Start with the control plane. Governance documents, accountability matrices, and risk taxonomies matter, but they depend on enforceable requests and usable logs. If the enforcement path does not exist first, governance remains unproven and observability remains incomplete, which leaves AIUC-1 compliance without a technical foundation.
Why the Control Plane Comes Before Governance Artifacts
For AI agents, governance is only credible when it can be enforced. A policy document can define accountability, but it cannot prevent an agent from acting outside scope, nor can it produce trustworthy evidence after the fact. The control plane turns intent into request-level decisions, approved actions, and logs that can be audited, tested, and revoked.
That is why the first implementation question is not “what do we want to say about AI agents?” but “what can the system actually allow, deny, and record?” Without that layer, governance remains aspirational, and the organisation cannot prove that policy is more than a paper exercise.
What the Control Plane Must Establish First
The control plane should define who or what is acting, what action is being requested, what resource is in scope, and what policy decision is made at the moment of execution. For AI agents, that usually means request-scoped authorisation, explicit approval boundaries, and a log trail that ties each action back to a principal and a policy outcome.
In practice, this is where identity, privilege, and observability become operational rather than theoretical. If the agent can call tools, access data, or trigger workflows, those actions need enforceable gates, not just documented rules. A governance matrix without the enforcement path cannot tell you whether the agent was constrained, overprivileged, or simply lucky.
For that reason, design choices about authorization and logging are foundational. The AI Agent Authorisation Guide is relevant here because least privilege, per-action decisions, and human approval only work when the control plane can enforce them. The same is true of AI Agent Observability, Audit and Incident Response Guide, which shows why action logs and attribution are prerequisites for any credible governance claim.
How Governance Documents Still Fit, but Only After Enforcement Exists
Governance documents, accountability models, and risk taxonomies still matter. They define ownership, escalation paths, acceptable use, and the organisational standard for what “safe” means. The problem is sequencing: these artefacts should codify an operating model that the control plane can already enforce, not substitute for one.
That distinction matters most when multiple teams share responsibility. Security may own the control plane, the product team may own the agent, and risk or compliance may own policy language. If those layers are built in the wrong order, teams can overstate control maturity because the documentation exists while the technical guardrails do not.
This is also why agent identity and delegation must be treated as operational design choices, not just policy statements. Agentic AI Identity Guide is useful because it connects registration, delegation, and lifecycle control to how the agent actually behaves, while Zero Trust for AI Agents frames the same problem as continuous verification and no standing privilege. Those are control-plane concerns first, governance-document concerns second.
What Good Practitioner Sequencing Looks Like
Start by constraining execution, then document the policy model around the constraint. A practical order is: define the request and approval boundary, enforce tool and data access, record actionable logs, and only then formalise governance artefacts around ownership, risk acceptance, and exception handling.
What to verify: confirm that every meaningful agent action is mediated by a policy decision point, that logs can reconstruct who requested what, and that denied actions are observable as clearly as approved ones. If you cannot demonstrate those three things, the governance layer is premature.
What to prioritise: prioritise blast-radius reduction and auditability over completeness of the policy catalogue. A narrower but enforceable control plane is more valuable than a comprehensive policy set that no runtime component actually honours.
Practitioner takeaway: Governance documents should describe and govern an enforceable system, not attempt to compensate for the absence of one. If the control plane cannot constrain, attribute, and log agent actions, the organisation does not yet have operational governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | AI agents need enforced privilege boundaries to stop unauthorised actions. |
| Recommendation — Enforce per-action authorization and least privilege for agent requests. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Agent governance depends on auditable action trails and reconstructable events. |
| AC-6 — Least Privilege | The control plane must limit agent authority to the minimum required. | |
| IA-9 — Service Identification and Authentication | AI agents act as non-human actors that must be authenticated before access is granted. | |
| Recommendation — Define and retain audit events for agent actions and policy decisions. Restrict agent permissions to the minimum authority needed for each task. Authenticate agent-to-service requests before permitting access. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege | AI agent control planes need privilege boundaries that are enforced at request time. |
| Recommendation — Apply least-privilege enforcement to agent access and tool use. | ||
Related resources from NHI Mgmt Group
- How should organizations approach the governance of AI agents?
- How should organisations use AI agents in access reviews without losing governance control?
- Why do organisations need a unified control plane for agentic AI instead of separate stacks for models, tools, and agents?
- What should organisations do when AI agents become part of the production control plane?