AI agent governance is how an organization decides what its AI agents may do, enforces those decisions on the agents' actual actions, and keeps evidence that it did. It names an owner for each agent, sets the policy for consequential actions such as moving money, changing production or exporting customer data, and produces records an auditor or regulator can check.
What it covers
- Inventory and ownership: every agent known, with an accountable owner and a stated purpose, and for each AI system an AIBOM of what it is built from.
- Policy: which actions are allowed, denied or need a person's approval, and limits on spend.
- Enforcement: the policy applied at runtime, before an action executes, not only written down.
- Oversight: people who can review, approve and stop agents, through human-in-the-loop approval for single actions and a kill switch for incidents.
- Evidence: a record of decisions that holds up, mapped to frameworks such as the EU AI Act and ISO/IEC 42001.
How it differs from AI governance
AI governance in the broad sense covers the whole life of AI systems: choosing models, data quality, fairness, risk assessment and regulatory classification. AI agent governance is the part that deals with systems that act, and its centre of gravity is runtime: the decision on an action as it happens, and the record of that decision. Model governance asks whether a model is fit for use; agent governance asks whether this agent may take this action now.
Where to go next
The complete framework, from its five pillars to a maturity model, is in the AI agent governance guide. The AI control plane entry describes the layer that usually carries it, and how Praesidia supports each part is on the platform overview.
Common questions
Who owns AI agent governance in an organization?
Usually several functions: security owns the controls, compliance or risk owns the policy and the evidence, and each agent has a business owner accountable for what it does. Governance most often fails where an agent has no named owner.
Is AI agent governance required by law?
Not under that name. The EU AI Act sets duties such as logging and human oversight for high-risk AI systems, and an agent is covered when it is, or is part of, such a system. Frameworks such as ISO/IEC 42001 and SOC 2 are voluntary, but customers often ask for them.