PwC's Three Governance Shifts Put Runtime Agent Controls at the Center
What happened
PwC's Building Trust in Agentic AI: Three Governance Shifts sets out a practitioner framework for governing agents that act, delegate, and modify data during operation. The guidance argues that compliance programs built around point-in-time assessments cannot keep pace with agents that change state continuously. It calls on deploying organizations to assign explicit human owners to each agent, constrain the scope of tasks an agent may initiate without approval, and maintain tamper-evident logs of every autonomous action for audit and incident review. The framework treats runtime monitoring as the primary governance layer, not an afterthought added after deployment. This guidance arrives as a growing cluster of incidents has demonstrated that declared agent policies frequently diverge from actual runtime behavior, a pattern documented across multiple agentic AI disclosure events in 2026.
Why it matters
- ·Regulatory frameworks including the EU AI Act increasingly expect continuous monitoring and audit-ready logs for high-risk AI. Agents that lack tamper-evident runtime records will face documentation gaps at the first formal inspection.
- ·The ownership gap is now a named liability vector. When an agent takes a consequential autonomous action and no human is designated as accountable, organizations face exposure under incident-reporting obligations and, in some jurisdictions, executive liability. The Treasury Secretary's recent warning on executive criminal liability for agentic AI deployments makes this concrete.
- ·Static vendor contracts and pre-deployment due diligence cannot capture runtime behavior drift. Compliance teams that rely on vendor assurances without independent runtime monitoring are accepting a control gap that audit evidence increasingly cannot close.
Governance controls affected
What to do now
- ☐Assign a named human owner to every deployed agent, documented in your AI model registry, with defined escalation responsibilities.
- ☐Audit existing agent deployments to confirm task-authority boundaries are enforced at runtime, not merely declared in policy documents.
- ☐Implement tamper-evident logging for all autonomous agent actions, covering tool calls, data modifications, and delegation events.
- ☐Review vendor contracts for AI agents to require runtime activity disclosure and incident notification within defined SLA windows.
- ☐Schedule a tabletop exercise that tests what happens when a deployed agent exceeds its authorized scope and no designated owner is available to intervene.
What to watch next
Regulatory bodies in the EU and Singapore are actively developing binding guidance on agentic AI that will formalize many of the runtime controls PwC describes as best practice. The MDDI Response on Extending AI Governance to Agentic AI Systems and forthcoming EU AI Act secondary guidance on autonomous systems are the clearest near-term signals. Compliance teams should also monitor whether PwC's three-shift model is adopted by financial regulators as a reference architecture, given the firm's prior banking AI guidance has influenced supervisory expectations.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
