Operations / Governance & Compliance
Governance & Compliance
Accountability, audit, policy enforcement and the regulatory landscape — making agent decisions defensible.
- Audit Trails & ProvenanceWhat to capture to reconstruct any decision, hash-chained tamper-evidence, retention vs erasure, and the four-strand provenance of model, prompt, tools and data.
- Policy Enforcement & ControlsPolicy-as-code outside the model, enforcing pre/in/post loop, allowlist-by-default, and separation of duties so a compromised agent cannot close the loop alone.
- The Regulatory LandscapeA qualitative map (not legal advice): risk-tiered regulation, documentation and human-oversight duties, the provider/deployer split, and how NIST AI RMF and ISO/IEC 42001 operationalize it.
- EU AI Act, for agentsThe AI Act's risk tiers explained from an agent builder's perspective — what triggers high-risk, what general-purpose AI obligations look like, and the dates that matter.
- NIST AI RMF, for agentsMap / Measure / Manage / Govern read as a checklist for agent teams — what each function actually demands when the system is an autonomous agent rather than a model.
- Accountability & OwnershipAccountability never transfers to the agent: the named operator role, RACI on the autonomous action, sign-off that means something, and an accountability ladder set in advance.
- Data Governance for AgentsAn agent is a data-flow machine: lineage through the loop, purpose/consent enforced at point of use, boundary minimization for PII, governed training data, and invisible cross-border flow.
- Governance Without GridlockMake governance an enabler: risk-proportionate tiers, the safe default as the easy path, automated evidence with humans on judgment, and counting gridlock as a real cost.
- Third-Party Model & Vendor RiskThe question with teeth is not "is your model safe" but "what can change without telling me": version stability, subprocessor notice and retention terms as the three clauses that decide whether your evals stay true — plus the gateway that gives you all of it without the vendor's cooperation.
- Disclosure & Content ProvenanceDisclosure is a property of an artifact as it travels, and in an agent topology the person who must be told is rarely where your code is — so put it at one egress layer with a CI test per channel, and accept that text provenance rests on a record you hold, not a watermark a paraphrase removes.
- IP & Copyright for Agent OutputWhether you can stop others copying the output and whether your vendor will defend you if it infringes are the same variable read from opposite ends — how much human judgement is still in the artifact — so autonomy spends your ownership and your indemnity at once.
- Retention & Legal Hold for Agent TracesYour tracing platform's default TTL is a legal decision an engineer made to control storage cost — and the trap is not the primary store, which you can hold, but the copies: eval golden sets, fine-tuning extracts and vendor-side retention all escape both the deletion request and the hold.
- Serious-Incident ReportingLive since 2 August 2026, the AI Act's two-day track for widespread fundamental-rights infringements is an engineering deadline, not a legal one — the clock starts at the causal link, and sampled traces, rotated model versions and a deployer who is not the provider are what make it unmeetable.
- Agent Inventory & RegistryEvery governance regime opens with "enumerate your AI systems" and almost everyone answers with a voluntary spreadsheet, which omits exactly the agents that carry risk — derive the inventory from credential issuance, the gateway and the bill, make the grant rather than the name the unit of record, and put the register in the issuance path so it cannot drift.
- Delegated Access & Consent RecordsConnecting a user account creates a token every system stores and a consent almost nobody does — grantor, scope, purpose text, client ID and time — so the questions you will actually be asked are answered by the record you discarded; keep an append-only ledger, stamp its ID on every action, log exercised scope alongside granted scope, and rehearse revocation like a restore because the credential dies while the derived data, the queued job and the downstream effects do not.
- Erasure Requests Against Agent MemoryThe request names a person; your storage names a chunk, a vector, a summary and a graph edge, and a memory system earns its value precisely by deriving state that no longer carries the identifier — so key every derived artefact to its sources at write time, delete by rebuilding rather than by patching, and run one synthetic-subject drill to find out which of your six copies are actually reachable.
- Insurance & Liability for Agent ActionsWho absorbs the loss is not decided by fault but by three documents written months earlier — the vendor's liability cap, your customer contract, and whether your policy affirms or excludes AI — so build the three-document table per agent, get every AI clause from your broker before renewal now that standardised exclusions exist, and treat the decision receipt as the instrument that converts a claim into a payment.
- Model Risk Management for AgentsSR 26-2 replaced SR 11-7 on 17 April 2026 and put generative and agentic AI outside its scope, so the agent in a credit or AML decision lost its framework while the law over the decision did not move — the answer is not to wait for the promised follow-on guidance but to register the configuration tuple rather than the model, re-point conceptual soundness, ongoing monitoring and outcomes analysis at trajectories, and file the agent under operational risk with a signed determination memo per entry.
- Contestability & AppealsThe appeal lands six weeks late, by which time the model, the index, the policy and the prompt have all moved — so a re-run is a different system answering a different question, and your retention policy, not your appeals form, decides whether contestability exists. Pin ten fields at decision time on an unsampled long-retention path, give the reviewer different evidence rather than the model's own verdict and confidence, and read a near-zero overturn rate as proof the review is ceremonial rather than as success.
- Zero Data Retention & Abuse MonitoringZDR is a property of a model-and-endpoint pair, not of your account, and on frontier models safety programmes now carve back the retention the contract used to remove — with the longest windows attaching to the flagged traffic most likely to be sensitive. One agent task fans out across six boundaries including the failover nobody reviewed; inventory calls rather than vendors, and note that buying ZDR deletes the vendor-side evidence while leaving your own trace store untouched.
- Worker Consultation & Co-DeterminationGerman co-determination attaches to a system objectively suitable for recording behaviour or performance, and the employer's intent not to monitor is irrelevant — so the per-user trace store you built for debugging, not the agent, is what can stop a workplace rollout. Separate the AI Act's one-directional duty to inform workers' representatives before use from the bilateral duty to agree, bring your own versioned system description, and design for a yes: aggregate by default, pseudonymise at write time, and make the prohibition demonstrable rather than promised.
- Commercial Influence & Paid PlacementAffiliate content in retrieved pages, a marketplace someone paid to join, a preferred-supplier list and the model’s own brand priors are all commercial influence arriving through channels nobody registered — and the obligations that exist, from the FTC Endorsement Guides to DSA advertising transparency, all assume a human reader while your consumer is a model. Stamp provenance on every tool result rather than a banner on the page, separate relevance from commercial adjustment as a named logged step, and measure the influence rate with a counterfactual run instead of asserting impartiality.
- Access Reviews for Agent CredentialsEvery access review programme works because HR emits a termination event, and an agent has none — so adding service principals to the same quarterly attestation produces approval at scale and cleanup of nothing. Review the reachable call rather than the credential row, capture reason, owner and bound limit at grant time, and replace the attestation with use-based expiry driven off last-accessed data you already collect. The delegated half does have a leaver event: wire it.
- Decommissioning an AgentOnly 21% of organisations have a formal decommissioning process, and the enumerable half is the easy half — teardown order, draining as a side-effect decision, and the provenance boundary you owe the records, memory and documents that have no off switch.
- Impact Assessments for Agent DeploymentsAn impact assessment is a dated snapshot of a system whose behaviour is set by six things that mostly change without a release, so the document you file in March describes a system that stopped existing in May. The FRIA is a deployer obligation — no stack of vendor attestations discharges it — and the Digital Omnibus moved the enforcement date to December 2027 without touching the substance. Write conclusions as measurement, threshold, owner and re-assessment trigger, and make “stale” a deployment state with a consequence.