AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

Mayer Brown Guidance Exposes Gaps in Existing AI Governance for Agentic Systems

What happened

Mayer Brown published Governance of Agentic Artificial Intelligence Systems on February 5, 2026, offering structured practitioner guidance for legal and compliance teams navigating the shift from conventional AI tools to autonomous agents that plan and act with limited human supervision. The guidance argues that existing AI governance programs were designed for systems that produce outputs for human review, not for agents that chain together decisions and execute consequential actions across connected systems. It identifies authorization scope, human oversight design, and real-time monitoring as the three areas where current programs most commonly fall short. The document arrives as multiple concurrent developments, including IBM's agentic AI governance playbook and Anthropic's CISO guidance for agentic deployment, are collectively raising the practitioner standard for what adequate agentic governance looks like. Mayer Brown's contribution is notable for its legal framing, connecting governance gaps directly to liability exposure rather than treating the issue as a purely technical or operational matter.

Why it matters

  • ·Existing AI governance policies are generally designed around human-reviewed outputs, and agentic systems that act autonomously break the control assumptions those policies rest on. Organizations deploying agents without revisiting their authorization and oversight frameworks are running programs that do not match the risk profile of what they have deployed.
  • ·Regulatory frameworks including the EU AI Act increasingly expect documented human oversight rationales for high-risk automated decisions. Agentic systems that chain actions across multiple steps without clear oversight checkpoints create compliance exposure that point-in-time review policies do not address.
  • ·The legal framing in the Mayer Brown guidance signals that governance gaps in agentic deployments are becoming a liability question, not just a best-practice question. Compliance teams that cannot demonstrate how authorization limits and human oversight were designed and tested for a given agent deployment face growing legal and reputational risk if an agent causes harm.

Governance controls affected

What to do now

  • Inventory all agentic AI deployments and assess whether each has a documented authorization scope that limits the systems, data, and actions the agent can access or trigger.
  • Review human oversight design for each deployed agent and confirm that human review gates are placed before irreversible or high-impact actions, not only at final output.
  • Assess monitoring coverage for agentic systems and verify that behavioral anomaly detection is in place, not just output-level performance monitoring.
  • Map existing AI governance policies against the Mayer Brown guidance to identify where policy language assumes human-reviewed outputs rather than autonomous action chains.
  • Engage legal counsel to assess whether current governance documentation would be adequate to demonstrate reasonable care if an agentic system caused harm, using the liability framing in the guidance as a benchmark.

What to watch next

Regulatory bodies have not yet issued binding agentic-specific requirements in most jurisdictions, but the accumulation of practitioner guidance from law firms, major vendors, and research institutions is establishing a de facto standard that regulators and courts are likely to reference. The Bank of England's signaled bespoke agentic AI rules for financial services suggests sector-specific binding requirements may arrive before comprehensive horizontal frameworks do. Compliance teams should monitor whether the EU AI Act implementing guidance addresses agentic deployment patterns explicitly, particularly regarding what constitutes a meaningful human oversight checkpoint for multi-step agent workflows.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-07-29

Frontier AI Agents Pass Only 36% of Policy-Compliance Tasks, Benchmark Finds, Exposing Enterprise Automation Controls

Researchers have published HANDBOOK.md, a benchmark of 65 agentic tasks testing whether language model agents follow long-form enterprise policy documents during extended tool use. Under strict grading, the best-performing model configuration passed only 36.2% of trials, with most frontier models falling below 25%. Failure patterns include agents overriding standing policy in response to in-context requests, acting against completed compliance checks, and losing rule details over long task horizons.

Research2026-07-26

Trend Micro Identifies Four Agentic AI Controls Enterprises Are Missing: Inventory, Least-Agency, Supply Chain, and Communication Monitoring

Trend Micro has published research warning that agentic AI systems can plan and act across enterprise environments without meaningful visibility, creating governance gaps that standard endpoint and access controls do not address. The research recommends four specific control categories: agent inventorying, least-privilege and least-agency policies, supply-chain risk treatment for tools and extensions, and monitoring of inter-agent communication flows. Enterprise teams are advised to pair these controls with approval gates for high-impact autonomous actions.

Standards2026-08-01

NIST's Agent Standards Gap Leaves Enterprises Without Enforceable Agentic AI Controls

NIST's Center for AI Standards and Innovation has issued a request for information on autonomous AI agent cybersecurity controls, signaling that a formal NIST AI Agent Standards Initiative is underway. Cloud Security Alliance Labs published a research note on April 3, 2026, warning that no enforceable agent-specific controls yet exist. Until formal guidance matures, enterprises must build interim controls around least-privilege access, behavioral monitoring, and incident response.