AI Governance Institute
Topics

Agentic AI and Autonomy

As AI systems move from answering questions to taking independent actions, traditional governance frameworks are falling behind. This topic covers what organizations need to govern AI agents: autonomy boundaries, non-human identities, permissions, audit trails, and incident response for systems that can act without direct human instruction.

Key board-level questions

  • 1.Are we treating AI agents as digital employees with identities, permissions, and logs?
  • 2.What decisions are AI systems allowed to make autonomously versus with human oversight?
  • 3.How do we prevent runaway or irreversible actions from agentic systems?
  • 4.Do we have governance for non-human identities and their access rights?

Regulatory frameworks

US

NIST AI 600-1 Generative AI Profile

This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.

Global

OWASP Top 10 for Large Language Model Applications

OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.

EU

EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)

This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to establish workforce literacy measures. It also describes enforceable prohibitions on unacceptable-risk practices. Organizations must cease prohibited practices and demonstrate adequate staff competency by that date.

US

NIST Artificial Intelligence Risk Management Framework Playbook

The voluntary NIST AI RMF Playbook provides implementation guidance, suggested actions, and example outputs across AI use cases. It supports GOVERN, MAP, MEASURE, and MANAGE throughout the system lifecycle.

EU

AI Act Governance and Enforcement Framework

EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.

Playbook guidance