Enforcing an AI Policy Where Agents Run: A Four-Phase Governance Framework

Updated: 6 days ago
Title: Enforcing an AI Policy Where Agents Run: A Four-Phase Governance Framework
Date: 7 May 2026
Type: Paper
Author: SAASiQ (contact@saasiq.ai)
Word count: 2945 words
Reading time: 11 min
Published: 07-05-2026
Tags: #AI #Governance #Enterprise #Compliance
EU negotiators reached a provisional agreement in the early hours of 7 May to move the AI Act's high-risk obligations to 2 December 2027 for the systems listed in Annex III and 2 August 2028 for AI built into regulated products. On 1 May Microsoft made Agent 365, its registry and control system for AI agents, generally available at $15 per user per month. IBM's breach research found that 63 per cent of organisations had no AI governance policy, and that among those with one, fewer than half had an approval process for AI deployments. This paper sets out how to turn a written AI policy into controls that act where agents run, and into records that show they did.
What was agreed in Brussels
The Commission published the Digital Omnibus on AI on 19 November 2025. The Council agreed its position on 13 March and the European Parliament adopted its mandate on 26 March, and both backed fixed dates for the high-risk rules. The second political trilogue, on 28 April, ended without agreement after about 12 hours, over how AI in products already covered by sectoral law, such as machinery and medical devices, should be assessed. The Council announced the provisional deal on 7 May, the date of this paper.
Under the deal, the obligations for stand-alone high-risk systems in Annex III apply from 2 December 2027, and those for high-risk AI embedded in products under Annex I from 2 August 2028. Providers of generative systems already on the market get until 2 December 2026 to meet the watermarking rules in Article 50, while the Article 50 duties to tell people they are dealing with AI, or looking at a deepfake, still apply from 2 August 2026. The co-legislators also added a ban on AI systems that generate child sexual abuse material or non-consensual intimate images, kept the requirement to register high-risk systems in the EU database even where a provider claims an exemption, and extended some of the relief for small businesses to small mid-cap companies.
The agreement still has to be formally adopted by Parliament and Council and published in the Official Journal. Until that happens, 2 August 2026 remains the legal date for the high-risk obligations.
For an organisation that uses AI rather than builds it, the obligations that matter sit in Article 26. A deployer of a high-risk system has to assign human oversight to people with the competence and authority to exercise it, keep the logs the system generates for at least six months, and inform workers and their representatives before using a high-risk system in the workplace. Article 27 adds a fundamental rights impact assessment for public bodies, private organisations providing public services, and deployers of systems that score creditworthiness or price life and health insurance. UK organisations are outside the Act's direct reach unless they operate in the EU.
How far policy and practice are apart
IBM's Cost of a Data Breach Report, published on 30 July 2025 from research by the Ponemon Institute across 600 organisations, found that 63 per cent had no AI governance policy. Among the organisations that did have one, fewer than half had an approval process for AI deployments, and only 34 per cent audited regularly for unsanctioned AI. Of the organisations that had suffered an AI-related security incident, 97 per cent said they lacked proper AI access controls, and one in five of all those studied had had a breach linked to shadow AI.
In WRITER's survey of 2,400 people, published on 7 April, 36 per cent of executives said they had no formal plan for supervising AI agents, and 35 per cent said they could not immediately 'pull the plug' on a rogue one. Deloitte's State of AI in the Enterprise report, published on 21 January, found that 74 per cent of organisations planned to deploy agentic AI within two years and 21 per cent had a mature model for governing autonomous agents. McKinsey's State of AI survey, published in November 2025, found 23 per cent scaling an agentic system somewhere in the business.
Gartner predicted in August 2025 that 40 per cent of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5 per cent in 2025. It had also predicted, in June 2025, that more than 40 per cent of agentic AI projects will be cancelled by the end of 2027, with inadequate risk controls one of the three reasons it gave. A policy written for staff using chatbots does not describe any of the controls an agent needs, because an agent acts through tools and credentials rather than through a person at a keyboard.
Before starting
The framework assumes three things: a written AI policy, however incomplete, a named person accountable for AI risk with the authority to stop a deployment, and at least one agent in production or close to it. An organisation still at the experiment stage needs the policy and an inventory first.
The inventory has to include agents that arrived inside software the organisation already licenses. On its third-quarter earnings call on 10 March, Oracle said it had delivered well over 1,000 AI agents inside its applications, at no additional cost. Its 26B quarterly update reached the first customers' test environments on 1 May, and the readiness notes mark the new finance agents as Setup Required, so they do nothing until an administrator configures them. Other products handle new features in their own ways, so the inventory should come from the systems themselves as well as from asking teams.
Phase one: test each policy statement for a control
The first phase takes every statement in the AI policy and asks three questions of it. Is there a technical control that enforces it in the systems where AI runs? Is there evidence, kept somewhere an auditor can reach, that the control operated? And which AI uses does the statement apply to? The result is a table, one row per statement, with the gaps visible.
A statement such as 'AI-generated hiring recommendations must be reviewed by a person before action' is a useful test. If a recruiting agent can send a shortlist straight to a hiring manager, the statement has no control behind it. It also falls within Annex III, which covers AI used in recruitment, promotion, termination, task allocation and the monitoring of workers, so for an organisation operating in the EU it will become a legal duty as well as an internal rule.
A policy that treats AI as a separate tool people consult will miss agents that work inside an application's own security model, and agents built in Oracle AI Agent Studio are one example. When Oracle launched the studio in March 2025, it said agents adhere to Fusion's security configurations, policies and access controls, so an agent working for a user sees only the data and functions that user's roles allow. A policy that says nothing about agents acting within existing approval hierarchies has no statement to test against them.
The gaps should be ranked by what the AI can change. An agent that can create or approve transactions in a ledger, a payroll or a supplier master ranks above a chat assistant with read-only access, whatever the number of users. Unsanctioned tools belong in the inventory too: Netskope's Cloud and Threat Report in January found that 47 per cent of people using generative AI at work did so through personal accounts.
Phase two: one control matrix mapped to the frameworks
The second phase maps each row of that table to the frameworks and rules that apply, so the organisation keeps one set of controls instead of a separate AI programme with its own risk register. NIST's AI Risk Management Framework, version 1.0 from January 2023, organises the work into four functions (Govern, Map, Measure and Manage), and its Generative AI Profile, NIST AI 600-1, followed in July 2024.
ISO/IEC 42001, published in December 2023, is the certifiable management system standard for AI. Its structure follows ISO/IEC 27001:2022, so an organisation that already runs an information security management system can extend its risk assessment, internal audit and management review to cover AI. What 27001 lacks is the AI system impact assessment in clause 6.1.4, and ISO/IEC 42005, published in 2025, gives guidance on carrying one out. Annex A of 42001 lists 38 controls in nine areas.
For the regulatory column, Annex III of the AI Act lists eight areas of high-risk use: biometrics, critical infrastructure, education, employment, access to essential public and private services (including credit scoring), law enforcement, migration and border control, and the administration of justice and democratic processes. It works as a risk tiering even for an organisation outside the EU.
For threats, the OWASP Top 10 for LLM Applications, in its 2025 edition, lists prompt injection first and excessive agency sixth. OWASP's separate Top 10 for Agentic Applications, published on 9 December 2025, runs from ASI01, Agent Goal Hijack, to ASI10, Rogue Agents, and includes ASI07, insecure communication between agents, and ASI08, cascading failures, in which one agent's error or compromise spreads through a workflow. MITRE ATLAS, the catalogue of attacks on AI systems, had 16 tactics and 84 techniques in its November 2025 release. The releases since have added mostly agent-related techniques, among them AI Agent Tool Credential Harvesting in January and AI Agent Tool Poisoning in March, and the most recent came out on 4 May.
Singapore's Infocomm Media Development Authority published a Model AI Governance Framework for Agentic AI on 22 January, launched by the minister Josephine Teo at Davos. It has four dimensions: bounding risks up front through the choice of use case and limits on an agent's autonomy and data access, defining checkpoints at which a person must approve, technical controls across the agent's lifecycle, and helping end users understand what an agent can and cannot do.
The output of this phase is a single matrix, with each control linked to the policy statement it enforces, the frameworks it satisfies and a named owner for any gap.
Phase three: enforce at identity, action and data
The third phase puts controls where the agent acts, in three layers. The first is identity. Each agent needs its own identity, an owner, and permissions no wider than its task, managed in the same identity system as people and reviewed on the same schedule as privileged accounts. Agent 365 gives each agent an identity in Microsoft Entra, so conditional access and identity governance apply to it, and lets administrators start, stop and delete agents across platforms. NIST's National Cybersecurity Center of Excellence set out the open questions in a concept paper on 5 February, including whether an agent's identity should persist or last for a single task and how a compromised agent's credentials are revoked, and it wants every agent action traceable to the person who delegated the permissions.
The second layer checks each action against policy before it runs. Amazon made Policy in Bedrock AgentCore generally available on 3 March: a gateway intercepts the traffic between an agent and its tools and evaluates each request against policies before allowing or denying it. The policies can be written in plain English and are converted to Cedar, AWS's open-source policy language, which denies any request that no policy permits. Oracle published a runtime governance framework on 23 April in which a controller checks each proposed action against the active policy, the identity and approval bindings and the current budget, and returns ALLOW, ALLOW_WITH_REDACTION, REQUIRE_REVIEW or DENY. Microsoft has said runtime blocking of malicious agent behaviour in Agent 365 will follow in June. On 29 April the Cloud Security Alliance's new AI foundation took over the Autonomous Action Runtime Management specification, contributed by Vanta, which covers the same point of control.
The third layer sits in the data. The UK's National Cyber Security Centre advised in December 2025 that when a model processes content from an outside party, its privileges should drop to that party's level, and that the actions it can take should be limited by safeguards that do not depend on the model. Oracle made Deep Data Security available in Oracle AI Database 26ai on 1 May. It passes the identity of the end user, or of an agent acting for one, to the database at runtime, and row, column and cell policies decide what comes back, so an agent that has been manipulated into asking for data its user should not see still meets the same rule.
Delegation between agents needs a rule of its own. Where one agent hands work to another, the second should carry the limits of the user and task that started the chain rather than only its own permissions. OWASP's ASI03 covers agents acting with more authority than they should have, and ASI08 the way one agent's fault spreads to the others. The Singapore framework's checkpoints belong here too: an action that cannot be undone, such as a payment released or a candidate rejected, goes to a person.
Separation of duties when the actor is an agent
In an ERP system, separation of duties is a policy that already has a technical equivalent. Oracle's documentation gives the standard example: a check for users who hold the privileges both to create a payables invoice and to approve payment on it, and a transaction check for occasions when one user has actually done both. The Risk and Security Snapshot Report in Oracle Fusion Cloud Risk Management runs both kinds of analysis with prebuilt algorithms, grouped into content packs by business process.
Because a Fusion agent works within the roles of the user it acts for, the same analysis covers it. Oracle has also put an agent into the access process. The Access Request Assistant, added in release 25D, takes a request for roles in plain language and starts the Advanced Access Request workflow, which runs the separation of duties analysis before anything is granted. In 26A Oracle documented four Assurance Advisor agents, for Source to Settle, Order to Cash, Record to Report and Hire to Retire, which answer questions about the Snapshot report's findings.
SAASiQ's view is that for Fusion customers the role design done at implementation is also the security design for their agents, so a review of who can use each agent, run through the existing separation of duties analysis before an agent is switched on, is the first enforcement step.
Phase four: evidence and review
Auditors and regulators ask for evidence that a control operated. For each material action an agent takes, the record should answer four questions: which policy applied, whether it was evaluated, what the result was, and what the agent then did. Oracle's 23 April framework makes this its bottom layer, recording traces, provenance, tool identities and decision records so that any material decision can be replayed, and the NCSC advises logging inputs, outputs, tool use and API calls so that anyone probing the system is spotted early.
Retention has a legal floor where the AI Act applies, since Article 26 requires deployers of high-risk systems to keep the logs for at least six months. Agent-initiated transactions should also fall under the same audit configuration as those entered by people, so that the audit trail in a finance system does not have a gap wherever an agent acted.
A monthly review should cover policy violations and near misses, access certifications completed for agents, changes to agents and their models, and whether any control failed. Findings go back into the matrix: if agents keep tripping the same separation of duties rule in one workflow, the answer may be a change to the role or the workflow as well as a fix to the individual case.
The matrix also needs a schedule, because the frameworks keep moving. OWASP's agentic list was published in December, ATLAS has added agent techniques in several releases this year, and the EU text is not yet final. CrowdStrike's Global Threat Report, published on 24 February, found that AI-enabled adversaries increased their operations by 89 per cent in 2025, and that attackers injected malicious prompts into legitimate generative AI platforms at more than 90 organisations to generate commands for stealing credentials and cryptocurrency. The matrix should be checked against the frameworks at least once a quarter.
What it costs and where it breaks
The framework has running costs. The control matrix needs an owner, and the policy engine, whichever product provides it, is software to build, secure and maintain. Gartner said on 17 February that spending on AI governance platforms would reach $492 million in 2026 and pass $1 billion by 2030, as AI regulation extends to 75 per cent of the world's economies.
Each vendor's controls cover its own platform. Agent 365 governs agents in Microsoft's estate, with registry sync for agents on AWS Bedrock and Google Cloud still in public preview, AgentCore Policy governs tool calls that pass through its gateway, and Fusion's role security governs Fusion. An organisation running agents in several places needs its own matrix above all of them. Policies written in plain English and converted to code need checking by someone who can read the result.
This framework covers enforcement and evidence. It does not cover model-level safety testing, sector rules such as the FCA's and PRA's expectations for financial services, or the contract terms that pass governance requirements on to AI suppliers.
Oracle's 26B update reaches production for its first group of customers on 15 May, Microsoft's runtime blocking for Agent 365 is due in June, and the Omnibus has to be formally adopted and published before 2 August 2026 for the new high-risk dates to take effect in time.
SAASiQ - Intelligent Solutions for SaaS ©


