260727 Art. 14(1), 14(3) and 26(2) · verified 2026-09-05
    4. 4EU Publications Office CELEX 02024R1689-20260727 Art. 25(1) · verified 2026-09-05
    5. 5EU Publications Office CELEX 02024R1689-20260727 Art. 26(1) · verified 2026-09-05
    6. 6ISO/IEC 27002:2022 control 8.2, licensed copy · verified 2026-09-05
    7. 7EU Publications Office CELEX 02024R1689-20260727 Art. 14(4)(d) and 14(4)(e) · verified 2026-09-05
    8. 8EU Publications Office CELEX 02024R1689-20260727 Art. 9(1) to 9(2) · verified 2026-09-05
    9. 9EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) · verified 2026-09-05
    10. 10EU Publications Office CELEX 02024R1689-20260727 Art. 26(5) · verified 2026-09-05
    11. 11EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
    12. 12EU Publications Office CELEX 02024R1689-20260727 Art. 26(4) and 26(7) · verified 2026-09-05
    13. 13EU Publications Office CELEX 02024R1689-20260727 Art. 27(1) · verified 2026-09-05
    14. 14EU Publications Office CELEX 02024R1689-20260727 Art. 72(1) to 72(3) and Art. 73(2) · verified 2026-09-05
    15. 15ISO/IEC 27002:2022 control 5.15, licensed copy · verified 2026-09-05
    16. 16ISO/IEC 27002:2022 control 8.3, licensed copy · verified 2026-09-05
    17. 17OWASP Top 10 for LLM Applications 2026, LLM03, genai.owasp.org · verified 2026-09-05
    18. 18OWASP Top 10 for LLM Applications 2026, LLM04, genai.owasp.org · verified 2026-09-05
    19. 19ISO/IEC 27002:2022 control 8.15, licensed copy · verified 2026-09-05
    20. 20EU Publications Office CELEX 02024R1689-20260727 Art. 12(1) and Art. 26(6) · verified 2026-09-05
    21. 21OWASP Top 10 for LLM Applications 2026, LLM06, genai.owasp.org · verified 2026-09-05
    22. 22EU Publications Office CELEX 02024R1689-20260727 Art. 113 second paragraph · verified 2026-09-05
    23. 23EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(i) · verified 2026-09-05
    24. 24EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(ii) · verified 2026-09-05
    25. 25NIST AI 100-1 Table 1 and Table 4, nvlpubs.nist.gov · verified 2026-09-05
    26. 26ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
    27. 27ISO/IEC 27002:2022 controls 5.2 and 5.3, licensed copy · verified 2026-09-05
    28. 28ISO/IEC 27001:2022 clauses 5.3, 6.1.2, 6.1.3 and 9.1, iso.org/obp · verified 2026-09-03
    29. 29NIST CSWP 29 Appendix A GV.RR, GV.SC and PR.AA, nvlpubs.nist.gov · verified 2026-09-05