AI Governance Institute
← News

Mayer Brown Guidance Exposes Gaps in Existing AI Governance for Agentic Systems

What happened

Mayer Brown published Governance of Agentic Artificial Intelligence Systems on February 5, 2026, offering structured practitioner guidance for legal and compliance teams navigating the shift from conventional AI tools to autonomous agents that plan and act with limited human supervision. The guidance argues that existing AI governance programs were designed for systems that produce outputs for human review, not for agents that chain together decisions and execute consequential actions across connected systems. It identifies authorization scope, human oversight design, and real-time monitoring as the three areas where current programs most commonly fall short. The document arrives as multiple concurrent developments, including IBM's agentic AI governance playbook and Anthropic's CISO guidance for agentic deployment, are collectively raising the practitioner standard for what adequate agentic governance looks like. Mayer Brown's contribution is notable for its legal framing, connecting governance gaps directly to liability exposure rather than treating the issue as a purely technical or operational matter.

Why it matters

  • ·Existing AI governance policies are generally designed around human-reviewed outputs, and agentic systems that act autonomously break the control assumptions those policies rest on. Organizations deploying agents without revisiting their authorization and oversight frameworks are running programs that do not match the risk profile of what they have deployed.
  • ·Regulatory frameworks including the EU AI Act increasingly expect documented human oversight rationales for high-risk automated decisions. Agentic systems that chain actions across multiple steps without clear oversight checkpoints create compliance exposure that point-in-time review policies do not address.
  • ·The legal framing in the Mayer Brown guidance signals that governance gaps in agentic deployments are becoming a liability question, not just a best-practice question. Compliance teams that cannot demonstrate how authorization limits and human oversight were designed and tested for a given agent deployment face growing legal and reputational risk if an agent causes harm.

Governance controls affected

What to do now

  • Inventory all agentic AI deployments and assess whether each has a documented authorization scope that limits the systems, data, and actions the agent can access or trigger.
  • Review human oversight design for each deployed agent and confirm that human review gates are placed before irreversible or high-impact actions, not only at final output.
  • Assess monitoring coverage for agentic systems and verify that behavioral anomaly detection is in place, not just output-level performance monitoring.
  • Map existing AI governance policies against the Mayer Brown guidance to identify where policy language assumes human-reviewed outputs rather than autonomous action chains.
  • Engage legal counsel to assess whether current governance documentation would be adequate to demonstrate reasonable care if an agentic system caused harm, using the liability framing in the guidance as a benchmark.

What to watch next

Regulatory bodies have not yet issued binding agentic-specific requirements in most jurisdictions, but the accumulation of practitioner guidance from law firms, major vendors, and research institutions is establishing a de facto standard that regulators and courts are likely to reference. The Bank of England's signaled bespoke agentic AI rules for financial services suggests sector-specific binding requirements may arrive before comprehensive horizontal frameworks do. Compliance teams should monitor whether the EU AI Act implementing guidance addresses agentic deployment patterns explicitly, particularly regarding what constitutes a meaningful human oversight checkpoint for multi-step agent workflows.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-27

Meta's Agent Deployment Drove a 40% Incident Spike Before Plans Were Scrapped

Internal disclosures from Meta's canceled Project OT reveal that AI agents deployed to replace workers made large-scale, disruptive autonomous actions that contributed to a 40% rise in major technical and security incidents and up to a 70% increase in employee time spent resolving them. The program had targeted headcount reductions of up to 60% in some teams before being scrapped after an initial layoff wave. The case provides the most detailed quantified account of enterprise agentic AI failure yet reported by a named organization.

Standards2026-09-10

NCSC Agentic AI Guidance Sets Sandbox and Logging as Baseline Controls

The UK National Cyber Security Centre published guidance on managing cyber risk in agentic AI systems, identifying sandboxing, strict access controls, active oversight, and structured logging as essential security requirements. The guidance is directed at enterprise deployers and sets expectations that autonomous AI systems must operate within observable, bounded environments. Organizations running production AI agents are expected to align their deployment architecture with these recommendations.

Research2026-09-09

Weaver and Assury Map Four Agentic AI Governance Gaps Compliance Programs Are Missing

Consulting firms Weaver and Assury have published a practitioner framework identifying four governance gaps specific to agentic AI deployments: cumulative session risk, context-based authorization failures, dynamic autonomy changes, and the absence of pre-action audit evidence. The analysis maps these gaps directly to enterprise controls including approval workflows, least-privilege enforcement, and independent assurance over agent actions. Compliance teams using conventional AI governance programs will find those programs largely silent on all four issues.