The EU Cyber Resilience Act and AI Agent Products
How the EU Cyber Resilience Act's security-by-design, vulnerability handling, and reporting duties apply to AI agent software sold into the EU market.
Policies, audit trails, GDPR, and EU AI Act readiness for agentic AI.
The complete reference on AI governance: control points, guardrails, human-in-the-loop oversight, audit trails, and regulatory compliance for AI agents.
Read the guide →How the EU Cyber Resilience Act's security-by-design, vulnerability handling, and reporting duties apply to AI agent software sold into the EU market.
Workday's domain security model scopes agent access to HR data tightly, but integrations to external HRIS, payroll, and ATS systems fall outside it.
Snowflake's RBAC and row-level policies govern Cortex Agents tightly inside the platform, but external functions and exports fall outside that perimeter.
Joule inherits SAP's authorization objects in-landscape, but regulated estates need an audit trail spanning any system a Joule agent reaches beyond SAP.
Copilot agents respect Microsoft Graph permissions by default, but citizen-developer publishing in Copilot Studio outpaces central inventory and review.
Unity Catalog governs data and tool access tightly inside Databricks, but agents that reach outside it or span multi-cloud workspaces need separate controls.
China's Implementation Opinions regulate AI agents as their own category, not generative models, via a three-tier autonomy framework, as of late August 2026.
Hermes Agent ships a five-layer tool-use defense model, layered memory, and 40+ skills. A practitioner's guide to configuring it safely, not a feature tour.
A step-by-step decision workflow for classifying an AI agent's EU AI Act risk tier — prohibited, high-risk Annex III, Article 50 transparency, or minimal risk.
The sections a usable AI agent acceptable use policy needs, why a chatbot AUP isn't enough, and a draft-to-review process for authoring one.
Microsoft Agent Framework went GA as the successor to AutoGen and Semantic Kernel. What its design choices — and its own disclaimers — mean for governance.
n8n's AI Agent node bundles a model, memory, and tools into one node holding live credentials — and a CVSS-10 flaw showed exactly what that exposes.
SOC 2 is an attestation, ISO 42001 a certification — they prove different things about an AI agent program. A decision framework for which to pursue first.
Cyber policies largely cover attacks that use AI, not losses your own agents cause. The AI-agent coverage market is still forming as of August 2026.
Gartner projects 150,000+ agents per Fortune 500 enterprise by 2028, up from under 15 in 2025. Why sprawl is a different problem than shadow AI.
Since 2 August 2026, the EU AI Office can demand documentation, evaluate, restrict, and fine GPAI providers up to €15M or 3% of turnover, whichever is higher.
NIST's AI Agent Standards Initiative and COSAiS are drafting SP 800-53 control overlays for single- and multi-agent systems, as of August 2026.
Disambiguating three product categories that all call themselves 'AI governance': GRC extensions, risk systems of record, and runtime control planes.
The Cloud Security Alliance's AI Controls Matrix maps AI risk to concrete controls across 18 domains, and lines up with ISO 42001 and NIST AI 600-1.
ISO/IEC 42005:2025 defines how to run an AI system impact assessment. Here is what it requires and how it differs from a DPIA or the EU AI Act's FRIA.
DORA has applied to EU financial entities since January 2025. Here is when an AI or LLM vendor counts as a regulated ICT third party under it.
Per-tenant signing keys held in a customer-controlled KMS change what a platform compromise can do and what a tenant can prove. Learn the substrate options, the trade-offs, and the operational cost.
A public reputation lookup for agents leaks information unless it is designed carefully. Learn the anti-enumeration contract, why k-anonymity thresholds matter, and how reputation differs from trust.
What to log for AI agents, how to keep audit trails credible and tamper-evident, and how to reconstruct any agent action for compliance or forensics.
FINRA's 2026 oversight report and existing SEC rules set concrete expectations for AI agents at broker-dealers and RIAs — here is what they actually require.
California SB 53, New York's RAISE Act, Texas TRAIGA, and Colorado's amended AI Act target different companies — here is who actually has to comply.
Govern AI customer-support agents: PII detection, response guardrails, escalation triggers, and tamper-evident audit logs regulators expect.
How healthcare organizations protect PHI, enforce least privilege, and prove AI agent controls to satisfy HIPAA, the EU AI Act, and auditors.
Article 50 transparency obligations take effect 2 Aug 2026 — AI disclosure, synthetic-content marking, and what engineering teams must ship now.
The controls regulated financial firms need for AI agents: tamper-evident audit trails, scoped identity, approval gates, and on-demand regulatory evidence.
Colorado SB 189 delayed the Colorado AI Act to January 1, 2027 and narrowed it to developer disclosure, consumer notice, and human-review duties.
The EU AI Act Digital Omnibus entered into force 27 July 2026, deferring Annex III high-risk rules to Dec 2027 and Annex I to Aug 2028. Art. 49/50 unchanged.
Guardrails, evals, and monitoring each close a different AI safety gap at a different lifecycle stage — learn how to use all three correctly.
How insurers govern AI agents in underwriting and claims: consequential-decision controls, fairness monitoring, and exam-ready audit evidence.
How law firms and legal departments govern AI agents: privilege protection, matter-level access, ethical walls, and audit-ready evidence.
How government organizations govern AI agents: citizen-facing decision controls, transparency-grade audit trails, sovereignty, and procurement.
AI guardrails and LLM firewalls both inspect content but solve different problems. Learn the distinctions, evaluation approaches, and fail-mode trade-offs.
How to keep AI agent data within jurisdictional boundaries, satisfy GDPR and cross-border transfer rules, and produce the evidence regulators expect.
ISO/IEC 42001 sets requirements for AI management systems. See what the standard expects and how agent governance controls map directly to its Annex A clauses.
Most agents go from a developer's laptop to production with no promotion gate. Learn the lifecycle stages worth defining, what each gate should check, and how to keep promotion fast enough to use.
A practical AI agent compliance checklist covering identity, tamper-evident audit trails, GDPR erasure, EU AI Act risk tiers, and vendor due diligence.
Guardrails and agent configuration are security controls, so they need the change discipline of security controls. Learn how to version policy, review changes, and prove which version was in force.
Precise definitions of AI governance and agent security terms — guardrail, control plane, A2A, attestation, trust score — for specs and vendor evaluations.
Apply the NIST AI RMF to AI agents: map GOVERN, MAP, MEASURE, and MANAGE to controls like agent inventories, threat models, audit trails, and revocation.
Five stages of AI governance maturity for agents, from ad-hoc to optimized, with concrete indicators and the specific work needed to advance each stage.
Enabling a guardrail in blocking mode without measuring it first is how teams end up disabling guardrails entirely. Learn the shadow-to-enforce progression and the metrics that justify each promotion.
Any administrative action a single person can both request and approve is not controlled. Learn where maker-checker belongs in an AI platform, how self-approval sneaks back in, and how to keep it usable.
Detect and redact PII before it reaches AI models or persists in logs — covering entry points, detection techniques, redaction strategies, and compliance.
Choose the right enforcement action for AI agent guardrails — block, redact, or warn — and understand the fail-open vs fail-closed security trade-off.
What makes an audit trail credible to an auditor or court: hash-chaining, per-row digital signatures, and external anchoring explained for engineering teams.
Keep PII out of AI agent prompts, responses, and logs using detection-and-redaction controls that satisfy GDPR, HIPAA, and audit requirements.
Low-code platforms like Dify let anyone assemble an agent with tool access in minutes. That speed is the governance problem, not a side effect of it.
Texas's TRAIGA is already in force and applies broadly, with no size threshold — a practical checklist for teams operating AI agents that reach Texas users.
How PCI DSS's core requirements apply when an AI agent touches cardholder data, and the controls that keep it out of scope where possible.
Human-in-the-loop approvals pause AI agents before high-risk actions, preserve throughput with async queues, and build an auditable approval trail.
How the EU's NIS2 Directive's risk management, incident reporting, and supply-chain duties apply to organizations operating AI agent platforms.
New York's RAISE Act targets frontier-model developers with safety-framework and incident-reporting duties — who it reaches and what to build regardless.
Illinois regulates AI in employment decisions and AI-analyzed video interviews — what hiring agents need to satisfy notice, bias, and human-review duties.
How HIPAA's Security Rule and BAA requirements apply to AI agents that read, generate, or transmit protected health information.
How the GLBA Safeguards Rule's written information security program requirements apply when AI agents access customer financial data.
How FERPA's consent, disclosure, and recordkeeping requirements apply when AI agents access student education records in K-12 or higher education.
California's SB 53 requires frontier-model developers to publish safety frameworks and report incidents — here is the scope and the control work it implies.
SOC 2 auditors scrutinize AI platforms harder than traditional SaaS—learn which controls matter most, from tamper-evident audit trails to agent access.
How GDPR data subject rights apply to AI pipelines, what Article 17 erasure requires technically, and the design patterns that make compliance tractable.
EU AI Act for engineers after the 2026 Digital Omnibus: Annex III moves to Dec 2027, Art. 49/50 land 2 Aug 2026, plus a concrete readiness path.
How to discover, register, and maintain every AI agent you deploy — the foundational inventory that access policies, spend caps, and audit trails depend on.
AI agent governance defines the runtime controls — identity, authorization, guardrails, budgets, and audit trails — that keep autonomous agents accountable.
The UK governs AI agents through existing sector regulators and cross-cutting principles, not a single AI Act — the control mapping operators need to prepare.
The UAE and Saudi Arabia govern AI agents through national strategy bodies, data-protection law, and free-zone rules rather than a single binding AI statute.
Singapore governs AI through a voluntary framework and testing tools rather than binding law — the control mapping agent operators should build anyway.
South Korea's AI Framework Act creates a binding risk-tiered regime for high-impact AI — the obligations agent operators should map to now.
Japan's AI law takes a light-touch, cooperation-based approach with no direct fines — here's what agent operators should still be able to prove.
India governs AI agents through advisories, sector regulators, and data-protection law rather than a binding AI statute — the control mapping to prepare now.
A framework for governing AI agents across jurisdictions with different instrument types and sorting axes, built around one control set instead of ten.
Canada's proposed federal AI statute did not become law; here's how agent operators should govern deployments using existing privacy and sector rules instead.
Brazil's proposed AI bill would add EU-style risk tiers and rights to LGPD's existing data rules — the control mapping agent operators should build now.
Australia's Voluntary AI Safety Standard sets out guardrails agent operators should adopt now, ahead of proposed mandatory rules for high-risk AI.
A step-by-step procedure for building an AI agent risk register, from identifying risk categories to assigning owners and a review cadence.
What CISOs are accountable for as AI agents enter production, the questions they will be asked, and the artefacts they need to answer them.
Change management for agent configurations governs model, tool-scope, and budget edits with approval and audit, distinct from a canary or a policy cutover.
Tamper-evident audit logs use hash-chaining and signed Merkle proofs to give compliance teams independently verifiable records—no platform access needed.
How to run one readiness programme covering GDPR erasure and EU AI Act risk classification — shared controls, evidence collection, and the 2026-27 timeline.
How app-layer org scoping and database row-level security combine to prevent cross-tenant data leaks in multi-tenant AI platforms—and where each layer fits.
How content guardrails enforce policy on every AI agent interaction—blocking, redacting, or escalating PII, secrets, and violations at the trust boundary.