AI governance
Agentic AI governance covers the agent, not the answer
Every agentic AI governance framework on the first page of Google governs the same thing: what the agent is permitted to do. Almost none of them governs what the agent is acting on: who approved it, and whether it is still current. That is where the expensive failures live.
Sep 10, 2026 · 6 min read
Read the current guidance on agentic AI governance and a pattern emerges. Palo Alto Networks defines it as the structured management of delegated authority in autonomous AI systems, and its implementation guide runs to eight steps: scope and authority, identity and access boundaries, a pre-deployment impact assessment, runtime controls, logging and traceability, human oversight thresholds, incident response and shutdown, and drift monitoring. Okta, Box, BigID and the Cloud Security Alliance arrive at broadly the same list.
Cognatum governs the entry
source · version · approver · permissions
That list is sound, and a firm that works through it will be better off. It is also a list about half the problem. Every item governs what the agent is permitted to do. Not one governs what the agent is acting on.
The risk register has a hole in it
The same guide names seven principal risks of AI agents: loss of execution control, unauthorized tool invocation, privilege escalation, data misuse, emergent multi-agent effects, accountability diffusion, and drift over time.
Read them again. Every one describes an agent doing something it should not have been allowed to do. None describes an agent doing exactly what it was allowed to do, correctly, on the basis of a document that was superseded in March.
The failure nobody lists
That second failure is not exotic. In most enterprises it is the ordinary one. An agent with clean permissions, a complete action log and a human approval threshold can still quote a rate or route a submission on the strength of a procedure nobody has approved since 2023. Every control fires correctly. The outcome is still wrong, and nothing in the register catches it.
Governance moved from the answer to the action
IBM's Agentic AI Governance Playbook is unusually direct about the shift. Governing agents, it argues, means changing the focus from validation to control, from validating the answer to controlling the actions. The reasoning is fair. A predictive model produces an output a person reads and weighs. An agent produces an action that executes.
The difficulty is the word "from". Validating the answer did not stop mattering when the answer became an action. It started mattering more, because the person who used to sit between the answer and its consequence has been removed by design. Autonomy does not lower the standard of proof on the content. It removes the last human who might have noticed the content was wrong.
What the stall is costing
Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027, naming escalating costs, unclear business value and inadequate risk controls. That third category is worth sitting with. In a regulated firm, the control a reviewer asks about is rarely the network path. It is the basis of the decision.
The identity gap is real, and it is half the gap
Okta's AI Agents at Work 2026 survey of 292 executives and 492 knowledge workers across seven countries found 92% of executives reporting autonomous agents already in widespread or moderate use. In the same Okta survey, 58% of executives said their organization had an AI-related security incident or close call in the previous 12 months. Okta also found that only 34% of executives say their organization always applies the same security controls to the digital labor force as to the human one.
Credentials without a handbook
The Cloud Security Alliance, writing up that research, draws the conclusion the industry has settled on: an AI agent needs the identity verification, role-based access control and behavioral monitoring an employee gets. That is correct and overdue, and worth following one step further than it usually gets taken. When a person joins a regulated firm, you do not only issue credentials and monitor behavior. You hand them the current handbook: which procedure is in force, who signed it, when it was last reviewed. Onboarding has always been an access problem and a knowledge problem. Agents are being onboarded with credentials and no handbook.
What a reviewer will ask the agent's owner
Article 12 of the EU AI Act requires that high-risk AI systems technically allow for the automatic recording of events over the lifetime of the system, with logs sufficient to identify risks, support post-market monitoring and enable operational oversight. Article 14 requires those systems be designed so they can be effectively overseen by natural persons. FINRA's 2026 Annual Regulatory Oversight Report expands substantially on generative AI, reiterates that firms remain responsible when using these tools, and flags supervision, recordkeeping and emerging agent-based risks. The NIST AI Risk Management Framework, voluntary by design, is organized around governing and documenting rather than around any particular architecture.
What software can and cannot do
None of these confers compliance on a piece of software. Software can align with them and supply the evidence they call for: approvers, dates, sources and versions. It cannot make an organization compliant, and a vendor claiming otherwise is describing something the frameworks do not do.
The question an action log cannot answer
An action log tells you the agent issued a credit on 14 May at 09:12, under which identity, invoking which tool, and that a human cleared it. It does not tell you what the credit policy said on 14 May, who had approved that version, or whether it had been superseded eleven days earlier. When the question arrives months later, and in regulated industries it does, the log describes the action perfectly and the ground it stood on not at all.
The supply side of agentic governance
Your company's knowledge isn't missing. It just isn't usable. Cognatum changes that.
A record with an approver, a date and a source
Cognatum is a governed knowledge management system for regulated enterprises. It gives an organization a single approved home for what it knows, and serves that knowledge to people, applications, workflows, and AI systems, with a named approver, a timestamp, and a source on every entry. Information stays where it already lives, in the departmental repositories your teams already use. Cognatum does not ask you to move anything or tidy anything up first. It reads what is there, and it keeps reading. What it stores is the answer, not a second copy of your files.
Point in time, not only point of action
Two behaviors matter here. Cognatum records where the knowledge stood at the moment an answer was given, which is provenance at a point in time rather than an approver and a date alone. And when an underlying source changes, anything indexed against it is flagged and routed for re-check. Nothing goes stale in silence. The system does not quietly correct itself and it is not always current by assertion, because an answer that changes without a person approving the change is not a governed answer.
A test to run before the next agent ships
Take one agent you have deployed or plan to deploy, and write down the three decisions it makes most often. For each, name the record it consults, who approved that record, when, and what happens to the agent's behavior when that record changes.
If you can answer for all three, your remaining work really is permissions. If you cannot, no amount of scope definition, least privilege or runtime guardrail will settle it, because the agent will execute your governance perfectly and your knowledge badly.
Knowledge governed. Intelligence everywhere.
Sources
- A Complete Guide to Agentic AI Governance (paloaltonetworks.com)
- Agentic AI Governance Playbook (ibm.com)
- Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027 (gartner.com)
- AI Agents at Work 2026: Securing the Agentic Enterprise (okta.com)
- The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap (cloudsecurityalliance.org)
- Article 12: Record-Keeping, EU Artificial Intelligence Act (artificialintelligenceact.eu)
- Article 14: Human Oversight, EU Artificial Intelligence Act (artificialintelligenceact.eu)
- 2026 FINRA Annual Regulatory Oversight Report (finra.org)
- AI Risk Management Framework (nist.gov)
Common questions
Questions this raises.
Is agentic AI governance actually different from AI governance?
Yes, in what it has to control. Conventional AI governance was built around models producing outputs a person reads, so it emphasizes validation, explainability and fairness. Agents plan, invoke tools and act in real time, which adds authority limits, runtime controls and action logging. The mistake is treating the addition as a replacement. Agents still answer from content, and removing the human reader raises rather than lowers the standard that content has to meet.
Our agents retrieve from our document repositories. Doesn't that solve the knowledge side?
Retrieval solves findability, not authority. A retrieval layer can return the right file and still have no way to say which answer inside it was approved, by whom, or whether it is still in force. Most enterprises can index everything and still not name the current sentence. That is a governance property of the record, not a property of the search.
Can software make us compliant with the EU AI Act or the NIST AI RMF?
No. The NIST framework is voluntary and carries no certification, and EU AI Act obligations sit with providers and deployers rather than with a vendor. Software can align with these frameworks and produce the evidence they ask for, including approvers, timestamps, sources and versions. Compliance stays with the organization.
Do we have to consolidate everything into one system first?
No, and the attempt is usually where these programs die. Information living in departmental repositories is normal and generally fine. The problem is that nothing sits above those repositories to say which answer is approved and current. The fix is a governing layer, not a migration. It reads what is there, and it keeps reading.
What should we be logging about an agent's actions?
Log the action, the identity, the tool invoked, the model version and the point of human review, as the frameworks direct. Then log the basis: which knowledge record the agent relied on, its version, its approver and its state at that moment. The first set tells a reviewer what happened. Only the second tells them whether it should have.