Governing AI and agents: who decides what
AI governance as a table of decision rights: the three objects, a five-question test, who decides what an agent may do, and the evidence each decision leaves.
Governance5 Sept 20269 min read
On this page
What it is
Ask who owns AI and the answer is usually a document. A policy exists, a committee meets, and the questions have no owner: may we adopt this model, may the assistant send that message, who signs off when it fails.
AI governance is a table of decision rights before it is a policy. Three objects need separate answers. A model is adopted. A system is put into use for a stated purpose. An agent acts: in GRCIDE's working definition it calls tools, holds permissions, and takes steps between instruction and result. The agent changes the question, because content reaches it. OWASP places prompt injection first in its 2026 list 1. It adds hidden context exposure, recovering instructions and tool schemas behind an assistant 2.
One loop, not three silos. Deciding who may say yes is governance. Judging what could go wrong, and accepting what an agent may do, is risk. The records, oversight and literacy evidence are what compliance shows.
Who is in scope (decision test)
Five questions in order. The written answer is the record.
- Is an AI system or model in use, and in which role? Use the scope test in EU AI Act for security governance. Role is not permanent; the table below carries what moves it.
- Does anything act on the organisation's behalf? An agent with tools, or an assistant permitted to write rather than draft. If yes, the row needs a permissions answer.
- What permissions does it hold, and whose? One shared high-privilege identity is no answer; least privilege follows below.
- Is a human oversight duty in force? A high-risk system is designed so natural persons can effectively oversee it in use, with measures matched to risk, autonomy and context of use. The deployer assigns oversight to persons with the necessary competence, training and authority 3.
- Who has accepted the residual risk of this use? Named, dated, with an expiry. The method is in Risk acceptance and residual risk; the record is the risk acceptance record, linked from the AI use-case triage form row.
| Outcome | What it means | Next step |
|---|---|---|
| Decided | Every question has a role and a dated record | Operate; review on a calendar |
| Undecided | Something runs that no table covers | Grant nothing more; fill the rows |
| Needs legal input | Role, class or a rights duty is unclear | Written question, use case attached |
The decision-rights table
The three disciplines meet here. The decides column is governance; the permissions, autonomy and acceptance rows are risk decisions inside agreed criteria; the evidence column is what compliance produces. The security equivalent is The security operating model.
| Decision | Proposes | Decides | Consulted | Evidence | The requirement behind it |
|---|---|---|---|---|---|
| Adopt a model | AI governance owner | Top management | Security, legal, procurement | Adoption record, role decided | Art. 25(1), re-branding, substantial modification or a new high-risk purpose makes the deployer a provider 4 |
| Approve a use case | Business owner | AI governance owner | Security, legal, privacy | Triage row closed: proceed or stop | Art. 26(1), use per the instructions 5 |
| Grant an agent a permission | Requesting team | Owner of the target system | Security, identity | Approval with scope and expiry | Control 8.2, privileged rights restricted and managed 6 |
| Let an agent act unsupervised | Delivery lead | Risk owner, within criteria | Security, legal, oversight | Action class and reversibility, dated | Art. 14(4)(d) and (e), override, reverse or interrupt 7 |
| Accept a residual AI risk | Security function | Risk owner, within criteria | AI governance owner | Acceptance in the register, with expiry | Art. 9(1) to 9(2), lifecycle risk management 8 |
| Disclose to users | AI governance owner | Product owner | Legal, communications | The disclosure as built, and tested | Art. 50(1), people are told they interact with AI 9 |
| Stop a system | Any role, on evidence | The accountable business role | Security, provider, business | Suspension record, notification sent | Art. 26(5), inform and suspend on an Art. 79(1) risk 10 |
Two rules keep it honest: one role decides per row; a decision not in the table is escalated.
Four duties sit under the table. Apart from Articles 4 and 50, the articles cited bind only for high-risk systems. Providers and deployers owe AI literacy to staff and others operating systems for them 11. A deployer controlling input data keeps it relevant and sufficiently representative, and employers tell workers' representatives and affected workers before workplace use 12. A fundamental rights impact assessment precedes deployment of an Article 6(2) system by public bodies, public-service providers and Annex III 5(b) and 5(c) deployers. Annex III point 2 systems are excepted 13. Providers run post-market monitoring on a documented plan and report a serious incident within 15 days of awareness, the outer limit 14.
Agents in particular
An agent is a new subject inside an old control domain, the reading in Agent governance is a permissions problem. Four decisions carry the exposure.
The identity. An agent connecting as its installer inherits all that person can reach. Access rules come from business and information security requirements 15, and access is restricted in line with it 16. An agent needs its own scoped identity.
The tool list. OWASP gives excessive functionality, excessive permissions and excessive autonomy as the root causes of excessive agency 17. An approved allow-list is the governance form of that finding: written, reviewed, shortened when a tool stops earning it. Third-party tools and models are their own supply-chain question 18.
The loop. Whether an action class needs a person is a governance choice, not an engineering default. GRCIDE's working view is that the line worth drawing is reversibility: what can be undone may auto-approve, what cannot goes to a named human. The statutory floor is the overseer's powers.
The record. Logs of activity, exceptions, faults and relevant events are produced, stored, protected and analysed 19. High-risk systems record events automatically over their lifetime, and deployers keep those logs for at least six months 20. Cost belongs here too. Unbounded consumption is its own 2026 entry 21. An agent that loops is a budget event before it is a breach.
Dates (verified)
Three Article 113 rows matter; the AI Act briefing carries the rest.
Mapping to NIST AI RMF and ISO/IEC 42001
Identifiers and names as published 25, clause titles as logged 26.
| Decision | NIST AI RMF 1.0 | ISO/IEC 42001:2023 | ISO/IEC 27002:2022 | Gap |
|---|---|---|---|---|
| Adopt a model | GOVERN 1.6 inventory; GOVERN 6.1 third-party | 4.4 AI management system | 5.2 Information security roles and responsibilities 27 | No legal role test |
| Approve a use case | MANAGE 1.1 whether deployment proceeds | 8.2 AI risk assessment | 5.2 as above | No class or date |
| Grant an agent a permission | GOVERN 2.1 roles, communication lines | 5.3 Roles, responsibilities and authorities | 8.2 Privileged access rights; 8.3 Information access restriction | Agent identities named nowhere |
| Act unsupervised | GOVERN 3.2 human-AI configurations | 5.2 AI policy | 5.3 Segregation of duties | Reversibility not a category |
| Accept a residual AI risk | MANAGE 1.3 responses; MANAGE 1.4 residual risks | 8.3 AI risk treatment | 5.2, as above | No acceptor or expiry |
| Disclose to users | GOVERN 4.2 impacts communicated | — | — | No logged clause covers disclosure or its timing |
| Stop a system | MANAGE 2.4 deactivate; GOVERN 1.7 decommissioning | 9.1 Monitoring, measurement, analysis and evaluation | 8.15 Logging | Who pulls the switch |
Two anchors sit outside them. The management system carries clauses 5.3, 6.1.2, 6.1.3 and 9.1 28. NIST CSF 2.0 carries Roles, Responsibilities, and Authorities; Cybersecurity Supply Chain Risk Management; and Identity Management, Authentication, and Access Control 29. In GRCIDE's working view, as in GRC automation patterns, an agent estate is a new population inside them.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | List models, systems and agents separately; draft the table | AI governance owner | Inventory; draft |
| 2-3 | Approve the table; the AI governance stand-up is the escalation route | Top management | Approved table |
| 3-4 | Give each agent a scoped identity and a tool allow-list | Identity management | Allow-lists |
| 4-6 | Classify actions by reversibility; set which need a person | Risk owner | Action classes |
| 5-7 | Set logging and retention per Article 12 and 26(6) | Platform engineering | Retention tested |
| 6-8 | Record oversight assignments, competence, literacy plan | AI governance owner | Overseers; training |
| 8-12 | Re-run risk assessment over the agent estate; rehearse a stop | Security function | Acceptances; log |
References
ISO/IEC 27002:2022 controls are paraphrased from a licensed copy.
- European Parliament and Council. Regulation (EU) 2024/1689, consolidated text of 27 July 2026. CELEX 02024R1689-20260727. Read at the Cellar, 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
- NIST. AI Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
- OWASP GenAI Security Project. OWASP Top 10 for LLM Applications 2026. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
- ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en
- ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html
- ISO/IEC 42001:2023. https://www.iso.org/standard/42001
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST, OWASP or any other standards body.
Sources
- 1OWASP Top 10 for LLM Applications 2026, LLM01, genai.owasp.org · verified 2026-09-05
- 2OWASP Top 10 for LLM Applications 2026, LLM08, genai.owasp.org · verified 2026-09-05
- 3EU Publications Office CELEX 02024R1689-20260727 Art. 14(1), 14(3) and 26(2) · verified 2026-09-05
- 4EU Publications Office CELEX 02024R1689-20260727 Art. 25(1) · verified 2026-09-05
- 5EU Publications Office CELEX 02024R1689-20260727 Art. 26(1) · verified 2026-09-05
- 6ISO/IEC 27002:2022 control 8.2, licensed copy · verified 2026-09-05
- 7EU Publications Office CELEX 02024R1689-20260727 Art. 14(4)(d) and 14(4)(e) · verified 2026-09-05
- 8EU Publications Office CELEX 02024R1689-20260727 Art. 9(1) to 9(2) · verified 2026-09-05
- 9EU Publications Office CELEX 02024R1689-20260727 Art. 50(1) · verified 2026-09-05
- 10EU Publications Office CELEX 02024R1689-20260727 Art. 26(5) · verified 2026-09-05
- 11EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
- 12EU Publications Office CELEX 02024R1689-20260727 Art. 26(4) and 26(7) · verified 2026-09-05
- 13EU Publications Office CELEX 02024R1689-20260727 Art. 27(1) · verified 2026-09-05
- 14EU Publications Office CELEX 02024R1689-20260727 Art. 72(1) to 72(3) and Art. 73(2) · verified 2026-09-05
- 15ISO/IEC 27002:2022 control 5.15, licensed copy · verified 2026-09-05
- 16ISO/IEC 27002:2022 control 8.3, licensed copy · verified 2026-09-05
- 17OWASP Top 10 for LLM Applications 2026, LLM03, genai.owasp.org · verified 2026-09-05
- 18OWASP Top 10 for LLM Applications 2026, LLM04, genai.owasp.org · verified 2026-09-05
- 19ISO/IEC 27002:2022 control 8.15, licensed copy · verified 2026-09-05
- 20EU Publications Office CELEX 02024R1689-20260727 Art. 12(1) and Art. 26(6) · verified 2026-09-05
- 21OWASP Top 10 for LLM Applications 2026, LLM06, genai.owasp.org · verified 2026-09-05
- 22EU Publications Office CELEX 02024R1689-20260727 Art. 113 second paragraph · verified 2026-09-05
- 23EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(i) · verified 2026-09-05
- 24EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (c)(ii) · verified 2026-09-05
- 25NIST AI 100-1 Table 1 and Table 4, nvlpubs.nist.gov · verified 2026-09-05
- 26ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
- 27ISO/IEC 27002:2022 controls 5.2 and 5.3, licensed copy · verified 2026-09-05
- 28ISO/IEC 27001:2022 clauses 5.3, 6.1.2, 6.1.3 and 9.1, iso.org/obp · verified 2026-09-03
- 29NIST CSWP 29 Appendix A GV.RR, GV.SC and PR.AA, nvlpubs.nist.gov · verified 2026-09-05
Related
- AI governance stand-up under the EU AI Act
Engagement pattern
- The BISO operating model
Playbook
- Board and management reporting for security
Playbook