Mayer Brown Guidance Exposes Gaps in Existing AI Governance for Agentic Systems
What happened
Mayer Brown published Governance of Agentic Artificial Intelligence Systems on February 5, 2026, offering structured practitioner guidance for legal and compliance teams navigating the shift from conventional AI tools to autonomous agents that plan and act with limited human supervision. The guidance argues that existing AI governance programs were designed for systems that produce outputs for human review, not for agents that chain together decisions and execute consequential actions across connected systems. It identifies authorization scope, human oversight design, and real-time monitoring as the three areas where current programs most commonly fall short. The document arrives as multiple concurrent developments, including IBM's agentic AI governance playbook and Anthropic's CISO guidance for agentic deployment, are collectively raising the practitioner standard for what adequate agentic governance looks like. Mayer Brown's contribution is notable for its legal framing, connecting governance gaps directly to liability exposure rather than treating the issue as a purely technical or operational matter.
Why it matters
- ·Existing AI governance policies are generally designed around human-reviewed outputs, and agentic systems that act autonomously break the control assumptions those policies rest on. Organizations deploying agents without revisiting their authorization and oversight frameworks are running programs that do not match the risk profile of what they have deployed.
- ·Regulatory frameworks including the EU AI Act increasingly expect documented human oversight rationales for high-risk automated decisions. Agentic systems that chain actions across multiple steps without clear oversight checkpoints create compliance exposure that point-in-time review policies do not address.
- ·The legal framing in the Mayer Brown guidance signals that governance gaps in agentic deployments are becoming a liability question, not just a best-practice question. Compliance teams that cannot demonstrate how authorization limits and human oversight were designed and tested for a given agent deployment face growing legal and reputational risk if an agent causes harm.
Governance controls affected
What to do now
- ☐Inventory all agentic AI deployments and assess whether each has a documented authorization scope that limits the systems, data, and actions the agent can access or trigger.
- ☐Review human oversight design for each deployed agent and confirm that human review gates are placed before irreversible or high-impact actions, not only at final output.
- ☐Assess monitoring coverage for agentic systems and verify that behavioral anomaly detection is in place, not just output-level performance monitoring.
- ☐Map existing AI governance policies against the Mayer Brown guidance to identify where policy language assumes human-reviewed outputs rather than autonomous action chains.
- ☐Engage legal counsel to assess whether current governance documentation would be adequate to demonstrate reasonable care if an agentic system caused harm, using the liability framing in the guidance as a benchmark.
What to watch next
Regulatory bodies have not yet issued binding agentic-specific requirements in most jurisdictions, but the accumulation of practitioner guidance from law firms, major vendors, and research institutions is establishing a de facto standard that regulators and courts are likely to reference. The Bank of England's signaled bespoke agentic AI rules for financial services suggests sector-specific binding requirements may arrive before comprehensive horizontal frameworks do. Compliance teams should monitor whether the EU AI Act implementing guidance addresses agentic deployment patterns explicitly, particularly regarding what constitutes a meaningful human oversight checkpoint for multi-step agent workflows.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
