Weaver and Assury Map Four Agentic AI Governance Gaps Compliance Programs Are Missing
What happened
Weaver and Assury published How Agentic AI Is Changing AI Governance Requirements, a practitioner-oriented framework identifying control gaps that emerge when AI systems move from discrete, single-query interactions to extended, multi-step agentic sessions. The paper argues that conventional governance frameworks, designed around individual model outputs, cannot account for risks that accumulate across an agent session, where a sequence of individually permissible actions can combine into an outcome no single approval gate would have sanctioned. The authors identify four specific gaps: organizations are not tracking how authorization context shifts as an agent acquires information mid-session; autonomy levels are changing dynamically without triggering re-authorization or human review; and audit evidence is being captured after actions execute rather than before, eliminating the possibility of a meaningful pre-action approval record. The framework draws direct lines to enterprise control categories including least-privilege enforcement, human approval gates, logging architecture, and third-party assurance, and situates the analysis against a backdrop of agent governance becoming binding across multiple regulatory domains.
Why it matters
- ·Cumulative session risk is not addressed by most existing AI governance frameworks, meaning approval gates and audit trails calibrated to single-query outputs will not catch harm that emerges from a sequence of individually sanctioned agent steps, creating a direct compliance exposure as agentic deployments scale.
- ·Dynamic autonomy expansion during a session, where an agent effectively elevates its own permissions as it gathers context, mirrors the OAuth scope drift and credential escalation patterns documented in recent agentic attack research, and may constitute a control failure under frameworks requiring least-privilege enforcement and documented authorization changes.
- ·The absence of pre-action audit evidence fundamentally undermines the auditability requirements that regulators and frameworks such as the NIST Artificial Intelligence Risk Management Framework Playbook expect, shifting forensic burden onto organizations that assumed vendor-side logging would be sufficient.
Governance controls affected
What to do now
- ☐Audit existing agent approval workflows to determine whether they evaluate cumulative session risk or only individual action requests, and document the gap for remediation planning.
- ☐Map all deployed agentic systems to identify where autonomy levels can change mid-session without triggering a re-authorization event or human review, and implement controls to flag such changes.
- ☐Review your audit logging architecture to confirm that pre-action records are captured for consequential agent decisions, not only post-execution logs, and update log retention policies accordingly.
- ☐Assess whether least-privilege controls applied at agent session initiation remain enforced throughout the session as the agent acquires additional context or data access.
- ☐Incorporate the four gap categories identified by Weaver and Assury into your next agentic AI governance maturity review and update your risk register to reflect any unaddressed exposures.
What to watch next
Regulatory guidance on agentic AI is converging on precisely the control categories this framework identifies. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services and emerging domestic frameworks are likely to set binding expectations around pre-action authorization and audit evidence within the next 12 months, meaning organizations that treat these as aspirational today face a compliance gap tomorrow. Teams should also monitor whether NIST's ongoing work on agentic standards, noted as incomplete in NIST's Agent Standards Gap Leaves Enterprises Without Enforceable Agentic AI Controls, produces enforceable language on session-level risk tracking and dynamic autonomy controls before year-end.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
