AI Governance Institute
← All controls
AGT

Agentic AI

Operational controls for agentic ai, with maturity levels, evidence requirements, and implementation guidance.

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →

28 controls

AGT-001
Agenthigh

Agent Permission Boundaries

Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).

AGT-002
Agentmedium

Agent Prompt Injection Defense

Protect AI agents from prompt injection attacks, hidden instructions planted in outside content that take over agent behavior.

AGT-003
Agentmedium

Agent Memory and Context Governance

Set rules for agent memory and information kept between sessions. Define permitted content, retention periods, access rights, and deletion conditions.

AGT-004
Agenthigh

Multi-Agent Trust Hierarchy

Define explicit rules for which AI agents can instruct, call on, or delegate authority to other agents in multi-agent systems.

AGT-005
Agentmedium

Human Approval Gate for Irreversible Agent Actions

Require explicit human approval before hard-to-reverse AI agent actions. Examples include communications, record changes, transactions, and data deletion.

AGT-006
Agentmedium

Agent Action Audit Trail

Log every AI agent tool call, decision step, memory read or write, and external interaction. Records must allow reconstruction of the full action sequence.

AGT-007
Agentmedium

Agent Scope and Task Boundaries

Set and enforce each agent’s permitted activity. Prevent actions beyond its intended purpose.

AGT-008
Agenthigh

Agent Environment Isolation

Run AI agents in isolated environments. Limit system, network, and data access to what their tasks require.

AGT-009
Agenthigh

Agent and Non-Human Identity Management

Give each agent a distinct identity with narrowly limited credentials, access controls, and a defined lifecycle. Avoid shared service accounts and user identities.

AGT-010
Agentmedium

Agent Knowledge Source Integrity

Check documents, databases, and external sources retrieved by agents. Verify that nobody has tampered with, poisoned, or substituted the content.

AGT-011
Agenthigh

Agent Behavior Monitoring and Anomaly Detection

Monitor deployed AI agents for behavioral drift, unusual use of connected tools, unexpected resource use, and actions outside their permitted scope.

AGT-012
Agentmedium

Agent Kill Switch and Emergency Stop

Maintain an immediate stop for any agent session, workflow, or type of agent. It must work without agent cooperation and support recovery to a known-safe state.

AGT-013
Agentmedium

Kill-Switch Propagation Testing

Test emergency stops across subagents and agents running in parallel. Verify that all agent activity stops within a defined time window.

AGT-014
Agentmedium

Multi-Agent Delegation Chain Logging

Log every action in systems where AI agents work together. Preserve enough detail to identify its originating instruction, authorized agent, and responsible person.

AGT-015
Agentmedium

Agent OAuth Scope Drift Detection

Monitor AI agents’ OAuth permissions (scopes). Alert when permissions exceed the authorized set or arrive outside the formal approval process.

AGT-016
Agentmedium

Agentic AI Deployment Readiness Assessment

Assess tool-using AI agents before deployment. Verify governance controls and evaluate potential effects on connected systems before launch.

AGT-017
Agentmedium

Agentic Autonomy Expansion Criteria

Define criteria for expanding agent autonomy after deployment. Require supporting evidence and approval through the same governance process used for initial deployment.

AGT-018
Agentmedium

Agent Data Modification Blast-Radius Containment

Limit which data each agent can change. Cap the damage from malfunctions, misuse, or prompt injection, and make affected data recoverable.

AGT-019
Agentmedium

AI Tool and Plugin Supply Chain Risk Assessment

Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code added to production software. Apply software supply-chain controls to these outside components.

AGT-020
Agentmedium

RAG Retrieval Boundary Controls for Regulated Data

Set retrieval boundaries in RAG (AI document lookup) pipelines. Keep regulated, classified, and out-of-scope data out of what AI agents see to prevent unauthorized disclosure or sensitive-data mixing.

AGT-021
Agentlow

Human Oversight Classification Rationale Log

Document why each AI agent action requires human-in-the-loop (approval first) or human-on-the-loop (monitoring) oversight. Retain an auditable record of the reasoning behind those choices.

AGT-022
Agentmedium

Agentic AI Governance Tooling Attestation

Obtain vendor attestations before using platform tools as primary agent oversight controls. Verify that monitoring data (telemetry) is complete, tamper-evident, and adequate for governance.

AGT-023
Agenthigh

Agentic AI Security Assessment, CBRN and Cyber Espionage

Assess AI agent deployments for high-consequence misuse, including chemical, biological, radiological, and nuclear facilitation or AI-orchestrated cyber espionage. Implement mitigations proportionate to identified risks.

AGT-024
Agentmedium

AI Permission Escalation Tabletop Exercise Program

Run recurring tabletop exercises on AI agents gaining and spreading unauthorized permissions. Test containment controls, incident detection, response effectiveness, and governance procedures.

AGT-027
Agentlow

Agent Ownership and Accountability Register

Keep a register that names an accountable person for every deployed AI agent. Record who owns its outcomes, who sponsors it at executive level, and what happens when either person leaves.

AGT-028
Agentmedium

Agent External System Access Boundaries

Limit which outside websites, services, and government systems each agent may contact. Stop agents that keep retrying after being blocked, and alert on any contact outside the approved list.

AGT-029
Agentmedium

User-Built Agent Go-Live Review

Require a proportionate review before any agent built by an employee on a self-service platform goes live. Match the depth of review to what the agent can reach and do.

AGT-030
Agentmedium

MCP Server Inventory and Configuration Baseline

Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.

Agentic AI, tracked weekly

New agentic ai controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.

Powered by Buttondown.