AI Governance Institute
Topics

Agentic AI and Autonomy

As AI systems move from answering questions to taking independent actions, traditional governance frameworks are falling behind. This topic covers what organizations need to govern AI agents: autonomy boundaries, non-human identities, permissions, audit trails, and incident response for systems that can act without direct human instruction.

Key board-level questions

  • 1.Are we treating AI agents as digital employees with identities, permissions, and logs?
  • 2.What decisions are AI systems allowed to make autonomously versus with human oversight?
  • 3.How do we prevent runaway or irreversible actions from agentic systems?
  • 4.Do we have governance for non-human identities and their access rights?

Regulatory frameworks

US

NIST AI 600-1 Generative AI Profile

This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models (general-purpose models that handle text, images, and audio).

Global

OWASP Top 10 for Large Language Model Applications

OWASP's Top 10 for LLM Applications lists the most critical security risks in applications built on large language models. The current 2026 edition, published in August 2026, puts prompt injection, sensitive information disclosure, and excessive agency at the top. Development and security teams use it to prioritize safeguards.

EU

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.

US

NIST AI Risk Management Framework (AI RMF 1.0) and Playbook

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.

EU

AI Act Governance and Enforcement Framework

EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.

Playbook guidance