Agentic AI
Operational controls for agentic ai, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →28 controls
Agent Permission Boundaries
Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).
Agent Prompt Injection Defense
Protect AI agents from prompt injection attacks, hidden instructions planted in outside content that take over agent behavior.
Agent Memory and Context Governance
Set rules for agent memory and information kept between sessions. Define permitted content, retention periods, access rights, and deletion conditions.
Multi-Agent Trust Hierarchy
Define explicit rules for which AI agents can instruct, call on, or delegate authority to other agents in multi-agent systems.
Human Approval Gate for Irreversible Agent Actions
Require explicit human approval before hard-to-reverse AI agent actions. Examples include communications, record changes, transactions, and data deletion.
Agent Action Audit Trail
Log every AI agent tool call, decision step, memory read or write, and external interaction. Records must allow reconstruction of the full action sequence.
Agent Scope and Task Boundaries
Set and enforce each agent’s permitted activity. Prevent actions beyond its intended purpose.
Agent Environment Isolation
Run AI agents in isolated environments. Limit system, network, and data access to what their tasks require.
Agent and Non-Human Identity Management
Give each agent a distinct identity with narrowly limited credentials, access controls, and a defined lifecycle. Avoid shared service accounts and user identities.
Agent Knowledge Source Integrity
Check documents, databases, and external sources retrieved by agents. Verify that nobody has tampered with, poisoned, or substituted the content.
Agent Behavior Monitoring and Anomaly Detection
Monitor deployed AI agents for behavioral drift, unusual use of connected tools, unexpected resource use, and actions outside their permitted scope.
Agent Kill Switch and Emergency Stop
Maintain an immediate stop for any agent session, workflow, or type of agent. It must work without agent cooperation and support recovery to a known-safe state.
Kill-Switch Propagation Testing
Test emergency stops across subagents and agents running in parallel. Verify that all agent activity stops within a defined time window.
Multi-Agent Delegation Chain Logging
Log every action in systems where AI agents work together. Preserve enough detail to identify its originating instruction, authorized agent, and responsible person.
Agent OAuth Scope Drift Detection
Monitor AI agents’ OAuth permissions (scopes). Alert when permissions exceed the authorized set or arrive outside the formal approval process.
Agentic AI Deployment Readiness Assessment
Assess tool-using AI agents before deployment. Verify governance controls and evaluate potential effects on connected systems before launch.
Agentic Autonomy Expansion Criteria
Define criteria for expanding agent autonomy after deployment. Require supporting evidence and approval through the same governance process used for initial deployment.
Agent Data Modification Blast-Radius Containment
Limit which data each agent can change. Cap the damage from malfunctions, misuse, or prompt injection, and make affected data recoverable.
AI Tool and Plugin Supply Chain Risk Assessment
Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code added to production software. Apply software supply-chain controls to these outside components.
RAG Retrieval Boundary Controls for Regulated Data
Set retrieval boundaries in RAG (AI document lookup) pipelines. Keep regulated, classified, and out-of-scope data out of what AI agents see to prevent unauthorized disclosure or sensitive-data mixing.
Human Oversight Classification Rationale Log
Document why each AI agent action requires human-in-the-loop (approval first) or human-on-the-loop (monitoring) oversight. Retain an auditable record of the reasoning behind those choices.
Agentic AI Governance Tooling Attestation
Obtain vendor attestations before using platform tools as primary agent oversight controls. Verify that monitoring data (telemetry) is complete, tamper-evident, and adequate for governance.
Agentic AI Security Assessment, CBRN and Cyber Espionage
Assess AI agent deployments for high-consequence misuse, including chemical, biological, radiological, and nuclear facilitation or AI-orchestrated cyber espionage. Implement mitigations proportionate to identified risks.
AI Permission Escalation Tabletop Exercise Program
Run recurring tabletop exercises on AI agents gaining and spreading unauthorized permissions. Test containment controls, incident detection, response effectiveness, and governance procedures.
Agent Ownership and Accountability Register
Keep a register that names an accountable person for every deployed AI agent. Record who owns its outcomes, who sponsors it at executive level, and what happens when either person leaves.
Agent External System Access Boundaries
Limit which outside websites, services, and government systems each agent may contact. Stop agents that keep retrying after being blocked, and alert on any contact outside the approved list.
User-Built Agent Go-Live Review
Require a proportionate review before any agent built by an employee on a self-service platform goes live. Match the depth of review to what the agent can reach and do.
MCP Server Inventory and Configuration Baseline
Keep an inventory of every MCP server (the connectors that let AI agents use tools and data) in the organization. Hold each one to a baseline for authentication, permissions, logging, and data-loss coverage.
Agentic AI, tracked weekly
New agentic ai controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
